


Discover hidden parameters in Caido

A program for testing WAF functionality

CyberArk Security Audit


A proxy for net.tcp-based WCF traffic.

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

CVE-2023-23752 nuclei template

SQL Injection in 3CX CRM Integration

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。


Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

