
CVE-2026-27944
CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read…

Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data…

Insecure Permissions WeDayCare

Zap Extension for collaboration in Faraday

SQL Injection in 3CX CRM Integration

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI


Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain


The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10



Global API Integrity Assessor


API-based scanner that retrieves and lists the latest Common Vulnerabilities and Exposures (CVEs) for automated security assessment and vulnerability…