
CVE-2021-32648
Provides a manual patch for October CMS authentication bypass vulnerabilities CVE-2021-32648 and CVE-2021-29487 by converting loose to strict…

Provides a manual patch for October CMS authentication bypass vulnerabilities CVE-2021-32648 and CVE-2021-29487 by converting loose to strict…

Proof-of-concept exploit for CVE-2026-6274, an authentication bypass in Redline WR3200 routers allowing unauthorized password change via static…

Technical write-up of CVE-2026-26717, an HMAC timing attack in OpenFUN Richie LMS webhook authentication, including vulnerable code, impact, and fix…

Mind-Maps of Several Things

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

bypass all stages of the password reset flow

Jenkins plugin providing Git APIs for automated repository operations including fetch, checkout, merge, and tag, with support for credential-based…

web2py/web2py @ e94946d

Oracle Identity Manager 远程代码执行漏洞CVE-2025-61757

Full-featured open-source toolkit implementing SSL/TLS protocols and a general-purpose cryptography library, including ciphers, digests, public key…

authz test (CVE-2026-1999 siblings)

Reproducer for CVE-2026-46455 — Apache Camel camel-keycloak missing TokenVerifier.IS_ACTIVE check (expired access tokens accepted)

Proof-of-concept exploit for CVE-2026-11551, an unauthenticated privilege escalation vulnerability in the Branda White Label plugin for WordPress,…

Detailed disclosure of CVE-2025-63314: static, non-expiring password reset token in Acora CMS 10.7.1 enabling account takeover and privilege…
