
CVE-2025-12135
WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

Discover input surfaces and security issues in compiled .NET assemblies — without running them.



Reproducer for CVE-2026-46455 — Apache Camel camel-keycloak missing TokenVerifier.IS_ACTIVE check (expired access tokens accepted)

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

Oracle Identity Manager 远程代码执行漏洞CVE-2025-61757


authz test (CVE-2026-1999 siblings)

bypass all stages of the password reset flow

Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.

Proof of concept for CVE-2017-6640 as burp extension

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Mind-Maps of Several Things