
CVE-2026-55584
CVE-2026-55584 — phpSysInfo IP Allowlist Bypass

CVE-2026-55584 — phpSysInfo IP Allowlist Bypass

Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth

PoC | NextJS Middleware 15.2.2 - Authorization Bypass

Technical disclosure of CVE-2024-33676: weak authentication on Enel X JuiceBox EV chargers enabling PII extraction, settings manipulation, and OS…

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。

CVE-2025-29927: Next.js Middleware Bypass Vulnerability

Next.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。

CVE-2025-29927 Proof of Concept

PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes…

Local testing environment for Next.js middleware authorization bypass vulnerability (CVE-2025-29927). Demonstrates exploitation via crafted…

CVE-2025-29927 Proof of Concept