
DNN_CVE-2015-2794
NSE plugin for Nmap that scans a DotNetNuke (DNN) web application for an Administration Authentication Bypass vulnerability (CVE-2015-2794, EDB-ID:…

NSE plugin for Nmap that scans a DotNetNuke (DNN) web application for an Administration Authentication Bypass vulnerability (CVE-2015-2794, EDB-ID:…

Java-based wiki platform with detailed access control and JAAS security integration, provided as a vulnerable version for security testing and CVE…

Modulith runtime with hot deployment, dynamic configuration, JAAS-based RBAC, and centralized logging. Supports REST/API, web, and Spring Boot…

Brute Force Wordpress Blogs.

Centralized configuration server for distributed systems with HTTP API, Git-backed storage, property encryption/decryption, and integration with…

Proof-of-concept exploit for CVE-2023-31704: Incorrect access control in Sourcecodester Online Computer and Laptop Store 1.0 allows remote privilege…

CVE-2024-52316 - Apache Tomcat Authentication Bypass Vulnerability

Responsible disclosure of unpatched vulnerability in FluentCRM by WPManageNinja

Import Users From CSV with Meta 1.15 - Unauthorised Authenticated Users Export

Java-based wiki platform with JAAS security integration, access control, and detailed configuration auditing. Includes documentation for…

Provides community notes and an optional temporary hook to guard against CVE-2026-29204, a WHMCS client area addonId ownership vulnerability, with…

High-performance Java RPC and microservices framework with service discovery, traffic management, observability, and built-in security for building…

Macally WIFISD2

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

Docker-based lab for exploring and reproducing the Next.js CVE-2025-29927 middleware authorization bypass vulnerability. Includes vulnerable app,…

Apache ShenYu 管理员认证绕过

Jenkins plugin providing script approval workflows and Groovy sandboxing to enforce secure script execution, with ACL-aware permission checks and…

Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…