
otto-support
An implementation of a vulnerable MCP server using mcp-go

An implementation of a vulnerable MCP server using mcp-go

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

A new open-source tool to quickly audit SAP permissions.

Catch what's lurking in your Kafka clusters.

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

CVE-2026-55584 — phpSysInfo IP Allowlist Bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

CVE-2025-29927: Next.js Middleware Bypass Vulnerability

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Redacted cPanel/WHM authentication bypass analysis and authorized checker

Wechat Social login <= 1.3.0 - Authentication Bypass

Provides community notes and an optional temporary hook to guard against CVE-2026-29204, a WHMCS client area addonId ownership vulnerability, with…

Macally WIFISD2

CVE-2023-47564

CVE-2020-10130 - SearchBlox Product before V-9.1 is vulnerable to Business logic bypass

Critical vulnerability in next.js : Bypass middleware authentication

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

Checklist of the most important security countermeasures when designing, testing, and releasing your API