
CVE-2026-66917
IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery

IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)

authz research - CVE-2026-3306 fix coverage

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

Jenkins plugin providing script approval workflows and Groovy sandboxing to enforce secure script execution, with ACL-aware permission checks and…

[PoC] Privilege escalation & code execution via LFI in PwnDoC

General-purpose cryptography library implementing SSL/TLS protocols, symmetric/ asymmetric ciphers, message digests, and X.509 certificate handling…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including…


Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Web services framework for building and developing SOAP, RESTful, and CORBA services with support for WS-Security, WS-Trust, and JAX-WS/JAX-RS APIs.

CVE-2022-21660

OpenSSL 1.0.1g source code with CVE-2015-1791 patch, providing SSL/TLS and cryptographic library for secure communications.