
VECTR
Track red and blue team testing activities to measure detection and prevention capabilities across attack scenarios, with campaign management, TTP…

Track red and blue team testing activities to measure detection and prevention capabilities across attack scenarios, with campaign management, TTP…

Microworld Technologies eScan Management Console version 14.0.1400.2281 is vulnerable to a Stored Cross-Site Scripting (XSS) attack.

Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

Proof-of-concept for stored and reflected XSS vulnerabilities in CheckMK Management Web Console versions 1.5.0 to 2.0.0p9, with detailed disclosure…

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file…

Proof-of-concept exploit for CVE-2024-20405 demonstrating stored XSS in Cisco Finesse via RFI in the web-based management interface.

CVE-2026-3171 and CVE-2026-3170 vulnerability disclosure by Archana M

XSS Vulnerability in Rittal

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

In-depth IDOR write-up for Concrete CMS, covering the message_detail endpoint, missing authorization root cause, attack scenarios, impact, and fix.

Educational lab demonstrating CVE-2022-39227 JWT authentication bypass in python-jwt. Step-by-step attack against vulnerable and patched Flask apps…

CEREBRO-RED v2: Advanced LLM Red Team Research Platform with PAIR Algorithm and LLM-as-a-Judge Evaluation

SureTriggers <= 1.0.78 - Authorization Bypass Exploit