
CVE-2026-64849.yaml
Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4


Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

CVE-2025-29927: Next.js Middleware Exploit



Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls


Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

A basic PoC leak for CVE-2021-28663 (Internal of the Android kernel backdoor vulnerability)

Test for CVE-2000-0649, and return an IP address if vulnerable

Script fo testing CVE-2000-0649 for Apache and MS IIS servers