
CVE-2026-53959
4gaBoards < 3.3.9 - User Information Disclosure

4gaBoards < 3.3.9 - User Information Disclosure

Fingerprint OpenAI-compatible LLMs from tokenizer and behavior signals.

Proof of Concept (PoC) for a stack-based buffer overflow in Steghide 0.5.1. Demonstrates how long file paths trigger a crash (DoS) and leak sensitive…

No-dongle, no-root Bluetooth security assessment tool for wireless earbuds affected by the Airoha SDK vulnerability chain (CVE-2025-20700/20701/20702)

Sensitive Information Exposure via assignments in LearnDash.

Poc of SSRF for Request-Baskets (CVE-2023-27163)

Tool to discover paths in web applications

The code for personally reproducing the corresponding vulnerability

Python PoC exploiting CVE-2026-27739 in Angular SSR: header injection via prototype pollution and SSRF chaining to AWS IMDS/GCP metadata for…

CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

CVE-2026-42945 Nginx Rift

A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public…

The modern, high-speed successor to nsec3walker. A specialized NSEC3 forensics engine built in Go for rapid zone harvesting and automated hash…

Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

Proof-of-concept exploit for CVE-2022-36163, a format string vulnerability in pdftoroff hovacui 1.1.0 PDF reader, demonstrating local…