
CVE-2023-32117
Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

CVE-2023-23752 nuclei template

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Insecure Permissions WeDayCare

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

SQL Injection in 3CX CRM Integration

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

Maryam: Open-source Intelligence(OSINT) Framework

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.