
CVE-2025-53640
Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

Proof-of-concept exploit for CVE-2026-26012, demonstrating an authenticated organization collection permissions bypass and cipher enumeration in…

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

Proof-of-concept exploit for CVE-2024-50633, a Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9–v3.3.2, enabling unauthorized…

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Next generation web scanner

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

Tests your WAF with +160 payloads

WEB SERVICE SECURITY ASSESSMENT TOOL

Hidden parameters discovery suite

Discover hidden parameters in Caido

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Insecure Permissions WeDayCare