
CVE-2026-64849.yaml
Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

CVE-2023-23752 nuclei template

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

Insecure Permissions WeDayCare

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR