
CVE-2025-12720
g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Proof-of-concept demonstrating information leakage in OneinStack deployment tool via exposed endpoints (phpinfo.php, xprober.php, ocp.php) leading to…

Proof-of-concept exploit for CVE-2021-45232, an unauthorized access vulnerability in Apache APISIX Dashboard allowing export/import of admin…

Advisory detailing active debug code in production Gardyn Home Kit cloud API, exposing development endpoints and embedded credentials, with…

CasaOS expose multiple unauthenticated API endpoints that allow remote disclosure of sensitive configuration files and system debug information

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.