
truegaze
Static analysis tool for Android/iOS apps focusing on security issues outside the source code

Static analysis tool for Android/iOS apps focusing on security issues outside the source code

The format of various s3 buckets is convert in one format. for bugbounty and security testing.

Frog CMS 0.9.5 has an Upload > vulnerability that can create files via > /admin/?/plugin/file_manager/save

Proof-of-concept exploit for CVE-2026-37071: arbitrary file rename in Veno File Manager 4.4.9 enabling privilege escalation to super administrator…

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract…

Security risk analysis for Kubernetes resources

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

Password decryption tool for the McAfee SiteList.xml file

Checks a shared hosting environment for CVE-2017-9798

React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the…

Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.

BeHat Configuration file leaking

Best house rental management system Local file contains vulnerability

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

This tool is used to find php info page

eBPF + nftables + DNS proxy egress enforcement for GitLab Runner CI/CD job containers — community edition data plane https://leitwacht.eu/

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)