
firebase
Exploiting misconfigured firebase databases

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

Content hijacking proof-of-concept using Flash, PDF and Silverlight

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

ActionScript Proof of Concept to perform cross-domain reads

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…


CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

Event monster <= 1.4.3 - Information Exposure Via Visitors List Export

WP SuperBackup <= 2.3.3 - Missing Authorization to Unauthenticated Back-Up File Download

CVE-2023-28432 MinIO敏感信息泄露检测脚本

Proof-of-concept for CVE-2025-25279: path traversal in Mattermost Boards allows arbitrary file read via crafted import archive and board duplication.

trellix DLP Bypass

CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion