
kubesec
Security risk analysis for Kubernetes resources

Security risk analysis for Kubernetes resources

Subdomain takeover vulnerability checker

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

WP SuperBackup <= 2.3.3 - Missing Authorization to Unauthenticated Back-Up File Download

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

BeHat Configuration file leaking

This tool is used to find php info page

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

Password decryption tool for the McAfee SiteList.xml file

Supermicro IPMI/BMC Cleartext Password Scanner

Proof-of-concept for CVE-2025-25279: path traversal in Mattermost Boards allows arbitrary file read via crafted import archive and board duplication.

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

Drupal CVE-2024-45440

Vulnerability Description

POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure

Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file