

The CVE-2024-46982 is cache poisoning of next_js some site have API to load their image

HAProxy-CVE-2023-45539-PoC


Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Axigen WebAdmin Improper Access Control Vulnerability

Drag and Drop Multiple File Uploader PRO - Contact Form 7 v5.0.6.1 Path Traversal (CVE-2023-1112)

PoC CVE-2024-7646



Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update


WP Full Stripe Free <= 8.4.3 - Missing Authorization

Tiny File Manager v2.4.7 and below are vulnerable to Cross Site Scripting

cve-2023-2245

Chevereto downgrade attack - 1.0.0 - 1.1.4 Free, <= 3.13.5 Core
