
CVE-2026-13736
Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

Subdomain takeover vulnerability checker

This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and…

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

CVE-2026-25049

Disclosure for CVE-2025-9196

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Proof-of-concept for CVE-2024-57484: directory listing vulnerability in FoxyProxy extension exposing internal file structure and metadata, enabling…

Best house rental management system Local file contains vulnerability

CVE-2024-12008 information exposure vulnerability in W3 Total Cache

Proof-of-concept exploit for CVE-2021-21234, a directory traversal vulnerability in spring-boot-actuator-logview allowing unauthorized file read via…

Amanda Information Disclosure bug.

Issabel-pbx version 4.0.0-6 contains a Broken Access Control vulnerability that manifests as unauthenticated Directory Listing on the web interface.

Broken Access Control in OpenEyes 3.5.1

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

CVE-2019-19033 description and scripts to check the vulnerability in Jalios JCMS 10 (Authentication Bypass)

[Reserved for CVE-2022-30006]