


Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…

Audits Windows security settings against CIS, Microsoft, STIG, and BSI baselines, scores compliance, and applies hardening changes via registry or…


CVE-2026-54520 / GHSA-cm8g-8jfq-887p: ai-agent-automation workflow path traversal advisory landing page

Senior-CSO security audit skill for vibe-coded apps. 22-check audit anchored to real 2026 incidents (Moltbook, Lovable CVE-2025-48757). Drop-in…

Authenticated IDOR / Broken Access Control in Tutor LMS Plugin

Nuclei Templates Collection

Writeup of a Denial of Service vulnerability in the vBulletin 3.8.7 friends list.

Event monster <= 1.4.3 - Information Exposure Via Visitors List Export

School Fees Management System v1.0 - Incorrect Access Control - Directory Listing

Best Student Management System v1.0 - Incorrect Access Control - Directory Listing

Customer Support System 1.0 - Directory Listing

Labelgrup Fixer for CVE-2020-5250 vulnerability

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container