
CVE-2026-13736
Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

TEM FLEX-1080/FLEX-1085 1.6.0 log log.cgi Information Disclosure

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Apache Kylin API Unauthorized Access

A specialized vulnerability scanner designed to detect CVE-2024-38526, the Polyfill.io Supply Chain Attack, helping organizations identify and…

mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

Proof-of-concept exploit for CVE-2021-21234, a directory traversal vulnerability in spring-boot-actuator-logview allowing unauthorized file read via…

Amanda Information Disclosure bug.

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

Simple JMX RMI scanning tool

Novel-plus-install-v3.5.3-Druid Unauthorized access

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

Proof-of-concept exploit for CVE-2026-37071: arbitrary file rename in Veno File Manager 4.4.9 enabling privilege escalation to super administrator…

Proof-of-concept for absolute path disclosure in Veno File Manager 4.4.9 via an unauthenticated GET request to a debug script, revealing the server's…

Cachet configuration leak dumper. CVE-2021-39174 PoC.

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

PoC for CVE-2026-56423: MISP deleteSelection broken access control (CWE-862, contributor hard-deletes other orgs' Event Reports/Sharing Groups, CVSS…