
CVE-2021-21234
Directory traversal vulnerability in the spring-boot-actuator-logview library

Directory traversal vulnerability in the spring-boot-actuator-logview library

HAProxy-CVE-2023-45539-PoC

Apache Kylin有一个restful api会在没有任何认证的情况下暴露配置信息

Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

CSRF allows to Add Network Traffic Control Type Rule



The CVE-2024-46982 is cache poisoning of next_js some site have API to load their image

Ektron Content Management System (CMS) 9.20 SP2, remote re-enabling users (CVE-2018–12596)

Chevereto downgrade attack - 1.0.0 - 1.1.4 Free, <= 3.13.5 Core

cve-2023-2245

PoC CVE-2024-7646

YARPP <= 5.30.10 - Missing Authorization

CVE-2024-34221 | Insecure pemission

AdmirorFrames Joomla! Extension < 5.0 - HTML Injection

Solar Appscreener XXE

SimplCommerce is affected by a Broken Access Control vulnerability in the review system, allowing unauthorized users to post reviews for products…