
CVE-2026-37073
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from…

Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from…

Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated…

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract…

Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an…

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

Penetration tests guide based on OWASP including test cases, resources and examples.

AzureGoat : A Damn Vulnerable Azure Infrastructure

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

GCPGoat : A Damn Vulnerable GCP Infrastructure

Content hijacking proof-of-concept using Flash, PDF and Silverlight

Default signature for Jaeles Scanner

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

Checklist and tools for increasing security of Apache Airflow


A fix for CVE-2019-11358 (prototype pollution in jquery)

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

Reproducer for CVE-2026-40022: Apache Camel camel-platform-http-main authentication bypass on non-root context paths