
DBScanner
未授权访问+弱口令批量检测

未授权访问+弱口令批量检测

POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure

VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

Apache Kylin API Unauthorized Access

Proof-of-concept for CVE-2025-25279: path traversal in Mattermost Boards allows arbitrary file read via crafted import archive and board duplication.

Proof-of-concept exploit for CVE-2021-21234, a directory traversal vulnerability in spring-boot-actuator-logview allowing unauthorized file read via…

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract…

Novel-plus-install-v3.5.3-Druid Unauthorized access

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Proof-of-concept for absolute path disclosure in Veno File Manager 4.4.9 via an unauthenticated GET request to a debug script, revealing the server's…

Cachet configuration leak dumper. CVE-2021-39174 PoC.

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from…

CVE-2026-55726: Publicly Listable Azure Blob Storage Container (device logs) - Gardyn (ICSA-26-183-03)