
bash-apocalypse
Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)


Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices.…

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

IBM i Access Client Solution < 1.1.9.4 - Local server broken access control.

Checks for exposed Redis servers

CVE-2025-29705

A static + runtime security scanner for MCP (Model Context Protocol) servers

TOTOLINK-A702R-V1.0.0-B20161227.1023 Directory Indexing Vulnerability