
CVE-2025-14172-Nuclei-Template
The WP Page Permalink Extension plugin (<= 1.5.4) allows authenticated users with insufficient privileges to trigger the AJAX action…

The WP Page Permalink Extension plugin (<= 1.5.4) allows authenticated users with insufficient privileges to trigger the AJAX action…

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner

Disclosure for CVE-2025-9196

PoC exploit for CVE-2023-5142 targeting H3C GR series routers with an unauthenticated directory traversal vulnerability to extract sensitive…

Proof-of-concept for CVE-2023-36643: an incorrect access control vulnerability in ITB-GmbH TradePro v9.5 that allows remote attackers to enumerate…

IBM i Access Client Solution < 1.1.9.4 - Local server broken access control.

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

CGI Print ENV leaking

CVE-2023-39144 disclosure: cleartext password exposure in Element55 Maketime appliance admin pages, enabling privilege escalation via…

Exploit for CVE-2023-33477, an unauthorized configuration file download vulnerability in Harmonic NSG 9000-6G modulator, allowing remote attackers to…

Samsung Printer SCX-6X55X Improper Access Control

Checks for exposed Redis servers

Best Student Management System v1.0 - Incorrect Access Control - Directory Listing

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

Proof-of-concept exploit for CVE-2020-25747 demonstrating unauthenticated remote access to RTSP and ONVIF services on Rubetek RV-3406/3409/3411…

CVE-2025-29705

Proof-of-concept for CVE-2020-29666: directory listing vulnerability in Lan ATMService M3 ATM Monitoring System 6.1.0 that exposes log files…

School Fees Management System v1.0 - Incorrect Access Control - Directory Listing