
CVE-2026-55726
CVE-2026-55726: Publicly Listable Azure Blob Storage Container (device logs) - Gardyn (ICSA-26-183-03)

CVE-2026-55726: Publicly Listable Azure Blob Storage Container (device logs) - Gardyn (ICSA-26-183-03)

Perforce security research and tools - CVE-2026-6043

Issabel-pbx version 4.0.0-6 contains a Broken Access Control vulnerability that manifests as unauthenticated Directory Listing on the web interface.

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

Proof-of-concept for CVE-2021-40352 in OpenEMR 6.0.0, demonstrating unauthorized access to patient messages via parameter manipulation in…

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from…

CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion

Broken Access Control in OpenEyes 3.5.1

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

Drupal CVE-2024-45440

This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and…

This tool is designed to scan and identify whether a website has an exposed ".git" directory, which may contain sensitive information such as source…

CVE-2025-69727

Privilege Escalation in Teachers Record Management System using CodeIgnitor

Python scanner for TestRail servers vulnerable to CVE-2021-40875

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract…

Proof-of-concept for absolute path disclosure in Veno File Manager 4.4.9 via an unauthenticated GET request to a debug script, revealing the server's…