
CVE-2023-23138
short view of ruby on rails properties misconfiguration

short view of ruby on rails properties misconfiguration

A critical access control vulnerability in locally deployed Pro-Bit application in versions less than v1.77.4 allows unauthenticated attackers to…

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

CVE-2026-25049

Proof-of-concept exploit for CVE-2023-36144 demonstrating unauthenticated backup file download on Intelbras SG 2404 MR L2+ switch, exposing device…

[CVE-2021-3019] LanProxy Directory Traversal

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

Traveller is an Easy Linux machine featuring a Joomla 4.2.7 travel booking website vulnerable to CVE-2023-23752, an unauthenticated REST API…

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

CVE-2021-42671 - Broken access control vulnerability in the Engineers online portal system.

Sensitive Data exposure

Best house rental management system Local file contains vulnerability

Cloud Templates & Patterns collection <= 1.2.2 - Sensitive Information Exposure via Log File