
CVE-2022-24112-POC
Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Proof-of-concept exploit and advisory for CVE-2025-43921, an authentication bypass in GNU Mailman 2.1.39 that allows unauthenticated creation of…

Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

Responsible disclosure of unpatched vulnerability in FluentCRM by WPManageNinja

HardeningKitty - Checks and hardens your Windows configuration

Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.

Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…