
CVE-2025-56815
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Proof-of-concept exploit for CVE-2022-45265 targeting Sourcecodester Sanitization Management System 1.0 via unauthenticated user modification through…

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

The CVE-2024-46982 is cache poisoning of next_js some site have API to load their image

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

reproducing an old istio bug

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Repository contains psexec, which will help to exploit the forgotten pipe

HAProxy-CVE-2023-45539-PoC

SimplCommerce is affected by a Broken Access Control vulnerability in the review system, allowing unauthorized users to post reviews for products…

general purpose workaround for the log4j CVE-2021-44228 vulnerability

Java agent that transforms a vulnerable class to block exploitation of CVE-2024-43044 in Jenkins controllers, with optional forced shutdown on…

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

Script - Workaround instructions to address CVE-2021-44228 in vCenter Server

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates