
agentsid-scanner
Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Awesome information for WebSockets security research

PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.

Cisco ASA Software and ASDM Security Research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)

CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

Advanced security research on CVE-2025-55182 (React2Shell). Features an exploitation framework with 6 functional impact scenarios (RCE to Secret…

Unified Security Research Tool

More exploit-focused; great for security research repos.

The Online Diagnostic Lab Management System has a security problem called Cross-Site Scripting (XSS) in the Borrower section.

Security Advisory – CVE-2025-65300

ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - Security flaw allowing authenticated users with Contributor-level access to…

CVE-2025-45407: Multiple XSS Vulnerabilities in DiscoveryNG v6.0.8 Hotfix 2 Discovered by: YallaSec Security Research Team CVE ID: CVE-2025-45407…

MAL-003: Groovy Security Bypass and Stored XSS in Apache OfBiz