
CVE-2025-51864
Proof-of-concept for a reflected XSS vulnerability in AIBOX's chat component, demonstrating JWT token theft and account hijacking via crafted…

Proof-of-concept for a reflected XSS vulnerability in AIBOX's chat component, demonstrating JWT token theft and account hijacking via crafted…

CS50 Cybersecurity final project — Palo Alto OAuth token breach (CVE-2024-3400)

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…

Technical analysis of the cPanel/WHM auth bypass

NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

Responsible disclosure of unpatched vulnerability in FluentCRM by WPManageNinja

Implementation of the Google Zero-Knowledge library for Identity Protocols.


Security Bulletins that relate to Netflix Open Source

Agent Control Protocol (ACP) — Official English specification. Cryptographically verifiable authorization architecture for autonomous AI agents.

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…