
CVE-2022-36539
Insecure Permissions WeDayCare

Insecure Permissions WeDayCare

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

SQL Injection in 3CX CRM Integration

Authenticated WordPress IDOR exploit for CVE-2026-12400; enumerates FlowForms REST form IDs and modifies form content or hijacks email notifications.

RAGFlow 三洞审计工具 (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286)

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Zap Extension for collaboration in Faraday

Scanner: CVE-2026-42208 LiteLLM SQL Injection — Python scanner for BerriAI LiteLLM proxy instances

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Proof-of-concept exploit for CVE-2026-35045, a broken object-level authorization vulnerability in Tandoor Recipes, demonstrating unauthorized recipe…

PortSwigger Burp Plugin for the Log4j (CVE-2021-44228)

Proof-of-concept for CVE-2025-63406 in GroupOffice, demonstrating API-based object manipulation and authentication flow for vulnerability analysis…

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

The code for personally reproducing the corresponding vulnerability

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

FOSSBilling CVE-2026-53647 & CVE-2026-53646 PoC — Unauthenticated API key disclosure & password reset token reuse

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.