
mcpshield
Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)
Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.



CVE-2023-42442 JumpServer Session 录像任意下载漏洞


Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

CVE-2024-26026: BIG-IP Next Central Manager API UNAUTHENTICATED SQL INJECTION

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

A Test API for testing the POC against CVE-2022-1388

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

Code to reproduce the vulnerability individually

The code for personally reproducing the corresponding vulnerability

Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read…

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…
