

This script exploits the CVE-2024-40094 vulnerability in graphql-java

[CVE-2016-4014] SAP Netweaver AS JAVA UDDI Component XML External Entity (XXE)

CVE-2023-23752 nuclei template

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

SQL Injection in 3CX CRM Integration

Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。




Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

Spring-Cloud-Gateway-CVE-2022-22947

Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

一个由AI生成的漏洞验证应用

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…
