
CVE-2026-64849.yaml
Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4


peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

CVE-2025-29927: Next.js Middleware Exploit




CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

The code for personally reproducing the corresponding vulnerability

CVE‑2025‑55182 Detection


Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers




Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…