
CVE-2026-64849.yaml
Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC




A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Proof-of-concept exploit for CVE-2022-46364, an Apache CXF SSRF vulnerability enabling arbitrary file reads and internal network probing via crafted…

This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an…

CVE-2012-1823 - PHP CGI Argument Injection Remote Code Execution (RCE)

Proof-of-concept demonstrating an authorization bypass in Traefik's Kubernetes Gateway provider (CVE-2026-54761) via a crossProviderNamespaces…

Root-Level RCE via OS Command Injection in Ivanti Sentry

Security awareness training tool for authorized phishing simulations and internal IT audits

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

The code for personally reproducing the corresponding vulnerability

