
CVE-2026-2472-Vertex-AI-SDK-Google-Cloud
Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Security training for the apps you actually ship. Open your browser and start hacking.

Exploit for CVE-2024-44625 in Gogs 0.13.0, achieving remote code execution via symlink-follow to create a git hook, with reverse and bind shell modes.

Exploit chain for Flowise 3.0.5: unauthenticated account takeover via password-reset token disclosure (CVE-2025-58434) chained to CustomMCP…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

autonomous red teaming platform; multi-agent offensive-security meta-harness

CVE-2026-77276 pre-auth macro RCE via convert-to on Collabora Online

Proof-of-concept exploit for CVE-2026-71981, an insecure deserialization RCE in Cypht. Executes commands and prints output via logout response.…

Exploit for CVE-2026-44402 targeting Voltronic Power SNMP Web Pro 1.1, enabling unauthenticated remote code execution via malicious firmware upload.…

Exploit tool for CVE-2026-82222, an unauthenticated RCE in GiveWP WordPress plugin. Supports single-target and batch exploitation with…

Unauthenticated SQL injection exploit for GLPI versions before 10.0.18, enabling database enumeration, credential extraction, and API token…

Proof-of-concept exploit for CVE-2025-68613, an authenticated remote code execution vulnerability in N8N. Executes arbitrary bash commands on…

Non-destructive detector for unauthenticated RCE in BeyondTrust Remote Support and PRA, chaining argument injection and PostgreSQL escape bypass to…

Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

Proof-of-concept exploit for CVE-2026-7873 in Langflow, allowing authenticated remote code execution via a crafted Bash command.

Proof-of-concept exploit for CVE-2026-10134 in Langflow, allowing authenticated remote command execution via crafted requests.