
CVE-2025-3776
WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object…

PoC and verification toolkit for CVE-2026-28286, an arbitrary file write vulnerability in ZimaOS, exploiting API misconfiguration to write files…

PoC and detection guide for the critical unauthenticated RCE in IBM Langflow OSS, covering the auto_login token bypass and unsafe /validate/code…

Professional bug bounty report detailing the exploitation of a Blind SSRF vulnerability leading to Shellshock (CVE-2014-6271) remote code execution,…

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

Web vulnerability scanner written in Python3

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

An intentionally designed broken web application based on REST API.

Tests your WAF with +160 payloads


SAML2 Burp Extension

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

A rapid HTTP downgrade smuggling scanner written in Go.