
CVE-2026-33267-PoC
CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4


Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

CVE-2025-29927: Next.js Middleware Exploit



Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

The detection of internal security controls at a company

CVE-2026-25049

Test for CVE-2000-0649, and return an IP address if vulnerable

Script fo testing CVE-2000-0649 for Apache and MS IIS servers

CVE‑2025‑55182 Detection


Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.


Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…