
0xMiddleware
CVE-2025-29927: Next.js Middleware Exploit

CVE-2025-29927: Next.js Middleware Exploit
Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Internal Hostname Disclosure Vulnerability

The detection of internal security controls at a company

CVE-2022-23779: Internal Hostname Disclosure Vulnerability

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

A tool to make socks connections through HTTP agents

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

API Scraper Agent for Web API's


