
CVE-2021-20323
Proof-of-concept and analysis for CVE-2021-20323, a reflected XSS vulnerability in Keycloak's clients-registrations endpoint, with exploitation…

Proof-of-concept and analysis for CVE-2021-20323, a reflected XSS vulnerability in Keycloak's clients-registrations endpoint, with exploitation…

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

Free honeypot token scanner for Ethereum, Polygon & Arbitrum. Detect scam tokens before you buy. Instant analysis of smart contracts using 13…

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

Public disclosure and proof-of-concept for CVE-2026-26211, a stored XSS vulnerability in Ekushey Project Manager CRM v5.0, including technical…

Technical analysis and detection guidance for critical unrestricted file upload in Elementor Pro (CVE-2026-32475) leading to remote code execution.

Technical analysis of a reflected XSS vulnerability in the Tag Groups WordPress plugin before 2.2.0, covering root cause, attack flow, impact,…

Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Analysis and reproduction of CVE-2025-57833

Technical analysis and Proof of Concept (PoC) for CVE-2026-49049, an unauthenticated arbitrary file write vulnerability in JoomShaper Helix3 for…

Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

Stored XSS vulnerability disclosure for nirix traq v3.9.0 with PoC, root cause analysis, and mitigation guidance for security researchers and…

Multiple CVEs (CVE-2026-38934, CVE-2026-38935, CVE-2026-38936) discovered in diskover-community including CSRF and XSS vulnerabilities with…

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js