


Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from…

The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

A collection of web pages vulnerable to SQL injection flaws

Brosec - An interactive reference tool to help security professionals utilize useful payloads and commands.

Disrupt WAF by abusing SSL/TLS Ciphers

PoC for CVE-2026-8023: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')


Fast HTTP enumerator

YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…


Detect potentially malicious PHP files


A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.