
Log4j-CVE-2021-44228
Mass scanner for Log4j CVE-2021-44228 vulnerability with Python-based detection and exploit capabilities for automated security testing.

Mass scanner for Log4j CVE-2021-44228 vulnerability with Python-based detection and exploit capabilities for automated security testing.

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute…

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages # Date: 09/06/2025

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Operator Surname

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

Real-world incident response for CVE-2025-55182 (React2Shell) — script injection, server remediation, and post-incident report

This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

AI-driven vulnerability discovery and live validation

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

Zero-day in AppleMediaServices: Bag fetch failure disables Mescal/Absinthe signing. Requests to Apple services proceed unsigned, exposing downgrade,…

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

MeowEye is a real-time scanner for identifying multiple web vulnerabilities in live applications.