
CVE-2025-13407
GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

Automated reconnaissance framework with 17+ modules for subdomain enumeration, directory brute-forcing, JS/link mining, WAF fingerprinting, and…

Lightweight web page change monitor written in Go. Detects updates on target URLs and sends notifications via Telegram or other services, ideal for…

Automated WordPress vulnerability scanner that processes multiple sites concurrently using wpscan, analyzes results, and sends summaries via Telegram.

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username


Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Apache Real Time Logs Analyzer System

A standalone Blind XSS Script.

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

Multi-threaded mass exploiter chaining unauthenticated WordPress file-upload flaws in Super Forms and Elementor Pro to deploy and verify a PHP web…

HPLIP < 3.26.6 — Full admin takeover via PAPPL web interface (no auth). Related to CVE-2026-91097 through CVE-2026-91106 (CVSS 9.3)