
CVE-2026-41940
Redacted cPanel/WHM authentication bypass analysis and authorized checker

Redacted cPanel/WHM authentication bypass analysis and authorized checker

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

Bucky (An automatic S3 bucket discovery tool)

Custom Content Types and Fields plugin for WordPress

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

Repository for CVE-2023-4800 vulnerability.

GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

📬 Simple, private file sharing. Mirror of https://gitlab.com/timvisee/send

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

Public write-up and disclosure timeline for CVE-2026-1769 (Stored XSS in Xerox CentreWare Web)

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

CVE-2026-9848 is an Unauthenticated SQL Injection (SQLi) vulnerability affecting the WP Ticket (Customer Support Ticket System & Helpdesk) plugin for…

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

☣️ This repository contains the description and a proof of concept for CVE-2024-34312

Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for…

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)