
CVE-2021-32819
SquirrellyJS mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration…

SquirrellyJS mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration…

PhantomJS uses internal module: webpage, to open, close, render, and perform multiple actions on webpages, which suffers from an arbitrary file read…

There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions …

Test for CVE-2000-0649, and return an IP address if vulnerable

exim use after free exploit and detection

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access…

PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes…

Reverse engineering of the engine powering the PriPara games on arcade.


CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

Internal Hostname Disclosure Vulnerability

CVE-2014-3341 exploit

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…


The detection of internal security controls at a company