
CVE-2022-36539
Insecure Permissions WeDayCare

Insecure Permissions WeDayCare

Http request smuggling vulnerability scanner

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

Burp Suite extension that finds exposed admin panels and login pages of web applications and infrastructure. 1,000+ payloads, OWASP WSTG-CONF-05.

Zed Attack Proxy Scripts for finding CVEs and Secrets.

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

A Test API for testing the POC against CVE-2022-1388

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

Spring-Cloud-Gateway-CVE-2022-22947

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Structured playbook for integrating threat modeling into product security, covering stakeholder buy-in, organizational embedding, training, process…

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具