
UserLAnd
Main UserLAnd Repository

Main UserLAnd Repository

CVE-2026-77818 - Yordam Kütüphane Otomasyon Sistemi - Üç ayrı noktada yansıtılmış HTML enjeksiyonu, form action ele geçirme ve kimlik bilgisi…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Proof-of-concept exploit and advisory for CVE-2024-36058, a time-based blind SQL injection in Koha Library Software's opac-sendbasket.pl, enabling…

Advisory and proof-of-concept for CVE-2024-36057, an authenticated OS command injection in Koha Library Software, demonstrating arbitrary command…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Application Security Verification Standard

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

A security auditor for Tailscale configurations. Scans your tailnet for misconfigurations, overly permissive access controls, and security best…

Stored XSS via Location Title in DPCalendar Free

Web and mobile application security training platform

Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

⭐⭐ Join us at SNIA SDC for the SMB3 IO Lab (September 28 - October 1, 2026), see upcoming Interoperability Events

Exploits CVE-2026-9198 in Langflow to execute arbitrary bash commands on target instances via a crafted URL parameter.

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Linux application sandboxing and distribution framework

Proof-of-concept exploit for CVE-2026-73570, demonstrating SMTP command injection via crafted RCPT TO header to trigger service status changes.

Xyntia, the black-box deobfuscator