Contact Form by Supsystic versions 1.7.36 and below server-side template injection exploit that achieves remote code execution...
This script is a Python-based proof of concept exploit targeting a deserialization vulnerability in Oracle WebLogic Server's WLS-WSAT component. Th...
This Metasploit auxiliary module is designed to detect a vulnerability in strongSwan's EAP-TTLS implementation, identified as CVE-2026-25075. The i...
ThingsBoard IoT Platform version 4.2.0 suffers from a server-side request forgery vulnerability...
NocoBase versions 2.0.27 and below VM sandbox escape exploit...
The Chartify WordPress Chart plugin contains a missing authentication vulnerability in all versions up to and including 3.5.9. The plugin registers...
Exim versions 4.87 through 4.91 improper recipient-address validation remote command execution exploit...
The Apache Airflow Databricks Provider package disables TLS certificate verification when communicating with the Kubernetes API server during feder...
WordPress CatFolders plugin versions 2.5.2 and below suffer from a remote SQL injection vulnerability...
There is an unauthenticated path traversal in dash-uploader versions 0.1.0 through 0.7.0a2 allowing arbitrary file write, leading to but not limite...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.