webverse-pro 40
- SQL Injection Leads to Internal Service Exposure via SSRF | Probed
- Prompt Injection Leads to Remote Code Execution | Plotted
- PHP Object Injection Leads to Arbitrary File Write | Archived
- Server-Side Includes Injection Leads to Remote Code Execution | Tockerry
- Reflected XSS via Attribute Injection | Echoed
- FFmpeg Argument Injection Leads to Arbitrary File Read | Splice
- LDAP Injection Leads to Authentication Bypass and Blind Secret Extraction | Bound
- ZIP Slip Leads to Arbitrary File Write | Zippy
- AI Prompt Bypass Exposes Restricted Production Secret | Indexed
- Broken Access Control Leads to Account Takeover | Granted
- Weak OTP Verification Leads to Account Takeover | Comical
- Prompt Injection Leads to Command Execution | Shelled
- Prompt Injection Leads to Secret Disclosure | Statica
- Exposed Git Repository Leads to Header-Based Admin Bypass | Packed
- SQL Injection Exposes API Credentials | CarCloppin
- JWT Algorithm Confusion Leads to Platform Admin Access | Hookery
- Path Traversal Leads to Arbitrary File Read | Ohmly
- XXE Leads to Local File Disclosure | Chainline
- Client-Side Price Tampering Leads to Unauthorized Purchase | Ligature
- Exposed Admin Route and Default Credentials Lead to Staff Panel Access | Powerpopped
- Prompt Injection Leads to Internal Secret Disclosure | Snobble
- SQL Injection Exposes Internal Vault Secret | LuggageLift
- Prototype Pollution Leads to XSS | Subtracted
- Race Condition Leads to Like Counter Manipulation | CatTrap
- Blind Command Injection via GraphQL Host Checks | WorldWeb
- Parameter Pollution Leads to Checkout Abuse | Unsoakable
- Server-Side Template Injection Leads to Arbitrary File Read | HammerHopper
- Cross-Site Request Forgery Leads to Account Takeover | Crossed
- Command Injection Leads to Remote Code Execution | TheFallen
- Stored XSS Leads to Session Hijacking | DillyDent
- Path Traversal Leads to Access Control Bypass | Gassed Up
- SVG XXE Leads to Local File Disclosure | Educated
- Insecure Deserialization Leads to Dealer Portal Access | Scooot
- Information Disclosure via Exposed Git Repository | GamedYourself
- Password Reset Poisoning to Twig SSTI RCE | Inked
- JWT Algorithm Confusion Leads to Privilege Escalation | Bomb Threat
- Locked - Exposed Git Repository to Authentication Bypass | Locked"
- KrissCut — SQL Injection | KrissCut
- MooKoo — Server-Side Template Injection to RCE | Mookoo
- Blind Remote Code Execution via ExifTool CVE-2021-22204 | The Oak