
A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands,…

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

ARPrice <= 4.0.3 - Authenticated (Subscriber+) PHP Object Injection

MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS

Finding Java/C# gadget chains with CodeQL


POC for RCE vulnerability in ParseExcel library, and ParseXLSX too, as a depending library

CVE-2021-26084,Atlassian Confluence OGNL注入漏洞

CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!

CVE-2018-6574 POC : golang 'go get' remote command execution during source code build

CVE-2025-55182 检测方式和攻击利用

CVE-2022-22947批量

PoC for CVE-2026-12191

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction