
CVE-2026-39902
Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

Android netd vulnerability analysis and exploitation research for CVE-2023-40084, focusing on the platform's network daemon.

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

A wrapper around grep, to help you grep for things

Patch for CVE-2018-1000140 in rsyslog's librelp library, fixing a remote code execution vulnerability in the reliable event logging protocol…

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

Documenting the internals of Fingerprint Pro's commercial agent, not the open-source FingerprintJS library

Mind-Maps of Several Things

CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.

Fuzzing Framework for Modules in Apache HTTPD Server

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

BlockChain Security Construction

NCC Code Navigator

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Evidence-driven C/C++ vulnerability remediation pipeline + http-parser case study (CVE-2024-22019-class). Python core, React 19 console, 17-test…

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)