
CVE-2026-38360
Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

A drop-in fix for CVE-2023-29689 - SSTI in PyroCMS, via a custom Twig Sandbox implementation



Technical analysis of CVE-2025-68613, a critical Expression Injection vulnerability in n8n that allows authenticated attackers to achieve Remote Code…

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote…

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a craftedpayload to the…

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

CVE-2024-44337 POC The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. which allowed a…

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

PHPMailer < 5.2.18 Remote Code Execution Exploit

Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

PHP CGI Argument Injection.

CVE-2026-34038: Authenticated Remote Command Injection in Coolify

Proof of concept for CVE-2022-36532: RCE via File Upload in Bolt CMS 5.1.12 and below.