
CVE-2024-57487-and-CVE-2024-57488
Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

GHSA-4cx5-89vm-833x/CVE-2024-52800

Technical Details and Exploit for CVE-2024-11393

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

Technical Details and Exploit for CVE-2024-11392


Curated repository of vulnerability research write-ups with assigned CVEs, detailing discovered weaknesses, impact, and remediation across various…

Second CVE still Remote Code Execution

CVE-2026-22692 - Critical Twig Sandbox Bypass via collect()->mapInto() allowing RCE/LFI/XXE in October CMS

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

CVE-2026-23498 - Shopware Has Improper Control of Generation of Code in Twig rendered views

CVE-2019-3396 confluence SSTI RCE