
CVE-2026-56121-Feast-Unauth-RCE
CVE-2026-56121 — Feast <0.63.0 unauthenticated RCE via gRPC registry dill.loads of OnDemandFeatureView UDF (pre-auth). Lab + PoC, verified e2e.

CVE-2026-56121 — Feast <0.63.0 unauthenticated RCE via gRPC registry dill.loads of OnDemandFeatureView UDF (pre-auth). Lab + PoC, verified e2e.

Checker and fixer for all 13 vulnerabilities in the Next.js May 2026 security release (CVE-2026-23870)

Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536,…

CVE-2026-38165 (SSTI)

CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit

React2Shell Scanner (CVE-2025-55182 & CVE-2025-66478)

CVE-2025-31722 — Jenkins Templating Engine RCE



CVE-2025-64087 (SSTI)


CVE-2025-55182 检测方式和攻击利用

This POC demonstrates CVE-2025-55182 using actual `[email protected]` vulnerable code.

Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action


A drop-in fix for CVE-2023-29689 - SSTI in PyroCMS, via a custom Twig Sandbox implementation
