
CVE-2013-0156
Arbitrary deserialization that can be used to trigger SQL injection and even Code execution

Arbitrary deserialization that can be used to trigger SQL injection and even Code execution

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

Test to validate CVE-2025-7338 https://semgrep.dev/orgs/-/advisories?f=CAAQGRoTCg1jdmUtMjAyNS03MzM4GgAiAA%3D%3D

1C-Bitrix <= 25.100.500 (Translate Module) Remote Code Execution Vulnerability

Full-featured open-source toolkit implementing SSL/TLS protocols and a general-purpose cryptography library, including ciphers, digests, public key…

# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor…

OpenSSL toolkit implementing SSL/TLS protocols and a general-purpose cryptography library with ciphers, digests, public key algorithms, and X.509…

Spring Cloud Gateway远程代码执行漏洞

unzip-stream file write/overwrite vulnerability


Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload

OpenSSL 1.0.1g source code snapshot, providing SSL/TLS and general-purpose cryptography library with ciphers, digests, and X.509 certificate handling.

Fork spring-webmvc 5.3.39 to fix CVE-2024-38816, CVE-2024-38819


Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风…

