
cve-2025-4615
cve-2025-4615 poc & deep dive

cve-2025-4615 poc & deep dive
Advisory for textract ⌯⌲ 15 000 weekly downloads

Demonstrates a stored XSS vulnerability in lunary-ai/lunary's Analytics component, where unsanitized NEXT_PUBLIC_CUSTOM_SCRIPT injection leads to…

The code for personally reproducing the corresponding vulnerability


Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228

CVE-2026-22692 - Critical Twig Sandbox Bypass via collect()->mapInto() allowing RCE/LFI/XXE in October CMS

Second CVE still Remote Code Execution

CVE-2023-30253 — Dolibarr ERP/CRM 17.0.0 RCE via PHP code injection (exploit educativo)

All stages of exploring the polkit CVE-2021-4034 using codeql

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Advisory for node-tesseract-ocr ⌯⌲ 50 000 weekly downloads

Provides a ctypes wrapper for the splice syscall to enable exploitation of CVE-2026-31431 on Python versions below 3.10, tested on Python 3.7.3.

PoC de CVE-2026-0848: validacion de entrada indebida en NLTK que permite ejecucion de codigo via StanfordSegmenter.

Proof-of-concept for CVE-2025-60655: Remote Code Execution via unrestricted file upload bypassing client-side JavaScript validation, enabling…

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

Advisory for pdf-image ⌯⌲ 10 000 weekly downloads

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…