
CVE-2026-40579
Advisory for git-js ⌯⌲ 11 mill weekly downloads

Advisory for git-js ⌯⌲ 11 mill weekly downloads
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

Remote Code Execution in DbGate via functionName injection in the loadReader endpoint — CVSS 8.8

[CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

Technical analysis of CVE-2026-52885: a TOCTOU race condition in Notepad++ v8.9.6.2 allowing arbitrary command execution via HMAC integrity bypass.…

The code for personally reproducing the corresponding vulnerability

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

Second CVE still Remote Code Execution

Proof-of-concept exploit for CVE-2026-48800 demonstrating arbitrary code execution in Notepad++ ≤ 8.9.6 via malicious shortcuts.xml. Includes trigger…

CVE-2026-23498 - Shopware Has Improper Control of Generation of Code in Twig rendered views

Detailed CVE-2025-12758 disclosure with PoC demonstrating Unicode variation selector bypass in validator.js isLength(), including root cause…

CVE-2024-4367

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…

CVE-2026-42533 Nginx

A minimal, secure Python interpreter written in Rust for use by AI

Golang Secure Coding Practices guide