
CVE-2026-44401
Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.




PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

Proof of concept for CVE-2022-36234

Exploit code for CVE-2022-2588

Integer overflow in FreeType software, which also affects Chrome

CTFs are fun, but what about exploiting a real bug?

exploit for CVE-2022-2588

Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701

Dirty COW restricted to shmem in linux kernel