

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

PoC: identify silent security patches before CVE


Integer overflow in FreeType software, which also affects Chrome

Linux 内核升级指南 - 修复 CVE-2026-53359

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser

Analísis - POC - Mitigación

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…



Exploit code for CVE-2022-2588

CVE-2022-39275 Setup and POC