


Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)

PD2229B的43499(ghostlock)可行性研究


Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

CVE-2013-2028 python exploit

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

Kernel exploit for Xbox SystemOS using CVE-2024-30088

CVE-2025-70342: Credential Interception via Named Pipe in erase-install

OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.

Proof of Concept for CVE-2023-38434