
CVE-2026-52886
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)

Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)


Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

PD2229B的43499(ghostlock)可行性研究


Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

Integer overflow in FreeType software, which also affects Chrome

CVE-2026-46242

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

CVE-2026-54597 - Authenticated Time-Based Blind SQL Injection in ITFlow

CVE-2026-54596 - Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration

CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser

Analísis - POC - Mitigación


CVE-2025-70342: Credential Interception via Named Pipe in erase-install