
CVE-2025-70342
CVE-2025-70342: Credential Interception via Named Pipe in erase-install
exploitationprivilege-escalationvulnerability-analysis

CVE-2025-70342: Credential Interception via Named Pipe in erase-install


OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.



Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

Integer overflow in FreeType software, which also affects Chrome

PD2229B的43499(ghostlock)可行性研究


Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

Dirty COW restricted to shmem in linux kernel

CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser