
CVE-2024-10924
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass

Simple poc of CVE-2018-8353 Microsoft Scripting Engine Use After Free

Chevereto reflected XSS in Website Name - 1.0.0 - 1.1.4 Free, <= 3.13.5 Core

SolarWinds Serv-U CVE-2026-28318: unauthenticated Content-Encoding: deflate crash. Root-cause analysis (invalid free of an interior pointer -> heap…

WP Full Stripe Free <= 8.4.3 - Missing Authorization

Chevereto - 1.0.0 Free - 1.1.4 Free, 3.13.4 Core, Remote Code Execution

Pexels: Free Stock Photos <= 1.2.2 - Authenticated (Contributor+) Arbitrary File Upload

Cookie Information | Free GDPR Consent Solution <= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update

Two security issues identified in Sn1per v9.0 free version by XeroSecurity

An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown…

Free MP3 CD Ripper 2.6 版本中存在栈缓冲区溢出漏洞 (CVE-2019-9766),远程攻击者可借助特制的 .mp3 文件利用该漏洞执行任意代码。

Looking into the memory when sshd 9.1p1 aborts due to a double free bug.

UxPlay version 1.72 contains a double free vulnerability in its RTSP request handling logic.

Chevereto stored XSS in profile page - 1.0.0 - 1.1.4 Free, <= 3.13.5 Core

Chevereto downgrade attack - 1.0.0 - 1.1.4 Free, <= 3.13.5 Core

My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection

Double Free

CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)