
CVE-2026-54390
CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1

CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1

Cisco is aware of a potential vulnerability. Cisco is currently investigating and will update these details as appropriate as more…

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

Hustle Plugin <= 7.8.3 contains hardcoded HubSpot API credentials in inc/providers/hubspot/hustle-hubspot-api.php

Propovoice <= 1.7.6.7 - Unauthenticated Arbitrary File Read

CVE-2025-20393

Details for disclosing CVE-2019-13027

RSVPMarker <= 10.6.6 - Unauthenticated SQL Injection

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

Proof-of-concept exploit for a reflected XSS vulnerability in the Groundhogg WordPress plugin, demonstrating unauthenticated script injection via…

cve-2023-22515的python利用脚本

A CSRF POC for Updating the Profile of a Hospital leading to Account Takeover

CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook

Steam Client Service Local Privilege Escalation Vulnerability

Tools and Techniques for Red Team / Penetration Testing

Trying to tame the three-headed dog.

Kerberos relaying and unconstrained delegation abuse toolkit

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).