
Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC
In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…



CVE-2024-46383


CVE-2023-49965 | SpaceX / Starlink Router Gen 2 XSS

An issue in Orbe ONetView Roteador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status…

A PoC for CVE-2025-67445

Security advisory for CVE-2025-65855 - Multiple vulnerabilities in HelpFlash IoT OTA update mechanism

CVE-2025-41646 - Critical Authentication bypass

Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

CVE-2020-25749

CVE-2020-25747

TP-LINK Multiple HTML Injection Vulnerabilities

CSRF leads to change the password for "WLAN SSID"

Bitcoin Cryptanalysis: CVE-2025-27840 Vulnerability in ESP32 Microcontrollers Puts Billions of IoT Devices at Risk via Wi-Fi & Bluetooth