
DesckVB-RAT
Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Artefacts for blog post on finding CVE-2025-37899 with o3

Artefacts for blog post on finding CVE-2025-37899 with o3

Investigating CVE-2022-36804

An authenticated Remote Code Execution (RCE) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file manager…

CVE-2025-54123 exploit and documentation

Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability in the…

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox…

PoC of CVE-2024-32002 - Remote Code Execution while cloning special-crafted local repositories

Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting

PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5


Microworld Technologies eScan Management Console version 14.0.1400.2281 is vulnerable to a Stored Cross-Site Scripting (XSS) attack.

Exploiting CVE-2016-4657 to JailBreak the Nintendo Switch