
MAL-012
MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server

MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server
CVE-2025-54100 (CVSS 7.8 High) is a command injection vulnerability in the Invoke-WebRequest cmdlet of Windows PowerShell 5.1. It arises from…

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers…

CSRF vulnerability in FD602GW-DX-R410 router allows remote attackers to reboot the device via a crafted POST request to /boaform/admin/formReboot…

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms…

CVE-2026-34038: Authenticated Remote Command Injection in Coolify

CVE-2025-67511: Tricking a Security AI Agent Into Pwning Itself

Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption


Sensitive Data exposure


The Online Diagnostic Lab Management System has a security problem called Cross-Site Scripting (XSS) in the Borrower section.

CVE-2026-30691: Stored Cross-Site Scripting (XSS) in @cyntler/react-doc-viewer

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)