
CVE-RUBY
Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO
educationexploitationpayload-development+3

Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO
An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.