

tac_plus Pre-Auth Remote Command Execution Vulnerability (CVE-2023-45239 & CVE-2023-48643)

Reflected Cross-Site Scripting in Snipe-IT CSV Import Workflow



marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability


CVE-2025-68613


CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)

Cross Site Request Forgery (CSRF) in Commercify v1.0




Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…