

OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

CVE-2025-41646 - Critical Authentication bypass

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

Simple script to exploit open redirection vulnerability in Rockwell ControlLogix 1756-ENBT/A

Real world and CTFs exploiting web/binary POCs.