
CVE-2026-13158
Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512


CVE-2026-39259

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.


A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)


Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…


Bookea-tu-Mesa is vulnerable to SQL Injection

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package


Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…