


Multithread Golang application

Reflected Cross-Site Scripting in Snipe-IT CSV Import Workflow




CVE-2022-29359 - School Application System Stored Cross-Site Scripting




CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM

A modern vulnerable web app

CVE-2024-3673 Exploit: Local File Inclusion in Web Directory Free WordPress Plugin ( before 1.7.3 )

Double-free in Apache httpd mod_http2 stream cleanup leading to pre-auth RCE.

Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.

Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)