
CVE-2026-56292-AcyMailing-SQLi
CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

Exploit for CVE-2026-41940, an unauthenticated authentication bypass in cPanel/WHM that grants root-level WHM access via CRLF session injection, with…

Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom…

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

Exploits CVE-2026-39987 pre-auth RCE in Marimo <0.23.0 by connecting to the unauthenticated /terminal/ws WebSocket. Supports arbitrary command…

GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)


Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code…

CVE-2017-9805-Exploit


MCP environment-variable blocklist bypass leads to unauthenticated RCE in Flowise 3.1.1

Missing Authorization in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…