

CVE-2026-54596 - Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration

PoC for CVE-2022-23614 (Twig sort filter code execution/sandbox bypass)

CVE-2022-39275 Setup and POC

CVE-2013-2028 python exploit


CVE-2026-54597 - Authenticated Time-Based Blind SQL Injection in ITFlow

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field


OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.



Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

Integer overflow in FreeType software, which also affects Chrome


Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.