CVE-2026-54121 - Draft
Security Advisory for CVE-2026-51565
Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.
Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems
Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.
Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.
7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap
PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)
CVE-2026-54900, CVE-2026-54902 - Draft
CVE-2026-50522 PoC
CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web request yields a privileged NTLMv2 hash. Advisory SNWLID-2021-0003.
CVE-2021-3262 - Blind SQL Injection in the editOEN parameter of TripSpark VEO Transportation / NovusEDU. Unauthenticated, internet-facing. Payloads, annotated requests, and evidence.
CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in 1.2.18.
CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor report. Fixed in 1.0.0.9.74.
🚀 CVE-2026-31431 - Linux Kernel AF_ALG + splice() Privilege Escalation Exploit (Zero-Day → Root Persistence)
CVE-2026-61946: Unauthenticated IDOR in Easy Appointments <= 3.12.27
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.