Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
Langflow 1.9.0 - RCE
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
Zero-downtime livepatch for CVE-2026-53359 (Januscape), a guest-to-host escape vulnerability in the KVM/x86 shadow MMU.
🐳 docker-compose 를 활용한 취약한 환경 구성 및 검증 (vulhub 한글판)
Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287
CVE-2026-42980 PUBLIC EXPLOIT + RESEARCH
CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell verification. For authorized security testing only.
Next.js / RSC - Unauthenticated RCE (React2Shell) (CVE-2025-55182)
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution
ProtonVPN v4.4.1 - Unquoted Service Path
WordPress Bricks Builder Theme - RCE
iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter
Discuz! X5.0 - Authentication Bypass
Tenable Nessus 10.12.1 - SQL Injection
MCPJam Inspector - Remote Code Execution