patched ffmpeg-tools for jellyfin to patch CVE-2026-8461 aka PixelSmash
Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation harness. Detection and prevention only — no exploit code. TLP:CLEAR.
PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.
CVE-2026-0073-Android-ADBD-bypass-POC汉化版
CVE-2026-48907 is a CVSS 10.0 pre-auth RCE in Joomla Content Editor affecting all versions ≤ 2.9.99.4. The Grayxploit team breaks down the 3-weakness chain — missing auth, no extension validation, and an unsafe upload flag — that lets attackers pop a shell in 3 HTTP requests.
Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061
WP Full Stripe Free <= 8.4.3 - Missing Authorization
Out-of-bounds array read in LibRaw
CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research
Flowiseai Flowise Auth Bypass Vulnerability Proof of Concept
CVE-2026-12415-or-CVE-2026-12416.py
Cacti <= 1.2.30
Ghost CMS Content API Blind SQL Injection
Plane’s V2 asset subsystem trusted workspace slugs and asset UUIDs without enforcing the right membership checks, which let one authenticated user read, copy, delete, and overwrite assets in other workspaces.