Pinned Loading
- Roundcube-CVE-2025-49113
Roundcube-CVE-2025-49113 PublicProof-of-concept to CVE-2025-49113
- CVE-2026-44789-n8n-PrototypePollution-RCE
CVE-2026-44789-n8n-PrototypePollution-RCE PublicCVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified e2e.
Python
- CVE-2026-53753-Crawl4AI-RCE
CVE-2026-53753-Crawl4AI-RCE PublicCVE-2026-53753 — Crawl4AI <0.8.7 unauthenticated RCE (AST sandbox escape via gi_frame.f_back). Lab + PoC, verified e2e.
Python
- CVE-2026-56121-Feast-Unauth-RCE
CVE-2026-56121-Feast-Unauth-RCE PublicCVE-2026-56121 — Feast <0.63.0 unauthenticated RCE via gRPC registry dill.loads of OnDemandFeatureView UDF (pre-auth). Lab + PoC, verified e2e.
Python
- POC-IngressNightmare-CVE-2025-1974
POC-IngressNightmare-CVE-2025-1974 PublicPython
- POC-CVE-2026-65971
POC-CVE-2026-65971 PublicProof-of-concept and technical write-up for CVE-2026-65971 — SQL injection via the sortDirection Livewire property in power-components/livewire-powergrid (< 6.10.4)
Python 1
Something went wrong, please refresh the page to try again.
If the problem persists, check the GitHub status page or contact support.
If the problem persists, check the GitHub status page or contact support.
Uh oh!
There was an error while loading. Please reload this page.