Recent Advisories

Severity ID Title Vendor Product Date Type
NONE 420BEB65-BD63-

Exploit for CVE-2026-26897_420BEB65-BD63-521E-90B1-5065E05B96C0

EcoOnline EHS Android โ€” Deep Link Validation Bypass โ†’ WebView Open Redirect CVE-2026-26897 Public disclosure / advisory for CVE-2026-26897, a deep ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 PACKETSTORM:222614

๐Ÿ“„ MCPJam Inspector 1.4.2 Command Injection_PACKETSTORM:222614

This is an advanced Python proof of concept for CVE-2026-23744 demonstrating command injection through a vulnerable MCP API endpoint, leading to re...

N/A N/A PACKETSTORM
CRITICAL 9.8 7FE5A510-990A-

Exploit for Prototype Pollution in Cure53 Dompurify_7FE5A510-990A-5CCB-9427-6AA5D7B10937

No description provided...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 393A755A-8E32-

Exploit for Stack-based Buffer Overflow in Microsoft_393A755A-8E32-59DA-B6AC-2DE1A68B3BB0

LongLogon ยท CVE-2026-41089 LongLogon is an unauthenticated, non-destructive precondition checker for CVE-2026-41089, a pre-auth stack buffer overfl...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 472EEC26-F9C7-

coruna_472EEC26-F9C7-50CA-A4D6-2E1879CAC2F3

iOS Orchestrator โ€” Coruna Web server, C2 listener, and interactive shell for the Coruna exploit chain CVE-2024-23222. Targets Safari on iOS 13โ€“17.2...

N/A N/A GITHUBEXPLOIT
NONE PACKETSTORM:222620

๐Ÿ“„ Gogs Git Rebase Argument Injection / Remote Code Execution_PACKETSTORM:222620

This Metasploit module exploits an argument injection vulnerability in the pull request merge flow of Gogs versions less than or equal to 0.14.2 an...

N/A N/A PACKETSTORM
CRITICAL 9.8 93EFFA1D-01DF-

Exploit for Eval Injection in Geoserver_93EFFA1D-01DF-57C9-9826-139DBF9FD985

CVE-2024-36401 โ€” Unauthenticated RCE in GeoServer A complete, reproducible study of CVE-2024-36401, an unauthenticated remote code execution flaw i...

N/A N/A GITHUBEXPLOIT
NONE 8D02FC42-E11E-

ParamStriker_8D02FC42-E11E-5436-870C-E4CD77B99D8D

ParamStriker Offline JSON & Query Parameter Exploit Framework by Mohnad Alshobaili ยท X: @Mohnad ParamStriker is a offensive, offline payload-genera...

N/A N/A GITHUBEXPLOIT
NONE D2A2BDA2-A827-

Exploit for CVE-2026-35904_D2A2BDA2-A827-5C81-ACD9-A68148EC42CC

T3 Technology CPE โ€” Security Advisories Multiple critical vulnerabilities discovered in T3 Technology CPE ONU/Router devices deployed by TrueOnline...

N/A N/A GITHUBEXPLOIT
NONE FEF41599-6B58-

1click-gh-token-stealing-via-vscode-POC_FEF41599-6B58-5BDB-BB48-0E38230B7291

1-Click GitHub Token Stealing via VSCode Proof-of-Concept exploit for a critical VS Code zero-day vulnerability that allows attackers to steal GitH...

N/A N/A GITHUBEXPLOIT