Recent Advisories

Severity ID Title Vendor Product Date Type
NONE H1:3795615

curl: Duplicate chunked Transfer-Encoding lets a malicious origin smuggle a response across reused HTTP proxy connections_H1:3795615

## TL;DR A malicious HTTP origin can send `Transfer-Encoding: chunked, chunked, gzip` through a reusable HTTP proxy connection to bypass curl's "c...

N/A N/A HACKERONE
NONE C59EAF7F-FEBE-

MeshCentral-RogueAgent_C59EAF7F-FEBE-5CF2-A77B-B0BEFA18269C

MeshCentral RogueAgent A proof-of-concept exploit chain for a stored XSS vulnerability in MeshCentral that escalates to unauthenticated RCE across ...

N/A N/A GITHUBEXPLOIT
NONE FB29A6F9-8FD2-

Exploit-Development-master_FB29A6F9-8FD2-5475-894F-D5F10F83FA22

Exploit-Development Weaponized Exploit and Proof of Concepts PoC...

N/A N/A GITHUBEXPLOIT
NONE HACKREAD:64E286...

Extradited Ukrainian Man Admits Role in Conti Ransomware Attacks_HACKREAD:64E286FC57B32D2D654585E925DAF4F2

Ukrainian national Oleksii Lytvynenko has pleaded guilty in the US to wire fraud conspiracy linked to Conti ransomware, which hit more than 1,000 v...

N/A N/A HACKREAD
NONE DE042206-2F9D-

Web-kit-exploit-test_DE042206-2F9D-5911-A266-79D3C324E08D

No description provided...

N/A N/A GITHUBEXPLOIT
NONE WIRED:B6A7A3320...

The FCC Wants to Kill Burner Phones_WIRED:B6A7A3320F201953AE03CB69723D6E08

Plus: AI bug hunting fuels Microsoft’s biggest-ever Patch Tuesday, ShinyHunters ransomware gang exploits an Oracle zero-day, and more.

N/A N/A WIRED
NONE C5449C27-7E72-

vader-toctou_C5449C27-7E72-529E-BB3B-A2BECFAFBE53

OPERATION VADER — TOCTOU EXPLOITATION SYLLABUS OPERATIONS ORDER 001-26 VADER Classification: UNCLASSIFIED // ACADEMIC USE ONLY DTG: 130600Z JUN 202...

N/A N/A GITHUBEXPLOIT
NONE 9A5FD168-FC71-

metasploit-cheatsheet_9A5FD168-FC71-5513-9CDE-518F25F86CEB

Metasploit Cheatsheet A practical reference for using Metasploit. Split into two parts — one for people just starting out, and one for those who al...

N/A N/A GITHUBEXPLOIT
NONE 71DCF1B4-43FB-

Exploit for CVE-2026-48017_71DCF1B4-43FB-5CFC-AE79-56678B58E162

CVE-2026-48017 — Remote Code Execution in DbGate via functionName injection Severity: High CVSS 8.8 CWE: CWE-94 — Improper Control of Generation of...

N/A N/A GITHUBEXPLOIT
NONE 83B29156-2E5B-

web-vuln-scanner_83B29156-2E5B-5DE8-A514-617EF308D8E8

Web Vulnerability Scanner Basic web application vulnerability scanner built in Python. Tests for common OWASP Top 10 issues — written as a learning...

N/A N/A GITHUBEXPLOIT