<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - ⚠️ PoC]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/poc.xml]]></link>
<description><![CDATA[Proof of Concept Exploits & Vulnerability Verification. Technische Verifizierungen, Repositories und Aufklärungsanalysen zu bestätigten Sicherheitslücken.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 17 Sep 2026 10:00:05 +0200</lastBuildDate>
<pubDate>Thu, 17 Sep 2026 10:00:05 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - ⚠️ PoC</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - ⚠️ PoC]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/poc.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Self-Hosting a Dockerized App on WSL2, Exposed with a Cloudflare Tunnel]]></title>
<description><![CDATA[TL;DR: A proof-of-concept to-do app — Node/Express and Postgres, running in Docker on WSL2 — reachable at a real domain through a named cloudflared tunnel. No login system, just a per-browser cookie hash. If you already have WSL2 and a Cloudflare-managed domain, expect this to take a few minutes,...]]></description>
<link>https://tsecurity.de/de/4150746/poc/self-hosting-a-dockerized-app-on-wsl2-exposed-with-a-cloudflare-tunnel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150746/poc/self-hosting-a-dockerized-app-on-wsl2-exposed-with-a-cloudflare-tunnel/</guid>
<pubDate>Thu, 17 Sep 2026 05:40:31 +0200</pubDate>
<content:encoded><![CDATA[<p>TL;DR: A proof-of-concept to-do app — Node/Express and Postgres, running in Docker on WSL2 — reachable at a real domain through a named cloudflared tunnel. No login system, just a per-browser cookie hash. If you already have WSL2 and a Cloudflare-managed domain, expect this to take a few minutes, not hours. I wanted a small proof of concept: a... <a href="https://dev.to/gerardo_leon/self-hosting-a-dockerized-app-on-wsl2-exposed-with-a-cloudflare-tunnel-3c0l" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Practical Framework for Scoping an AI Proof of Concept]]></title>
<description><![CDATA[Most AI proof-of-concept projects don't break down while they're building. They fall down on scoping, weeks before coding is even written. If the objective is unclear, data is unavailable, or a success is not defined, a two-week experiment becomes a two-month drift, showing no return to a stakeho...]]></description>
<link>https://tsecurity.de/de/4133479/poc/a-practical-framework-for-scoping-an-ai-proof-of-concept/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4133479/poc/a-practical-framework-for-scoping-an-ai-proof-of-concept/</guid>
<pubDate>Mon, 14 Sep 2026 23:42:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Most AI proof-of-concept projects don&#039;t break down while they&#039;re building. They fall down on scoping, weeks before coding is even written. If the objective is unclear, data is unavailable, or a success is not defined, a two-week experiment becomes a two-month drift, showing no return to a stakeholder. I&#039;ve seen this on my own projects and on teams... <a href="https://dzone.com/articles/ai-poc-practical-framework" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Private Enterprise AI: How SUSE AI Factory Moves GenAI Beyond the Pilot Stage]]></title>
<description><![CDATA[Most enterprise AI projects never make it past the demo. A team spins up a proof of concept, it impresses a room and then it stalls. Governance questions do not have answers yet, the public cloud bill is unpredictable and nobody signed off on where the model actually runs. Months later, the pilot...]]></description>
<link>https://tsecurity.de/de/4130729/poc/private-enterprise-ai-how-suse-ai-factory-moves-genai-beyond-the-pilot-stage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4130729/poc/private-enterprise-ai-how-suse-ai-factory-moves-genai-beyond-the-pilot-stage/</guid>
<pubDate>Mon, 14 Sep 2026 20:03:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Most enterprise AI projects never make it past the demo. A team spins up a proof of concept, it impresses a room and then it stalls. Governance questions do not have answers yet, the public cloud bill is unpredictable and nobody signed off on where the model actually runs. Months later, the pilot is still […] The post Private Enterprise AI: How... <a href="https://www.suse.com/c/private-enterprise-ai-how-suse-ai-factory-moves-genai-beyond-the-pilot-stage/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone Duo’s Opening Animation Is Already Running on a Galaxy Fold]]></title>
<description><![CDATA[The iPhone Duo’s smooth opening animation is already running on a Samsung Galaxy Z Fold 8 in an unofficial proof of concept, only days after Apple introduced its first foldable. The experiment suggests that one of the Duo’s most recognizable software touches could spread to other folding phones. ...]]></description>
<link>https://tsecurity.de/de/4126341/poc/iphone-duos-opening-animation-is-already-running-on-a-galaxy-fold/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4126341/poc/iphone-duos-opening-animation-is-already-running-on-a-galaxy-fold/</guid>
<pubDate>Mon, 14 Sep 2026 14:30:55 +0200</pubDate>
<content:encoded><![CDATA[<p>The iPhone Duo’s smooth opening animation is already running on a Samsung Galaxy Z Fold 8 in an unofficial proof of concept, only days after Apple introduced its first foldable. The experiment suggests that one of the Duo’s most recognizable software touches could spread to other folding phones. The effect is not an official Samsung feature and is... <a href="https://www.macobserver.com/news/iphone-duo-opening-animation-copied-android-foldables/?utm_source=macobserver&amp;utm_medium=rss&amp;utm_campaign=rss_everything" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[forti-research]]></title>
<description><![CDATA[Proof-of-concept exploiting a Fortinet fortimon3_74.sys kernel driver flaw to bypass PPL and terminate protected processes like lsass.exe via an unauthenticated kill command. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4054685/poc/forti-research/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4054685/poc/forti-research/</guid>
<pubDate>Fri, 11 Sep 2026 17:04:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Proof-of-concept exploiting a Fortinet fortimon3_74.sys kernel driver flaw to bypass PPL and terminate protected processes like lsass.exe via an unauthenticated kill command. <a href="https://kitploit.com/en/tools/github/mein-0/forti-research" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM Technology: OpenAI talks GPT-6 Astra and Millenium Prize, researchers create WeWorm exploit & IBM’s US Open app]]></title>
<description><![CDATA[YouTube VideoVisit Mixture of Experts podcast page to get more AI content  → https://ibm.biz/~AHBoMt9Qu

It's been a week that proves AI is moving faster than anyone can fully keep up with, unless you’ve got a good backhand. On episode 124 of Mixture of Experts, host Tim Hwang and co-host David Z...]]></description>
<link>https://tsecurity.de/de/4054255/poc/openai-talks-gpt-6-astra-and-millenium-prize-researchers-create-weworm-exploit-ibms-us-open-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4054255/poc/openai-talks-gpt-6-astra-and-millenium-prize-researchers-create-weworm-exploit-ibms-us-open-app/</guid>
<pubDate>Fri, 11 Sep 2026 17:01:36 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/XPReiOKCzFI"></iframe></p><div class="youtube-description">Visit Mixture of Experts podcast page to get more AI content  → https://ibm.biz/~AHBoMt9Qu<br />
<br />
It&#039;s been a week that proves AI is moving faster than anyone can fully keep up with, unless you’ve got a good backhand. On episode 124 of Mixture of Experts, host Tim Hwang and co-host David Zax are joined by Bri Kopecki, Aaron Baughman, and Olivia Buzek to talk about new advances from OpenAI, new cybersecurity threats, and new tools for US Open fans from IBM. <br />
<br />
First, OpenAI introduced GPT-6 Astra as the company&#039;s most intelligent and aligned model yet, reaching state-of-the-art results across computer use, software engineering, cybersecurity and science. Not missing a beat, the company dropped a second bit of news: an internal model produced a proof related to the 3-D Navier-Stokes equation, resolving one of mathematics&#039; most famous unsolved problems. We dig into both the breakthrough and the conversation around the use of AI to solve these seemingly impossible problems.<br />
<br />
Then, IBM and the USTA unveiled new AI-powered fan features for the 2026 US Open, including a Serve Quality metric and personalized stats, designed to bring fans closer to the action than ever. <br />
<br />
Finally, we talk WeWorm, an AI-assisted exploit by California security firm built as a proof-of-concept self-spreading worm, capable of hijacking WeChat accounts before a victim even had a chance to answer a phone call. It&#039;s a sobering demonstration of what AI-assisted offensive security now looks like.<br />
<br />
All that and more on Mixture of Experts.<br />
<br />
00:00 – Intro<br />
0:54 - OpenAI talks Navier-Stokes and GPT-6 Astra<br />
14:30 - IBM&#039;s AI analysis at the US Open<br />
22:55 - What WeWorm means for exploits<br />
<br />
&quot;The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication.&quot;<br />
<br />
AI news moves fast. Sign up for a monthly newsletter for AI updates from IBM → https://ibm.biz/~Uc9A8pkUe<br />
#aimodel #openai #navier-stokes <br />
<br />
AI was used in the creation of the transcript and metadata for this video.</div>]]></content:encoded>
<enclosure url="https://i1.ytimg.com/vi/XPReiOKCzFI/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel]]></title>
<description><![CDATA[A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT session could retriev...]]></description>
<link>https://tsecurity.de/de/4051133/poc/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4051133/poc/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel/</guid>
<pubDate>Fri, 11 Sep 2026 06:21:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT session could retrieve email data and relay it to an attacker-controlled... <a href="https://www.csoonline.com/article/4220203/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account]]></title>
<description><![CDATA[Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connect...]]></description>
<link>https://tsecurity.de/de/4050347/poc/chatgpt-flaw-let-a-planted-prompt-send-a-victims-gmail-data-to-another-account/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4050347/poc/chatgpt-flaw-let-a-planted-prompt-send-a-victims-gmail-data-to-another-account/</guid>
<pubDate>Fri, 11 Sep 2026 06:09:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user&#039;s question as usual. In the company&#039;s proof of concept, that hidden work read data from the user&#039;s connected Gmail account and passed it to a second ChatGPT... <a href="https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Swiss government explores replacing Microsoft 365 with open-source software]]></title>
<description><![CDATA[Swiss authorities have launched a pilot project to determine whether it is possible to replace Microsoft 365 with similar open-source services, RTS reports. This follows a proof-of-concept project in which 172 civil servants tested the German open-source platform openDesk. According to Matthias S...]]></description>
<link>https://tsecurity.de/de/4049072/poc/swiss-government-explores-replacing-microsoft-365-with-open-source-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4049072/poc/swiss-government-explores-replacing-microsoft-365-with-open-source-software/</guid>
<pubDate>Fri, 11 Sep 2026 02:28:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Swiss authorities have launched a pilot project to determine whether it is possible to replace Microsoft 365 with similar open-source services, RTS reports. This follows a proof-of-concept project in which 172 civil servants tested the German open-source platform openDesk. According to Matthias Stürmer, a professor at the University of Bern, there... <a href="https://www.computerworld.com/article/4219743/swiss-authorities-want-to-replace-microsoft-365-with-open-source-software.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Switzerland's Federal Government is Replacing Microsoft on 3,000 Computers]]></title>
<description><![CDATA[Switzerland's federal government has launched a pilot program to replace Microsoft 365 with open source alternatives across 3,000 workstations. That's about 7% of the federal workforce. The target is to complete the migration by end of 2027. This move follows a successful proof-of-concept and a n...]]></description>
<link>https://tsecurity.de/de/4007843/poc/switzerlands-federal-government-is-replacing-microsoft-on-3000-computers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4007843/poc/switzerlands-federal-government-is-replacing-microsoft-on-3000-computers/</guid>
<pubDate>Sun, 06 Sep 2026 18:32:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Switzerland&#039;s federal government has launched a pilot program to replace Microsoft 365 with open source alternatives across 3,000 workstations. That&#039;s about 7% of the federal workforce. The target is to complete the migration by end of 2027. This move follows a successful proof-of-concept and a new digital sovereignty law. A separate fast-track... <a href="https://feed.itsfoss.com/link/24361/17441270/switzerland-replace-microssoft-pilot" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building Reliable AI Agents Beyond the Hype: Lessons from $5.70/Month to 388K Stars]]></title>
<description><![CDATA[Originally published on tamiz.pro. The Reality Behind the Hype Every wave of AI agent enthusiasm follows the same arc: early prototypes that work in isolation, rapid demos powered by generous API credits, and then a crash into production constraints where reliability becomes non-negotiable. The j...]]></description>
<link>https://tsecurity.de/de/3990498/poc/building-reliable-ai-agents-beyond-the-hype-lessons-from-570month-to-388k-stars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3990498/poc/building-reliable-ai-agents-beyond-the-hype-lessons-from-570month-to-388k-stars/</guid>
<pubDate>Sun, 06 Sep 2026 08:11:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Originally published on tamiz.pro. The Reality Behind the Hype Every wave of AI agent enthusiasm follows the same arc: early prototypes that work in isolation, rapid demos powered by generous API credits, and then a crash into production constraints where reliability becomes non-negotiable. The journey from a $5.70/month proof-of-concept to... <a href="https://dev.to/tamizuddin/building-reliable-ai-agents-beyond-the-hype-lessons-from-570month-to-388k-stars-4nk7" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The file nobody reread]]></title>
<description><![CDATA[Field notes from a hosting migration for an NHS food-diary proof of concept. A certificate checker was quietly lying about whether a fix had worked, and two sessions rejected the same hosting idea twice, four days apart, without either reading the other's reasoning. The move itself was still on h...]]></description>
<link>https://tsecurity.de/de/3978898/poc/the-file-nobody-reread/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3978898/poc/the-file-nobody-reread/</guid>
<pubDate>Sat, 05 Sep 2026 20:11:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Field notes from a hosting migration for an NHS food-diary proof of concept. A certificate checker was quietly lying about whether a fix had worked, and two sessions rejected the same hosting idea twice, four days apart, without either reading the other&#039;s reasoning. The move itself was still on hold when this was written. This is a... <a href="https://dev.to/thekilteddev/the-file-nobody-reread-5d5" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI stellt GPT-6 Astra vor: 100% auf ExploitBench, PoC-Exploit-Anfragen blockiert]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – OpenAI hat GPT-6 Astra offiziell vorgestellt und meldet für ExploitBench eine Punktzahl von 100%. Laut Unternehmen soll das Modell dennoch nur für sichere Code-Reviews und Patch-Workflows freigeschaltet sein, während Anfragen nach Proof-of-Concept-Exploits abgelehnt werden....]]></description>
<link>https://tsecurity.de/de/3960439/poc/openai-stellt-gpt-6-astra-vor-100-auf-exploitbench-poc-exploit-anfragen-blockiert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3960439/poc/openai-stellt-gpt-6-astra-vor-100-auf-exploitbench-poc-exploit-anfragen-blockiert/</guid>
<pubDate>Sat, 05 Sep 2026 05:43:27 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – OpenAI hat GPT-6 Astra offiziell vorgestellt und meldet für ExploitBench eine Punktzahl von 100%. Laut Unternehmen soll das Modell dennoch nur für sichere Code-Reviews und Patch-Workflows freigeschaltet sein, während Anfragen nach Proof-of-Concept-Exploits abgelehnt werden. Astra wird zunächst nur an eine kleine Gruppe von... <a href="https://www.it-boltwise.de/openai-stellt-gpt-6-astra-vor-100-auf-exploitbench-poc-exploit-anfragen-blockiert.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests]]></title>
<description><![CDATA[OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness...]]></description>
<link>https://tsecurity.de/de/3957873/poc/gpt-6-astra-scores-100-on-exploitbench-as-openai-blocks-poc-exploit-requests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3957873/poc/gpt-6-astra-scores-100-on-exploitbench-as-openai-blocks-poc-exploit-requests/</guid>
<pubDate>Sat, 05 Sep 2026 01:23:32 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the &quot;world&#039;s most intelligent and aligned model.&quot; The development comes days after the artificial intelligence (AI) company said the model had reached the &quot;Critical&quot; cybersecurity capability threshold under its Preparedness Framework. &quot;Astra is state-of-the-art on computer... <a href="https://thehackernews.com/2026/09/gpt-6-astra-scores-100-on-exploitbench.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Acer's Strangest Gaming Handheld Prototype Doubles as a Tiny Windows Laptop]]></title>
<description><![CDATA[It's only a proof of concept for now. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3957027/poc/acers-strangest-gaming-handheld-prototype-doubles-as-a-tiny-windows-laptop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3957027/poc/acers-strangest-gaming-handheld-prototype-doubles-as-a-tiny-windows-laptop/</guid>
<pubDate>Fri, 04 Sep 2026 18:55:24 +0200</pubDate>
<content:encoded><![CDATA[<p>It&#039;s only a proof of concept for now. <a href="https://www.extremetech.com/gaming/acers-strangest-gaming-handheld-prototype-doubles-as-a-tiny-windows-laptop" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[pocindex]]></title>
<description><![CDATA[Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3953111/poc/pocindex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3953111/poc/pocindex/</guid>
<pubDate>Fri, 04 Sep 2026 03:50:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub. <a href="https://kitploit.com/en/tools/github/0xmarcio/pocindex" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GreenSection]]></title>
<description><![CDATA[Proof-of-concept for NVIDIA GreenSection memory corruption 0day, demonstrating out-of-bounds write via shared memory section, enabling cross-user compromise. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3950435/poc/greensection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3950435/poc/greensection/</guid>
<pubDate>Thu, 03 Sep 2026 21:51:36 +0200</pubDate>
<content:encoded><![CDATA[<p>Proof-of-concept for NVIDIA GreenSection memory corruption 0day, demonstrating out-of-bounds write via shared memory section, enabling cross-user compromise. <a href="https://kitploit.com/en/tools/github/msnightmare/greensection" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[dos] EVerest 2025.9.0 - DoS]]></title>
<description><![CDATA[EVerest 2025.9.0 - DoS Weiterlesen]]></description>
<link>https://tsecurity.de/de/3939037/poc/dos-everest-202590-dos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3939037/poc/dos-everest-202590-dos/</guid>
<pubDate>Wed, 02 Sep 2026 17:30:26 +0200</pubDate>
<content:encoded><![CDATA[<p>EVerest 2025.9.0 - DoS <a href="https://www.exploit-db.com/exploits/52679" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities]]></title>
<description><![CDATA[Fullhan FH8626V100 - Multiple Vulnerabilities Weiterlesen]]></description>
<link>https://tsecurity.de/de/3938555/poc/hardware-fullhan-fh8626v100-multiple-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3938555/poc/hardware-fullhan-fh8626v100-multiple-vulnerabilities/</guid>
<pubDate>Wed, 02 Sep 2026 16:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>Fullhan FH8626V100 - Multiple Vulnerabilities <a href="https://www.exploit-db.com/exploits/52674" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Securing Amazon Quick from POC to production: Agents, Flows, and Spaces]]></title>
<description><![CDATA[Amazon Quick proof of concept (POC) projects often succeed with a small pilot team, then stall when security and compliance teams review the production plan. A permission model that works for ten pilot users often breaks when you add five departments. Agents can return data outside their intended...]]></description>
<link>https://tsecurity.de/de/3928102/poc/securing-amazon-quick-from-poc-to-production-agents-flows-and-spaces/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3928102/poc/securing-amazon-quick-from-poc-to-production-agents-flows-and-spaces/</guid>
<pubDate>Tue, 01 Sep 2026 18:38:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Amazon Quick proof of concept (POC) projects often succeed with a small pilot team, then stall when security and compliance teams review the production plan. A permission model that works for ten pilot users often breaks when you add five departments. Agents can return data outside their intended scope, and compliance teams struggle to audit how... <a href="https://aws.amazon.com/blogs/machine-learning/securing-amazon-quick-from-poc-to-production-agents-flows-and-spaces/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nightmare Eclipse releases PoC exploit for Kaspersky Endpoint Security.]]></title>
<description><![CDATA[Healthcare companies disclose breaches. Attackers exploit recently patched JFrog Artifactory flaw. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3928015/poc/nightmare-eclipse-releases-poc-exploit-for-kaspersky-endpoint-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3928015/poc/nightmare-eclipse-releases-poc-exploit-for-kaspersky-endpoint-security/</guid>
<pubDate>Tue, 01 Sep 2026 18:35:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Healthcare companies disclose breaches. Attackers exploit recently patched JFrog Artifactory flaw. <a href="https://thecyberwire.com/newsletters/daily-briefing/15/167" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] EasyAppointments  1.5.1 - Blind SQL Injection]]></title>
<description><![CDATA[EasyAppointments 1.5.1 - Blind SQL Injection Weiterlesen]]></description>
<link>https://tsecurity.de/de/3926344/poc/webapps-easyappointments-151-blind-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3926344/poc/webapps-easyappointments-151-blind-sql-injection/</guid>
<pubDate>Tue, 01 Sep 2026 16:35:49 +0200</pubDate>
<content:encoded><![CDATA[<p>EasyAppointments 1.5.1 - Blind SQL Injection <a href="https://www.exploit-db.com/exploits/52667" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Payload CMS 3.72.0 - Blind SQL Injection]]></title>
<description><![CDATA[Payload CMS 3.72.0 - Blind SQL Injection Weiterlesen]]></description>
<link>https://tsecurity.de/de/3926343/poc/webapps-payload-cms-3720-blind-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3926343/poc/webapps-payload-cms-3720-blind-sql-injection/</guid>
<pubDate>Tue, 01 Sep 2026 16:35:04 +0200</pubDate>
<content:encoded><![CDATA[<p>Payload CMS 3.72.0 - Blind SQL Injection <a href="https://www.exploit-db.com/exploits/52671" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] C-MOR  6.0104 - Directory Traversal]]></title>
<description><![CDATA[C-MOR 6.0104 - Directory Traversal Weiterlesen]]></description>
<link>https://tsecurity.de/de/3902200/poc/webapps-c-mor-60104-directory-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3902200/poc/webapps-c-mor-60104-directory-traversal/</guid>
<pubDate>Mon, 31 Aug 2026 15:31:23 +0200</pubDate>
<content:encoded><![CDATA[<p>C-MOR 6.0104 - Directory Traversal <a href="https://www.exploit-db.com/exploits/52666" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] CubeCart 6.7.4 - SQL injection]]></title>
<description><![CDATA[CubeCart 6.7.4 - SQL injection Weiterlesen]]></description>
<link>https://tsecurity.de/de/3902198/poc/webapps-cubecart-674-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3902198/poc/webapps-cubecart-674-sql-injection/</guid>
<pubDate>Mon, 31 Aug 2026 15:31:11 +0200</pubDate>
<content:encoded><![CDATA[<p>CubeCart 6.7.4 - SQL injection <a href="https://www.exploit-db.com/exploits/52664" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] CubeCart 6.7.4 - SQL]]></title>
<description><![CDATA[CubeCart 6.7.4 - SQL Weiterlesen]]></description>
<link>https://tsecurity.de/de/3902196/poc/webapps-cubecart-674-sql/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3902196/poc/webapps-cubecart-674-sql/</guid>
<pubDate>Mon, 31 Aug 2026 15:31:08 +0200</pubDate>
<content:encoded><![CDATA[<p>CubeCart 6.7.4 - SQL <a href="https://www.exploit-db.com/exploits/52663" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command Injection]]></title>
<description><![CDATA[Linksys E1200_2.0.04 - Unauthenticated OS Command Injection Weiterlesen]]></description>
<link>https://tsecurity.de/de/3902192/poc/webapps-linksys-e12002004-unauthenticated-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3902192/poc/webapps-linksys-e12002004-unauthenticated-os-command-injection/</guid>
<pubDate>Mon, 31 Aug 2026 15:30:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Linksys E1200_2.0.04 - Unauthenticated OS Command Injection <a href="https://www.exploit-db.com/exploits/52660" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exchange-Sicherheitslücke: 85 Prozent der On-Prem-Server in Deutschland anfällig]]></title>
<description><![CDATA[Ein Proof-of-Concept-Exploit für eine hochriskante Exchange-Lücke ist öffentlich. 85 Prozent der On-Premises-Server sind anfällig. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3889420/poc/exchange-sicherheitsluecke-85-prozent-der-on-prem-server-in-deutschland-anfaellig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3889420/poc/exchange-sicherheitsluecke-85-prozent-der-on-prem-server-in-deutschland-anfaellig/</guid>
<pubDate>Mon, 31 Aug 2026 08:11:39 +0200</pubDate>
<content:encoded><![CDATA[<p>Ein Proof-of-Concept-Exploit für eine hochriskante Exchange-Lücke ist öffentlich. 85 Prozent der On-Premises-Server sind anfällig. <a href="https://www.heise.de/news/Exchange-Sicherheitsluecke-85-Prozent-der-On-Prem-Server-in-Deutschland-anfaellig-11434785.html?wt_mc=rss.red.ho.ho.rdf.beitrag.beitrag" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[cve — Updated!]]></title>
<description><![CDATA[Latest CVEs with their Proof of Concept exploits. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3886854/poc/cve-updated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3886854/poc/cve-updated/</guid>
<pubDate>Mon, 31 Aug 2026 06:57:21 +0200</pubDate>
<content:encoded><![CDATA[<p>Latest CVEs with their Proof of Concept exploits. <a href="https://kitploit.com/en/posts/github-0xmarcio-cve-40171cf6e265bd1fbd03c93820a717b5457d6bbeea112530b6637cb1b2f905e5" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Asia 2026 | Payload Compromised: Full Key Recovery in Rocket.Chat E2EE]]></title>
<description><![CDATA[YouTube VideoRocket.Chat is used in more than 150 countries, where many organizations rely on its end-to-end encryption (E2EE) for security-critical communication. This talk presents the first comprehensive analysis of Rocket.Chat's E2EE as deployed in real systems. By combining automated symboli...]]></description>
<link>https://tsecurity.de/de/3868763/poc/black-hat-asia-2026-payload-compromised-full-key-recovery-in-rocketchat-e2ee/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3868763/poc/black-hat-asia-2026-payload-compromised-full-key-recovery-in-rocketchat-e2ee/</guid>
<pubDate>Sun, 30 Aug 2026 15:42:17 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/35kun8wzFRU"></iframe></p><div class="youtube-description">Rocket.Chat is used in more than 150 countries, where many organizations rely on its end-to-end encryption (E2EE) for security-critical communication. This talk presents the first comprehensive analysis of Rocket.Chat&#039;s E2EE as deployed in real systems. By combining automated symbolic analysis with in-depth manual inspection of the implementation, we identify practical attacks that break both confidentiality and integrity.<br />
<br />
Our most severe finding is a practical key-recovery attack.<br />
An attacker with access to encrypted user backups can recover private keys and all derived group keys in twelve days under realistic assumptions. We validate this attack with practical proof-of-concept exploits. This results from weak offline-attack resistance combined with a biased, low-entropy password generator used to encrypt key backups. At the time of reporting, any server operating under a malicious-server threat model could execute the attack.<br />
<br />
We also uncover structural failures in the platform&#039;s key-rotation workflow. Although E2EE passwords and a master key were rotated, the group keys protecting message content were never replaced. Clients continued to accept and redistribute compromised group keys, which were then reused to encrypt new messages and decrypt past ones. A single key recovery therefore enabled expanding and persistent compromise across group communication.<br />
<br />
Manual analysis further revealed integrity failures, including ciphertext forgery made possible by unauthenticated AES-CBC encryption.<br />
<br />
Beyond the technical flaws, we also reconstruct how this fragile design emerged by examining public development discussions and historical commits. This OSINT analysis explains why several fundamental E2EE principles were never integrated and how long-term structural risks accumulated.<br />
<br />
The most severe vulnerabilities, including key recovery and broken key rotation, were fixed within six months of disclosure, and remaining integrity issues were patched after extended coordination. Attendees will learn how to analyze real-world E2EE systems, detect specification-implementation gaps, and replace password-based architectures with modern best practices.<br />
<br />
Hayato Kimura  |  Researcher, National Institute of Information and Communications Technology &amp; The University of Osaka<br />
Ryoma Ito  |  Senior Researcher, National Institute of Information and Communications Technology<br />
Kazuhiko Minematsu  |  Research Fellow, NEC Corporation<br />
Takanori Isobe  |  Professor, The University of Osaka<br />
<br />
https://blackhat.com/asia-26/briefings/schedule/?#payload-compromised-full-key-recovery-in-rocketchat-e2ee-50105</div>]]></content:encoded>
<enclosure url="https://i4.ytimg.com/vi/35kun8wzFRU/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[JSON Deserialiser Unconstrained Resource Consumption Proof of	Concept]]></title>
<description><![CDATA[Posted by Daniel Owens via Fulldisclosure on Aug 29On 26 October 2025 we published "Struts2 and Related Framework Array/Collection DoS", which was followed up on 07 March 2026 by "JSON Deserialiser Unconstrained Resource Consumption Quick Overview". Today we are publishing a proof of concept that...]]></description>
<link>https://tsecurity.de/de/3864157/poc/json-deserialiser-unconstrained-resource-consumption-proof-ofconcept/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3864157/poc/json-deserialiser-unconstrained-resource-consumption-proof-ofconcept/</guid>
<pubDate>Sun, 30 Aug 2026 09:52:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Posted by Daniel Owens via Fulldisclosure on Aug 29On 26 October 2025 we published &quot;Struts2 and Related Framework Array/Collection DoS&quot;, which was followed up on 07 March 2026 by &quot;JSON Deserialiser Unconstrained Resource Consumption Quick Overview&quot;. Today we are publishing a proof of concept that we have been using for more than 15 years against... <a href="https://seclists.org/fulldisclosure/2026/Aug/117" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI Projects Stall Between Proof of Concept and Production]]></title>
<description><![CDATA[A proof of concept is often the easiest part of an AI project. The scope is narrow, the users are friendly, the data sample is controlled, and the success criteria are usually simple enough to prove that something can work. A chatbot answers support questions. A model predicts churn with acceptab...]]></description>
<link>https://tsecurity.de/de/3857084/poc/why-ai-projects-stall-between-proof-of-concept-and-production/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3857084/poc/why-ai-projects-stall-between-proof-of-concept-and-production/</guid>
<pubDate>Sun, 30 Aug 2026 01:06:26 +0200</pubDate>
<content:encoded><![CDATA[<p>A proof of concept is often the easiest part of an AI project. The scope is narrow, the users are friendly, the data sample is controlled, and the success criteria are usually simple enough to prove that something can work. A chatbot answers support questions. A model predicts churn with acceptable accuracy. A document processing tool extracts... <a href="https://dzone.com/articles/why-production-ai-projects-stall" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Avoid these 5 pitfalls in your cybersecurity technology PoC]]></title>
<description><![CDATA[A cybersecurity technology proof of concept can validate a good purchasing decision -- or waste months of your team's time. Look out for these five common PoC missteps. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3856536/poc/avoid-these-5-pitfalls-in-your-cybersecurity-technology-poc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3856536/poc/avoid-these-5-pitfalls-in-your-cybersecurity-technology-poc/</guid>
<pubDate>Sun, 30 Aug 2026 01:02:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A cybersecurity technology proof of concept can validate a good purchasing decision -- or waste months of your team&#039;s time. Look out for these five common PoC missteps. <a href="https://www.techtarget.com/cybersecurity/feature/Avoid-these-5-pitfalls-in-your-cybersecurity-technology-PoC" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exchange-Sicherheitslücke: Wegen Proof-of-Concept Angriffe wahrscheinlich | heise online]]></title>
<description><![CDATA[Ein Hacker. (Bild: LuckyStep / Shutterstock.com). 13:01 Uhr. Lesezeit: 2 Min. Security. Von. Dirk Knop. Anzeige. close notice. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3814541/poc/exchange-sicherheitsluecke-wegen-proof-of-concept-angriffe-wahrscheinlich-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3814541/poc/exchange-sicherheitsluecke-wegen-proof-of-concept-angriffe-wahrscheinlich-heise-online/</guid>
<pubDate>Thu, 27 Aug 2026 23:58:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Ein Hacker. (Bild: LuckyStep / Shutterstock.com). 13:01 Uhr. Lesezeit: 2 Min. Security. Von. Dirk Knop. Anzeige. close notice. <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.heise.de/news/Angriffe-erwartbar-Proof-of-Concept-fuer-Exchange-Luecke-veroeffentlicht-11431561.html&amp;ct=ga&amp;cd=CAIyGTY2ODI4YjRlZGNiMmJmMmM6ZGU6ZGU6REU&amp;usg=AOvVaw34bpHLmt-acT4i7DyrRMHf" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude, Codex, and Hermes installed unowned code inside corporate networks]]></title>
<description><![CDATA[Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigure...]]></description>
<link>https://tsecurity.de/de/3810077/poc/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3810077/poc/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/</guid>
<pubDate>Thu, 27 Aug 2026 19:58:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live... <a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exchange-Sicherheitslücke: Wegen Proof-of-Concept Angriffe wahrscheinlich]]></title>
<description><![CDATA[Für eine hochriskante Lücke in Exchange, die die Systemübernahme erlaubt, ist Exploit-Code erschienen. Admins müssen updaten. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3802334/poc/exchange-sicherheitsluecke-wegen-proof-of-concept-angriffe-wahrscheinlich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3802334/poc/exchange-sicherheitsluecke-wegen-proof-of-concept-angriffe-wahrscheinlich/</guid>
<pubDate>Thu, 27 Aug 2026 13:23:00 +0200</pubDate>
<content:encoded><![CDATA[<p>Für eine hochriskante Lücke in Exchange, die die Systemübernahme erlaubt, ist Exploit-Code erschienen. Admins müssen updaten. <a href="https://www.heise.de/news/Angriffe-erwartbar-Proof-of-Concept-fuer-Exchange-Luecke-veroeffentlicht-11431561.html?wt_mc=rss.red.ho.ho.rdf.beitrag.beitrag" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MySQL: Native ANN Vector Indexing in InnoDB]]></title>
<description><![CDATA[YouTube VideoImaan Rana and Mayank Prasad present approaches for bringing native approximate nearest-neighbor (ANN) vector indexing to MySQL InnoDB. They compare Google’s production tree-based implementation with Oracle’s proof of concept, covering design tradeoffs, SQL syntax, storage, search be...]]></description>
<link>https://tsecurity.de/de/3782109/poc/native-ann-vector-indexing-in-innodb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3782109/poc/native-ann-vector-indexing-in-innodb/</guid>
<pubDate>Wed, 26 Aug 2026 20:18:29 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/tc5WD2uwcy8"></iframe></p><div class="youtube-description">Imaan Rana and Mayank Prasad present approaches for bringing native approximate nearest-neighbor (ANN) vector indexing to MySQL InnoDB. They compare Google’s production tree-based implementation with Oracle’s proof of concept, covering design tradeoffs, SQL syntax, storage, search behavior, and opportunities for community feedback.</div>]]></content:encoded>
<enclosure url="https://i1.ytimg.com/vi/tc5WD2uwcy8/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[break-golf]]></title>
<description><![CDATA[Cryptanalysis golf: break schemes and prove it in Lean 4. Proof-of-concept board. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3761206/poc/break-golf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3761206/poc/break-golf/</guid>
<pubDate>Tue, 25 Aug 2026 00:52:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Cryptanalysis golf: break schemes and prove it in Lean 4. Proof-of-concept board. <a href="https://kitploit.com/en/tools/github/trailofbits/break-golf" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CHIRP-CodeExecution_via_Malicious_ImageFile]]></title>
<description><![CDATA[Proof-of-concept exploit for arbitrary code execution through eval() injection in a ham radio programming application, including malicious .itm/.img file payloads and root-cause analysis. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3751838/poc/chirp-codeexecutionviamaliciousimagefile/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3751838/poc/chirp-codeexecutionviamaliciousimagefile/</guid>
<pubDate>Sat, 22 Aug 2026 23:32:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Proof-of-concept exploit for arbitrary code execution through eval() injection in a ham radio programming application, including malicious .itm/.img file payloads and root-cause analysis. <a href="https://kitploit.com/en/tools/github/cduram/chirp-codeexecution_via_malicious_imagefile" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] D-Link DNS_340L - OS Command Injection]]></title>
<description><![CDATA[D-Link DNS_340L - OS Command Injection Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745265/poc/remote-d-link-dns340l-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745265/poc/remote-d-link-dns340l-os-command-injection/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:38 +0200</pubDate>
<content:encoded><![CDATA[<p>D-Link DNS_340L - OS Command Injection <a href="https://www.exploit-db.com/exploits/52643" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[dos] NanaZip 6.5  -  DoS]]></title>
<description><![CDATA[NanaZip 6.5 - DoS Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745264/poc/dos-nanazip-65-dos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745264/poc/dos-nanazip-65-dos/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:38 +0200</pubDate>
<content:encoded><![CDATA[<p>NanaZip 6.5 - DoS <a href="https://www.exploit-db.com/exploits/52652" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] flyto_core 2.26.7 - Server-Side Request Forgery]]></title>
<description><![CDATA[flyto_core 2.26.7 - Server-Side Request Forgery Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745263/poc/webapps-flytocore-2267-server-side-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745263/poc/webapps-flytocore-2267-server-side-request-forgery/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:37 +0200</pubDate>
<content:encoded><![CDATA[<p>flyto_core 2.26.7 - Server-Side Request Forgery <a href="https://www.exploit-db.com/exploits/52651" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] ipTIME A3004T  - Remote Code Execution]]></title>
<description><![CDATA[ipTIME A3004T - Remote Code Execution Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745262/poc/remote-iptime-a3004t-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745262/poc/remote-iptime-a3004t-remote-code-execution/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:37 +0200</pubDate>
<content:encoded><![CDATA[<p>ipTIME A3004T - Remote Code Execution <a href="https://www.exploit-db.com/exploits/52644" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload]]></title>
<description><![CDATA[WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745261/poc/webapps-woocommerce-150-unauthenticated-arbitrary-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745261/poc/webapps-woocommerce-150-unauthenticated-arbitrary-file-upload/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:36 +0200</pubDate>
<content:encoded><![CDATA[<p>WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload <a href="https://www.exploit-db.com/exploits/52642" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla JCE_2.9.15 - Remote Code Execution]]></title>
<description><![CDATA[Joomla JCE_2.9.15 - Remote Code Execution Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745260/poc/webapps-joomla-jce2915-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745260/poc/webapps-joomla-jce2915-remote-code-execution/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Joomla JCE_2.9.15 - Remote Code Execution <a href="https://www.exploit-db.com/exploits/52645" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Probo 0.222.2 -  IDOR]]></title>
<description><![CDATA[Probo 0.222.2 - IDOR Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745259/poc/webapps-probo-02222-idor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745259/poc/webapps-probo-02222-idor/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Probo 0.222.2 - IDOR <a href="https://www.exploit-db.com/exploits/52650" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] webpack_devserver 5.2.5 -  CSRF]]></title>
<description><![CDATA[webpack_devserver 5.2.5 - CSRF Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745258/poc/webapps-webpackdevserver-525-csrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745258/poc/webapps-webpackdevserver-525-csrf/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:35 +0200</pubDate>
<content:encoded><![CDATA[<p>webpack_devserver 5.2.5 - CSRF <a href="https://www.exploit-db.com/exploits/52649" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass]]></title>
<description><![CDATA[phpSysInfo 3.4.5 - IP Allowlist Bypass Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745257/poc/remote-phpsysinfo-345-ip-allowlist-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745257/poc/remote-phpsysinfo-345-ip-allowlist-bypass/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:34 +0200</pubDate>
<content:encoded><![CDATA[<p>phpSysInfo 3.4.5 - IP Allowlist Bypass <a href="https://www.exploit-db.com/exploits/52648" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak]]></title>
<description><![CDATA[Duplicati 2.2.0.3 - JWT Signing Key Leak Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745256/poc/webapps-duplicati-2203-jwt-signing-key-leak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745256/poc/webapps-duplicati-2203-jwt-signing-key-leak/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Duplicati 2.2.0.3 - JWT Signing Key Leak <a href="https://www.exploit-db.com/exploits/52646" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[dos] Nmap  7.99  - Extension Header Integer Underflow]]></title>
<description><![CDATA[Nmap 7.99 - Extension Header Integer Underflow Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745255/poc/dos-nmap-799-extension-header-integer-underflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745255/poc/dos-nmap-799-extension-header-integer-underflow/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Nmap 7.99 - Extension Header Integer Underflow <a href="https://www.exploit-db.com/exploits/52647" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] PCMan 2.0.7 - Buffer Overflow]]></title>
<description><![CDATA[PCMan 2.0.7 - Buffer Overflow Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745254/poc/remote-pcman-207-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745254/poc/remote-pcman-207-buffer-overflow/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:33 +0200</pubDate>
<content:encoded><![CDATA[<p>PCMan 2.0.7 - Buffer Overflow <a href="https://www.exploit-db.com/exploits/52657" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[dos] NanaZip 6.5  - DoS]]></title>
<description><![CDATA[NanaZip 6.5 - DoS Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745253/poc/dos-nanazip-65-dos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745253/poc/dos-nanazip-65-dos/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:31 +0200</pubDate>
<content:encoded><![CDATA[<p>NanaZip 6.5 - DoS <a href="https://www.exploit-db.com/exploits/52656" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] flyto-core 2.26.7 - Arbitrary File Write]]></title>
<description><![CDATA[flyto-core 2.26.7 - Arbitrary File Write Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745252/poc/webapps-flyto-core-2267-arbitrary-file-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745252/poc/webapps-flyto-core-2267-arbitrary-file-write/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:27 +0200</pubDate>
<content:encoded><![CDATA[<p>flyto-core 2.26.7 - Arbitrary File Write <a href="https://www.exploit-db.com/exploits/52655" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF]]></title>
<description><![CDATA[Linuxfabrik monitoring_plugins_6.0.0 - SSRF Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745251/poc/webapps-linuxfabrik-monitoringplugins600-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745251/poc/webapps-linuxfabrik-monitoringplugins600-ssrf/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Linuxfabrik monitoring_plugins_6.0.0 - SSRF <a href="https://www.exploit-db.com/exploits/52653" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Nodemailer 9.0.0 - File Read/ SSRF]]></title>
<description><![CDATA[Nodemailer 9.0.0 - File Read/ SSRF Weiterlesen]]></description>
<link>https://tsecurity.de/de/3745250/poc/webapps-nodemailer-900-file-read-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3745250/poc/webapps-nodemailer-900-file-read-ssrf/</guid>
<pubDate>Fri, 21 Aug 2026 14:32:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Nodemailer 9.0.0 - File Read/ SSRF <a href="https://www.exploit-db.com/exploits/52654" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OrkesConductor 3.30.2 Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[Topic: OrkesConductor 3.30.2 Unauthenticated Remote Code Execution Risk: High Text:#!/usr/bin/env python3  # Exploit Title:        OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution  # CVE:          ...]]></description>
<link>https://tsecurity.de/de/3714302/poc/orkesconductor-3302-unauthenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714302/poc/orkesconductor-3302-unauthenticated-remote-code-execution/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:43 +0200</pubDate>
<content:encoded><![CDATA[Topic: OrkesConductor 3.30.2 Unauthenticated Remote Code Execution Risk: High Text:#!/usr/bin/env python3  # Exploit Title:        OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution  # CVE:          ...]]></content:encoded>
</item>
<item>
<title><![CDATA[strongSwan 5.9.13 DoS]]></title>
<description><![CDATA[Topic: strongSwan 5.9.13 DoS Risk: Medium Text:# Exploit Title: strongSwan 5.9.13 - DoS  # Date: 2026-05-13  # Exploit Author: Lukas Johannes Moeller  # Vendor Homepage: http...]]></description>
<link>https://tsecurity.de/de/3714301/poc/strongswan-5913-dos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714301/poc/strongswan-5913-dos/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:43 +0200</pubDate>
<content:encoded><![CDATA[Topic: strongSwan 5.9.13 DoS Risk: Medium Text:# Exploit Title: strongSwan 5.9.13 - DoS  # Date: 2026-05-13  # Exploit Author: Lukas Johannes Moeller  # Vendor Homepage: http...]]></content:encoded>
</item>
<item>
<title><![CDATA[LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting]]></title>
<description><![CDATA[Topic: LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Risk: Low Text:#!/usr/bin/env python3  # Exploit Title:        LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting  # CVE:                 ...]]></description>
<link>https://tsecurity.de/de/3714300/poc/luci-dhcpv6-lease-hostname-stored-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714300/poc/luci-dhcpv6-lease-hostname-stored-cross-site-scripting/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:43 +0200</pubDate>
<content:encoded><![CDATA[Topic: LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Risk: Low Text:#!/usr/bin/env python3  # Exploit Title:        LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting  # CVE:                 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Joomla Extension 4.1.4 PHP Object injection]]></title>
<description><![CDATA[Topic: Joomla Extension 4.1.4 PHP Object injection Risk: High Text:Exploit Ttile: Joomla Extension 4.1.4 - PHP Object injection   Affected : JoomShaper SP LMS < = 4.1.3  Fixed    : JoomShaper SP ...]]></description>
<link>https://tsecurity.de/de/3714299/poc/joomla-extension-414-php-object-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714299/poc/joomla-extension-414-php-object-injection/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:43 +0200</pubDate>
<content:encoded><![CDATA[Topic: Joomla Extension 4.1.4 PHP Object injection Risk: High Text:Exploit Ttile: Joomla Extension 4.1.4 - PHP Object injection   Affected : JoomShaper SP LMS &lt; = 4.1.3  Fixed    : JoomShaper SP ...]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Apache Gravitino 1.2.1 - SSRF]]></title>
<description><![CDATA[Apache Gravitino 1.2.1 - SSRF]]></description>
<link>https://tsecurity.de/de/3714298/poc/webapps-apache-gravitino-121-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714298/poc/webapps-apache-gravitino-121-ssrf/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:41 +0200</pubDate>
<content:encoded><![CDATA[Apache Gravitino 1.2.1 - SSRF]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Blocksy Companion  2.1.46 - RCE]]></title>
<description><![CDATA[Blocksy Companion  2.1.46 - RCE]]></description>
<link>https://tsecurity.de/de/3714297/poc/webapps-blocksy-companion-2146-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714297/poc/webapps-blocksy-companion-2146-rce/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:41 +0200</pubDate>
<content:encoded><![CDATA[Blocksy Companion  2.1.46 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] PraisonAI praisonaiagents  1.6.77 - Remote Code Execution]]></title>
<description><![CDATA[PraisonAI praisonaiagents  1.6.77 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3714296/poc/remote-praisonai-praisonaiagents-1677-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714296/poc/remote-praisonai-praisonaiagents-1677-remote-code-execution/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:41 +0200</pubDate>
<content:encoded><![CDATA[PraisonAI praisonaiagents  1.6.77 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] mcp-server-kubernetes 3.8.x - Argument Injection]]></title>
<description><![CDATA[mcp-server-kubernetes 3.8.x - Argument Injection]]></description>
<link>https://tsecurity.de/de/3714295/poc/remote-mcp-server-kubernetes-38x-argument-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714295/poc/remote-mcp-server-kubernetes-38x-argument-injection/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:41 +0200</pubDate>
<content:encoded><![CDATA[mcp-server-kubernetes 3.8.x - Argument Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[dos] LuCI DHCPv6 -  Lease Hostname Stored Cross-Site Scripting]]></title>
<description><![CDATA[LuCI DHCPv6 -  Lease Hostname Stored Cross-Site Scripting]]></description>
<link>https://tsecurity.de/de/3714294/poc/dos-luci-dhcpv6-lease-hostname-stored-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714294/poc/dos-luci-dhcpv6-lease-hostname-stored-cross-site-scripting/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:41 +0200</pubDate>
<content:encoded><![CDATA[LuCI DHCPv6 -  Lease Hostname Stored Cross-Site Scripting]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion]]></title>
<description><![CDATA[Ray 2.56.0 - Directory Traversal & Local File Inclusion]]></description>
<link>https://tsecurity.de/de/3714293/poc/webapps-ray-2560-directory-traversal-local-file-inclusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714293/poc/webapps-ray-2560-directory-traversal-local-file-inclusion/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:41 +0200</pubDate>
<content:encoded><![CDATA[Ray 2.56.0 - Directory Traversal &amp; Local File Inclusion]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Planyo_Online_Reservation_System  3.0 - Arbitrary File Read via SSRF]]></title>
<description><![CDATA[Planyo_Online_Reservation_System  3.0 - Arbitrary File Read via SSRF]]></description>
<link>https://tsecurity.de/de/3714292/poc/webapps-planyoonlinereservationsystem-30-arbitrary-file-read-via-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714292/poc/webapps-planyoonlinereservationsystem-30-arbitrary-file-read-via-ssrf/</guid>
<pubDate>Thu, 13 Aug 2026 16:24:41 +0200</pubDate>
<content:encoded><![CDATA[Planyo_Online_Reservation_System  3.0 - Arbitrary File Read via SSRF]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3713867/poc/webapps-orkesconductor-3302-unauthenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713867/poc/webapps-orkesconductor-3302-unauthenticated-remote-code-execution/</guid>
<pubDate>Tue, 11 Aug 2026 00:59:31 +0200</pubDate>
<content:encoded><![CDATA[OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Microsoft Edge 150.0.4078.48 - RCE]]></title>
<description><![CDATA[Microsoft Edge 150.0.4078.48 - RCE]]></description>
<link>https://tsecurity.de/de/3713866/poc/local-microsoft-edge-1500407848-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713866/poc/local-microsoft-edge-1500407848-rce/</guid>
<pubDate>Tue, 11 Aug 2026 00:59:31 +0200</pubDate>
<content:encoded><![CDATA[Microsoft Edge 150.0.4078.48 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] CorgetGpsDget 2_3.2 - OS Command Injection]]></title>
<description><![CDATA[CorgetGpsDget 2_3.2 - OS Command Injection]]></description>
<link>https://tsecurity.de/de/3713865/poc/webapps-corgetgpsdget-232-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713865/poc/webapps-corgetgpsdget-232-os-command-injection/</guid>
<pubDate>Tue, 11 Aug 2026 00:59:30 +0200</pubDate>
<content:encoded><![CDATA[CorgetGpsDget 2_3.2 - OS Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla 2.9.99.4 - Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[Joomla 2.9.99.4 - Unauthenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3713864/poc/webapps-joomla-29994-unauthenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713864/poc/webapps-joomla-29994-unauthenticated-remote-code-execution/</guid>
<pubDate>Tue, 11 Aug 2026 00:59:30 +0200</pubDate>
<content:encoded><![CDATA[Joomla 2.9.99.4 - Unauthenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[ArcadeDB <  26.7.2 Cross-Database Authorization Bypass (IDOR)]]></title>
<description><![CDATA[Topic: ArcadeDB <  26.7.2 Cross-Database Authorization Bypass (IDOR) Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: ArcadeDB <  26.7.2 Cross-Database Authorization Bypass (IDOR)  # CVE: CVE-2026-67342  #...]]></description>
<link>https://tsecurity.de/de/3698396/poc/arcadedb-2672-cross-database-authorization-bypass-idor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698396/poc/arcadedb-2672-cross-database-authorization-bypass-idor/</guid>
<pubDate>Mon, 03 Aug 2026 00:10:13 +0200</pubDate>
<content:encoded><![CDATA[Topic: ArcadeDB &lt;  26.7.2 Cross-Database Authorization Bypass (IDOR) Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: ArcadeDB &lt;  26.7.2 Cross-Database Authorization Bypass (IDOR)  # CVE: CVE-2026-67342  #...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Excel LTSC 2024 Remote Code Execution]]></title>
<description><![CDATA[Topic: Microsoft Excel LTSC 2024 Remote Code Execution Risk: High Text:# Titles: Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)  # Author: nu11secur1ty  # Date: 06/16/2025  # Vendor: Micros...]]></description>
<link>https://tsecurity.de/de/3693433/poc/microsoft-excel-ltsc-2024-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693433/poc/microsoft-excel-ltsc-2024-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:05:05 +0200</pubDate>
<content:encoded><![CDATA[Topic: Microsoft Excel LTSC 2024 Remote Code Execution Risk: High Text:# Titles: Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)  # Author: nu11secur1ty  # Date: 06/16/2025  # Vendor: Micros...]]></content:encoded>
</item>
<item>
<title><![CDATA[Langflow 1.2.x Remote Code Execution (RCE)]]></title>
<description><![CDATA[Topic: Langflow 1.2.x Remote Code Execution (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Langflow 1.2.x - Remote Code Execution (RCE)  # Date: 2025-07-11  # Exploit Author: Ra...]]></description>
<link>https://tsecurity.de/de/3693432/poc/langflow-12x-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693432/poc/langflow-12x-remote-code-execution-rce/</guid>
<pubDate>Sat, 25 Jul 2026 10:05:03 +0200</pubDate>
<content:encoded><![CDATA[Topic: Langflow 1.2.x Remote Code Execution (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Langflow 1.2.x - Remote Code Execution (RCE)  # Date: 2025-07-11  # Exploit Author: Ra...]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious XDG Desktop File]]></title>
<description><![CDATA[Topic: Malicious XDG Desktop File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693431/poc/malicious-xdg-desktop-file/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693431/poc/malicious-xdg-desktop-file/</guid>
<pubDate>Sat, 25 Jul 2026 10:05:02 +0200</pubDate>
<content:encoded><![CDATA[Topic: Malicious XDG Desktop File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE]]></title>
<description><![CDATA[Topic: Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE Risk: High Text:package main    import (  	"flag"  	"fmt"  	"io"  	"net/http"  	"net/url"  	"os"  	"strings"  )    /*  Shenzhen Aitemi M300 Wi-...]]></description>
<link>https://tsecurity.de/de/3693430/poc/shenzhen-aitemi-m300-wi-fi-repeater-unauthenticated-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693430/poc/shenzhen-aitemi-m300-wi-fi-repeater-unauthenticated-rce/</guid>
<pubDate>Sat, 25 Jul 2026 10:05:00 +0200</pubDate>
<content:encoded><![CDATA[Topic: Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE Risk: High Text:package main    import (  	"flag"  	"fmt"  	"io"  	"net/http"  	"net/url"  	"os"  	"strings"  )    /*  Shenzhen Aitemi M300 Wi-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Pandora ITSM Authenticated Command Injection]]></title>
<description><![CDATA[Topic: Pandora ITSM Authenticated Command Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693429/poc/pandora-itsm-authenticated-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693429/poc/pandora-itsm-authenticated-command-injection/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:59 +0200</pubDate>
<content:encoded><![CDATA[Topic: Pandora ITSM Authenticated Command Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco ISE 3.0 Remote Code Execution]]></title>
<description><![CDATA[Topic: Cisco ISE 3.0 Remote Code Execution Risk: High Text:# Exploit Title: Cisco ISE 3.0 - Remote Code Execution (RCE)  # Exploit Author: @ibrahimsql ibrahimsql.com  # Exploit Author's ...]]></description>
<link>https://tsecurity.de/de/3693428/poc/cisco-ise-30-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693428/poc/cisco-ise-30-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:57 +0200</pubDate>
<content:encoded><![CDATA[Topic: Cisco ISE 3.0 Remote Code Execution Risk: High Text:# Exploit Title: Cisco ISE 3.0 - Remote Code Execution (RCE)  # Exploit Author: @ibrahimsql ibrahimsql.com  # Exploit Author's ...]]></content:encoded>
</item>
<item>
<title><![CDATA[JetBrains TeamCity 2023.11.4 Authentication Bypass]]></title>
<description><![CDATA[Topic: JetBrains TeamCity 2023.11.4 Authentication Bypass Risk: High Text:#!/usr/bin/env python3  # -*- coding: utf-8 -*-  """  # Exploit Title: JetBrains TeamCity 2023.11.4 - Authentication Bypass  # ...]]></description>
<link>https://tsecurity.de/de/3693427/poc/jetbrains-teamcity-2023114-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693427/poc/jetbrains-teamcity-2023114-authentication-bypass/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:56 +0200</pubDate>
<content:encoded><![CDATA[Topic: JetBrains TeamCity 2023.11.4 Authentication Bypass Risk: High Text:#!/usr/bin/env python3  # -*- coding: utf-8 -*-  """  # Exploit Title: JetBrains TeamCity 2023.11.4 - Authentication Bypass  # ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Projectworlds Online Admission System 1.0 SQL Injection]]></title>
<description><![CDATA[Topic: Projectworlds Online Admission System 1.0 SQL Injection Risk: Medium Text:/*   * Title           : projectworlds Online Admission System 1.0 - SQL Injection   * Author       : Byte Reaper   * CVE      ...]]></description>
<link>https://tsecurity.de/de/3693426/poc/projectworlds-online-admission-system-10-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693426/poc/projectworlds-online-admission-system-10-sql-injection/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:55 +0200</pubDate>
<content:encoded><![CDATA[Topic: Projectworlds Online Admission System 1.0 SQL Injection Risk: Medium Text:/*   * Title           : projectworlds Online Admission System 1.0 - SQL Injection   * Author       : Byte Reaper   * CVE      ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Tenda AC20 16.03.08.12 Command Injection]]></title>
<description><![CDATA[Topic: Tenda AC20 16.03.08.12 Command Injection Risk: Medium Text:/*   * Exploit Title : Tenda AC20 16.03.08.12 - Command Injection   * Author       : Byte Reaper   * CVE          : CVE-2025-90...]]></description>
<link>https://tsecurity.de/de/3693425/poc/tenda-ac20-16030812-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693425/poc/tenda-ac20-16030812-command-injection/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:53 +0200</pubDate>
<content:encoded><![CDATA[Topic: Tenda AC20 16.03.08.12 Command Injection Risk: Medium Text:/*   * Exploit Title : Tenda AC20 16.03.08.12 - Command Injection   * Author       : Byte Reaper   * CVE          : CVE-2025-90...]]></content:encoded>
</item>
<item>
<title><![CDATA[DOS Baby POP3 Server 1.04]]></title>
<description><![CDATA[Topic: DOS Baby POP3 Server 1.04 Risk: Medium Text:# Exploit Title: DOS Baby POP3 Server 1.04  # Date: 12/08/2025  # Exploit Author: Érick Sousa (https://www.linkedin.com/in/eri...]]></description>
<link>https://tsecurity.de/de/3693424/poc/dos-baby-pop3-server-104/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693424/poc/dos-baby-pop3-server-104/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:52 +0200</pubDate>
<content:encoded><![CDATA[Topic: DOS Baby POP3 Server 1.04 Risk: Medium Text:# Exploit Title: DOS Baby POP3 Server 1.04  # Date: 12/08/2025  # Exploit Author: Érick Sousa (https://www.linkedin.com/in/eri...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ghost CMS 5.59.1 Arbitrary File Read]]></title>
<description><![CDATA[Topic: Ghost CMS 5.59.1 Arbitrary File Read Risk: Medium Text:#!/usr/bin/env python3  # -*- coding: utf-8 -*-  """  # Exploit Title: Ghost CMS 5.59.1 - Arbitrary File Read  # Date: 2023-09-...]]></description>
<link>https://tsecurity.de/de/3693423/poc/ghost-cms-5591-arbitrary-file-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693423/poc/ghost-cms-5591-arbitrary-file-read/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:50 +0200</pubDate>
<content:encoded><![CDATA[Topic: Ghost CMS 5.59.1 Arbitrary File Read Risk: Medium Text:#!/usr/bin/env python3  # -*- coding: utf-8 -*-  """  # Exploit Title: Ghost CMS 5.59.1 - Arbitrary File Read  # Date: 2023-09-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ultimate Member WordPress Plugin 2.6.6 Privilege Escalation]]></title>
<description><![CDATA[Topic: Ultimate Member WordPress Plugin 2.6.6 Privilege Escalation Risk: Medium Text:#!/usr/bin/env python3    # Exploit Title: Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation  # Exploit Author: Gur...]]></description>
<link>https://tsecurity.de/de/3693422/poc/ultimate-member-wordpress-plugin-266-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693422/poc/ultimate-member-wordpress-plugin-266-privilege-escalation/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:49 +0200</pubDate>
<content:encoded><![CDATA[Topic: Ultimate Member WordPress Plugin 2.6.6 Privilege Escalation Risk: Medium Text:#!/usr/bin/env python3    # Exploit Title: Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation  # Exploit Author: Gur...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sitecore XP Post-Authentication File Upload]]></title>
<description><![CDATA[Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693421/poc/sitecore-xp-post-authentication-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693421/poc/sitecore-xp-post-authentication-file-upload/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:48 +0200</pubDate>
<content:encoded><![CDATA[Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Commvault CLI Argument Injection / Traversal / Remote Code Execution]]></title>
<description><![CDATA[Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693420/poc/commvault-cli-argument-injection-traversal-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693420/poc/commvault-cli-argument-injection-traversal-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:46 +0200</pubDate>
<content:encoded><![CDATA[Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Belkin F9K1009 F9K1010 2.00.04/2.00.09 Hard Coded Credentials]]></title>
<description><![CDATA[Topic: Belkin F9K1009 F9K1010 2.00.04/2.00.09 Hard Coded Credentials Risk: High Text:/*   * Title           : Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials   * Author       : Byte Reaper   * CVE...]]></description>
<link>https://tsecurity.de/de/3693419/poc/belkin-f9k1009-f9k1010-2000420009-hard-coded-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693419/poc/belkin-f9k1009-f9k1010-2000420009-hard-coded-credentials/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:45 +0200</pubDate>
<content:encoded><![CDATA[Topic: Belkin F9K1009 F9K1010 2.00.04/2.00.09 Hard Coded Credentials Risk: High Text:/*   * Title           : Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials   * Author       : Byte Reaper   * CVE...]]></content:encoded>
</item>
<item>
<title><![CDATA[SugarCRM unauthenticated Remote Code Execution (RCE)]]></title>
<description><![CDATA[Topic: SugarCRM unauthenticated Remote Code Execution (RCE) Risk: High Text:# Exploit Title: SugarCRM unauthenticated Remote Code Execution (RCE)  # Exploit Author: DANG  # Vendor Homepage: https://www.s...]]></description>
<link>https://tsecurity.de/de/3693418/poc/sugarcrm-unauthenticated-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693418/poc/sugarcrm-unauthenticated-remote-code-execution-rce/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:43 +0200</pubDate>
<content:encoded><![CDATA[Topic: SugarCRM unauthenticated Remote Code Execution (RCE) Risk: High Text:# Exploit Title: SugarCRM unauthenticated Remote Code Execution (RCE)  # Exploit Author: DANG  # Vendor Homepage: https://www.s...]]></content:encoded>
</item>
<item>
<title><![CDATA[Vvveb CMS 1.0.5 Remote Code Execution]]></title>
<description><![CDATA[Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693417/poc/vvveb-cms-105-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693417/poc/vvveb-cms-105-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:42 +0200</pubDate>
<content:encoded><![CDATA[Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Swagger UI 1.0.3 Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[Topic: Swagger UI 1.0.3 Cross-Site Scripting (XSS) Risk: Low Text:/*   * Author       : Byte Reaper   * Telegram     : @ByteReaper0   * CVE          : CVE-2025-8191   * Title : Swagger UI 1.0.3...]]></description>
<link>https://tsecurity.de/de/3693416/poc/swagger-ui-103-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693416/poc/swagger-ui-103-cross-site-scripting-xss/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:41 +0200</pubDate>
<content:encoded><![CDATA[Topic: Swagger UI 1.0.3 Cross-Site Scripting (XSS) Risk: Low Text:/*   * Author       : Byte Reaper   * Telegram     : @ByteReaper0   * CVE          : CVE-2025-8191   * Title : Swagger UI 1.0.3...]]></content:encoded>
</item>
<item>
<title><![CDATA[Flowise 3.0.4 Remote Code Execution]]></title>
<description><![CDATA[Topic: Flowise 3.0.4 Remote Code Execution Risk: High Text:# Exploit Title: Flowise 3.0.4 - Remote Code Execution (RCE)  # Date: 10/11/2025  # Exploit Author: [nltt0] (https://github.com...]]></description>
<link>https://tsecurity.de/de/3693415/poc/flowise-304-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693415/poc/flowise-304-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:39 +0200</pubDate>
<content:encoded><![CDATA[Topic: Flowise 3.0.4 Remote Code Execution Risk: High Text:# Exploit Title: Flowise 3.0.4 - Remote Code Execution (RCE)  # Date: 10/11/2025  # Exploit Author: [nltt0] (https://github.com...]]></content:encoded>
</item>
<item>
<title><![CDATA[MonstaFTP Unauthenticated File Upload]]></title>
<description><![CDATA[Topic: MonstaFTP Unauthenticated File Upload Risk: Medium Text:# Titles: MonstaFTP Unauthenticated File Upload CVE-2025-34299  # Author: ibrahimsql  # Date: 11/21/2025  # Vendor: https://www...]]></description>
<link>https://tsecurity.de/de/3693414/poc/monstaftp-unauthenticated-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693414/poc/monstaftp-unauthenticated-file-upload/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:38 +0200</pubDate>
<content:encoded><![CDATA[Topic: MonstaFTP Unauthenticated File Upload Risk: Medium Text:# Titles: MonstaFTP Unauthenticated File Upload CVE-2025-34299  # Author: ibrahimsql  # Date: 11/21/2025  # Vendor: https://www...]]></content:encoded>
</item>
<item>
<title><![CDATA[Mbed TLS 3.6.4 Use-After-Free]]></title>
<description><![CDATA[Topic: Mbed TLS 3.6.4 Use-After-Free Risk: High Text:/*   * Exploit Title: Mbed TLS 3.6.4 - Use-After-Free   * Google Dork: N/A   * Date: 2025-08-29   * Exploit Author: Byte Reaper...]]></description>
<link>https://tsecurity.de/de/3693413/poc/mbed-tls-364-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693413/poc/mbed-tls-364-use-after-free/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:36 +0200</pubDate>
<content:encoded><![CDATA[Topic: Mbed TLS 3.6.4 Use-After-Free Risk: High Text:/*   * Exploit Title: Mbed TLS 3.6.4 - Use-After-Free   * Google Dork: N/A   * Date: 2025-08-29   * Exploit Author: Byte Reaper...]]></content:encoded>
</item>
<item>
<title><![CDATA[dotCMS 25.07.02-1 Authenticated Blind SQL Injection]]></title>
<description><![CDATA[Topic: dotCMS 25.07.02-1 Authenticated Blind SQL Injection Risk: Medium Text:#!/usr/bin/env python3    # Exploit Title: dotCMS 25.07.02-1 - Authenticated Blind SQL Injection  # Google Dork: N/A  # Date: 2...]]></description>
<link>https://tsecurity.de/de/3693412/poc/dotcms-250702-1-authenticated-blind-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693412/poc/dotcms-250702-1-authenticated-blind-sql-injection/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:35 +0200</pubDate>
<content:encoded><![CDATA[Topic: dotCMS 25.07.02-1 Authenticated Blind SQL Injection Risk: Medium Text:#!/usr/bin/env python3    # Exploit Title: dotCMS 25.07.02-1 - Authenticated Blind SQL Injection  # Google Dork: N/A  # Date: 2...]]></content:encoded>
</item>
<item>
<title><![CDATA[Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure]]></title>
<description><![CDATA[Topic: Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure Risk: Low Text:/*   * Exploit Title : Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure   * Author       : Byte Reaper   *...]]></description>
<link>https://tsecurity.de/de/3693411/poc/birth-chart-compatibility-wordpress-plugin-20-full-path-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693411/poc/birth-chart-compatibility-wordpress-plugin-20-full-path-disclosure/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:33 +0200</pubDate>
<content:encoded><![CDATA[Topic: Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure Risk: Low Text:/*   * Exploit Title : Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure   * Author       : Byte Reaper   *...]]></content:encoded>
</item>
<item>
<title><![CDATA[LangChain Core - Serialization Injection to Jinja2 SSTI/RCE]]></title>
<description><![CDATA[Topic: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE  Risk: High Text:# Exploit Title: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE   # Date: 2025-12-29  # Exploit Author: Mohammed I...]]></description>
<link>https://tsecurity.de/de/3693410/poc/langchain-core-serialization-injection-to-jinja2-sstirce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693410/poc/langchain-core-serialization-injection-to-jinja2-sstirce/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:32 +0200</pubDate>
<content:encoded><![CDATA[Topic: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE  Risk: High Text:# Exploit Title: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE   # Date: 2025-12-29  # Exploit Author: Mohammed I...]]></content:encoded>
</item>
<item>
<title><![CDATA[deephas < = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS]]></title>
<description><![CDATA[Topic: deephas < = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS Risk: High Text:#!/usr/bin/env python3  #  # Exploit Title: deephas < = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS  #...]]></description>
<link>https://tsecurity.de/de/3693409/poc/deephas-107-prototype-pollution-leading-to-arbitrary-code-execution-dos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693409/poc/deephas-107-prototype-pollution-leading-to-arbitrary-code-execution-dos/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:31 +0200</pubDate>
<content:encoded><![CDATA[Topic: deephas &lt; = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS Risk: High Text:#!/usr/bin/env python3  #  # Exploit Title: deephas &lt; = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS  #...]]></content:encoded>
</item>
<item>
<title><![CDATA[aiohttp 3.9.1 Directory Traversal]]></title>
<description><![CDATA[Topic: aiohttp 3.9.1 Directory Traversal Risk: Medium Text:# Exploit Title: Python aiohttp directory traversal PoC (CVE-2024-23334)  # Google Dork: N/A  # Date: 2025-10-06  # Exploit Aut...]]></description>
<link>https://tsecurity.de/de/3693408/poc/aiohttp-391-directory-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693408/poc/aiohttp-391-directory-traversal/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:29 +0200</pubDate>
<content:encoded><![CDATA[Topic: aiohttp 3.9.1 Directory Traversal Risk: Medium Text:# Exploit Title: Python aiohttp directory traversal PoC (CVE-2024-23334)  # Google Dork: N/A  # Date: 2025-10-06  # Exploit Aut...]]></content:encoded>
</item>
<item>
<title><![CDATA[Siklu EtherHaul Series EH-8010 Remote Command Execution]]></title>
<description><![CDATA[Topic: Siklu EtherHaul Series EH-8010 Remote Command Execution Risk: High Text:# Exploit Title:Siklu EtherHaul Series EH-8010 - Remote Command Execution  # Shodan Dork: "EH-8010" or "EH-1200"  # Date: 2025-...]]></description>
<link>https://tsecurity.de/de/3693407/poc/siklu-etherhaul-series-eh-8010-remote-command-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693407/poc/siklu-etherhaul-series-eh-8010-remote-command-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:28 +0200</pubDate>
<content:encoded><![CDATA[Topic: Siklu EtherHaul Series EH-8010 Remote Command Execution Risk: High Text:# Exploit Title:Siklu EtherHaul Series EH-8010 - Remote Command Execution  # Shodan Dork: "EH-8010" or "EH-1200"  # Date: 2025-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Chrome <  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free]]></title>
<description><![CDATA[Topic: Google Chrome <  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free Risk: High Text:# Exploit Title: Google Chrome <  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free  # Date: 2026-02-23  # Exploit Author: ...]]></description>
<link>https://tsecurity.de/de/3693406/poc/google-chrome-1450763275-cssfontfeaturevaluesmap-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693406/poc/google-chrome-1450763275-cssfontfeaturevaluesmap-use-after-free/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:26 +0200</pubDate>
<content:encoded><![CDATA[Topic: Google Chrome &lt;  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free Risk: High Text:# Exploit Title: Google Chrome &lt;  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free  # Date: 2026-02-23  # Exploit Author: ...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution]]></title>
<description><![CDATA[Topic: OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution  # CVE:             CV...]]></description>
<link>https://tsecurity.de/de/3693405/poc/openclaw-toolsexecsafebins-2026222-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693405/poc/openclaw-toolsexecsafebins-2026222-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:25 +0200</pubDate>
<content:encoded><![CDATA[Topic: OpenClaw tools.exec.safeBins &lt; = 2026.2.22 Remote Code Execution Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw tools.exec.safeBins &lt; = 2026.2.22 Remote Code Execution  # CVE:             CV...]]></content:encoded>
</item>
<item>
<title><![CDATA[Kanboard < = 1.2.50 Authenticated SQL Injection]]></title>
<description><![CDATA[Topic: Kanboard < = 1.2.50 Authenticated SQL Injection  Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        Kanboard Authenticated SQL Injection in ProjectPermissionController  # CVE:    ...]]></description>
<link>https://tsecurity.de/de/3693404/poc/kanboard-1250-authenticated-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693404/poc/kanboard-1250-authenticated-sql-injection/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:24 +0200</pubDate>
<content:encoded><![CDATA[Topic: Kanboard &lt; = 1.2.50 Authenticated SQL Injection  Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        Kanboard Authenticated SQL Injection in ProjectPermissionController  # CVE:    ...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw <  2026.3.28 Discord Text Approval Authorization Bypass]]></title>
<description><![CDATA[Topic: OpenClaw <  2026.3.28 Discord Text Approval Authorization Bypass Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw Discord Text Approval Authorization Bypass  # CVE: CVE-2026-41303  # Date: 20...]]></description>
<link>https://tsecurity.de/de/3693403/poc/openclaw-2026328-discord-text-approval-authorization-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693403/poc/openclaw-2026328-discord-text-approval-authorization-bypass/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:22 +0200</pubDate>
<content:encoded><![CDATA[Topic: OpenClaw &lt;  2026.3.28 Discord Text Approval Authorization Bypass Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw Discord Text Approval Authorization Bypass  # CVE: CVE-2026-41303  # Date: 20...]]></content:encoded>
</item>
<item>
<title><![CDATA[Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Vulnerability - Realistic Full Chain Attack on F-16 Avionics (Ground]]></title>
<description><![CDATA[Topic: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Vulnerability - Realistic Full Chain Attack on F-16 Avionics (Ground Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Full Chain - Realistic F-16...]]></description>
<link>https://tsecurity.de/de/3693402/poc/green-hills-integrity-rtos-ipcomshell-telnet-format-string-vulnerability-realistic-full-chain-attack-on-f-16-avionics-ground/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693402/poc/green-hills-integrity-rtos-ipcomshell-telnet-format-string-vulnerability-realistic-full-chain-attack-on-f-16-avionics-ground/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:21 +0200</pubDate>
<content:encoded><![CDATA[Topic: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Vulnerability - Realistic Full Chain Attack on F-16 Avionics (Ground Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Full Chain - Realistic F-16...]]></content:encoded>
</item>
<item>
<title><![CDATA[NiceGUI 3.6.1 Path Traversal]]></title>
<description><![CDATA[Topic: NiceGUI 3.6.1 Path Traversal Risk: Medium Text:# Exploit Title: NiceGUI 3.6.1 - Path Traversal   # Author: Mohammed Idrees Banyamer  # Instagram: @banyamer_security  # GitHub...]]></description>
<link>https://tsecurity.de/de/3693401/poc/nicegui-361-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693401/poc/nicegui-361-path-traversal/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:20 +0200</pubDate>
<content:encoded><![CDATA[Topic: NiceGUI 3.6.1 Path Traversal Risk: Medium Text:# Exploit Title: NiceGUI 3.6.1 - Path Traversal   # Author: Mohammed Idrees Banyamer  # Instagram: @banyamer_security  # GitHub...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service]]></title>
<description><![CDATA[Topic: Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Risk: Medium Text:# Exploit Title: Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service  # Google Dork: intext:"Apache/2.4.66" "...]]></description>
<link>https://tsecurity.de/de/3693400/poc/apache-http-server-2466-modhttp2-double-free-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693400/poc/apache-http-server-2466-modhttp2-double-free-denial-of-service/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:17 +0200</pubDate>
<content:encoded><![CDATA[Topic: Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Risk: Medium Text:# Exploit Title: Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service  # Google Dork: intext:"Apache/2.4.66" "...]]></content:encoded>
</item>
<item>
<title><![CDATA[ePati Antikor NGFW 2.0.1301  Authentication Bypass]]></title>
<description><![CDATA[Topic: ePati Antikor NGFW 2.0.1301  Authentication Bypass Risk: Medium Text:# Exploit Title: ePati Antikor NGFW 2.0.1301 -  Authentication Bypass   # Date: 2026-04-13  # Exploit Author: [SADIK ERTÜRK]  ...]]></description>
<link>https://tsecurity.de/de/3693399/poc/epati-antikor-ngfw-201301-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693399/poc/epati-antikor-ngfw-201301-authentication-bypass/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:16 +0200</pubDate>
<content:encoded><![CDATA[Topic: ePati Antikor NGFW 2.0.1301  Authentication Bypass Risk: Medium Text:# Exploit Title: ePati Antikor NGFW 2.0.1301 -  Authentication Bypass   # Date: 2026-04-13  # Exploit Author: [SADIK ERTÜRK]  ...]]></content:encoded>
</item>
<item>
<title><![CDATA[XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057]]></title>
<description><![CDATA[Topic: XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 Risk: Low Text:#!/usr/bin/env python3  """  XenForo XSS CVE Scanner  Author: Xasthur    Passive detection for CVE-2026-35055, CVE-2026-35054, ...]]></description>
<link>https://tsecurity.de/de/3693398/poc/xenforo-xss-cve-scanner-passive-detection-tool-for-cve-2026-35055-cve-2026-35054-cve-2026-35057/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693398/poc/xenforo-xss-cve-scanner-passive-detection-tool-for-cve-2026-35055-cve-2026-35054-cve-2026-35057/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:12 +0200</pubDate>
<content:encoded><![CDATA[Topic: XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 Risk: Low Text:#!/usr/bin/env python3  """  XenForo XSS CVE Scanner  Author: Xasthur    Passive detection for CVE-2026-35055, CVE-2026-35054, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[PraisonAI CodeAgent < = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution]]></title>
<description><![CDATA[Topic: PraisonAI CodeAgent < = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution Risk: High Text:#!/usr/bin/env python3  # Exploit Title:         PraisonAI CodeAgent < = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM ...]]></description>
<link>https://tsecurity.de/de/3693397/poc/praisonai-codeagent-1677-remote-code-execution-rce-via-unsandboxed-llm-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693397/poc/praisonai-codeagent-1677-remote-code-execution-rce-via-unsandboxed-llm-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:08 +0200</pubDate>
<content:encoded><![CDATA[Topic: PraisonAI CodeAgent &lt; = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution Risk: High Text:#!/usr/bin/env python3  # Exploit Title:         PraisonAI CodeAgent &lt; = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Edge < = 150.0.4078.48 (Chromium-based) Type Confusion RCE]]></title>
<description><![CDATA[Topic: Microsoft Edge < = 150.0.4078.48 (Chromium-based) Type Confusion RCE Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        Microsoft Edge < = 150.0.4078.48 (Chromium-based) Type Confusion RCE  # CVE:    ...]]></description>
<link>https://tsecurity.de/de/3693396/poc/microsoft-edge-1500407848-chromium-based-type-confusion-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693396/poc/microsoft-edge-1500407848-chromium-based-type-confusion-rce/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:07 +0200</pubDate>
<content:encoded><![CDATA[Topic: Microsoft Edge &lt; = 150.0.4078.48 (Chromium-based) Type Confusion RCE Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        Microsoft Edge &lt; = 150.0.4078.48 (Chromium-based) Type Confusion RCE  # CVE:    ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)]]></title>
<description><![CDATA[Topic: Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)  # Goog...]]></description>
<link>https://tsecurity.de/de/3679245/poc/joomla-page-builder-ck-3510-unauthenticated-arbitrary-file-upload-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679245/poc/joomla-page-builder-ck-3510-unauthenticated-arbitrary-file-upload-rce/</guid>
<pubDate>Sun, 19 Jul 2026 11:36:24 +0200</pubDate>
<content:encoded><![CDATA[Topic: Joomla Page Builder CK &lt; = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Joomla Page Builder CK &lt; = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)  # Goog...]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></title>
<description><![CDATA[Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></description>
<link>https://tsecurity.de/de/3654511/poc/webapps-atarim-wordpress-plugin-422-sensitive-information-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654511/poc/webapps-atarim-wordpress-plugin-422-sensitive-information-exposure/</guid>
<pubDate>Wed, 08 Jul 2026 15:54:08 +0200</pubDate>
<content:encoded><![CDATA[Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></title>
<description><![CDATA[Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3654510/poc/webapps-krayin-crm-v22x-authenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654510/poc/webapps-krayin-crm-v22x-authenticated-remote-code-execution/</guid>
<pubDate>Wed, 08 Jul 2026 15:54:07 +0200</pubDate>
<content:encoded><![CDATA[Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Langflow 1.9.0 - RCE]]></title>
<description><![CDATA[Langflow 1.9.0 - RCE]]></description>
<link>https://tsecurity.de/de/3654473/poc/webapps-langflow-190-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654473/poc/webapps-langflow-190-rce/</guid>
<pubDate>Wed, 08 Jul 2026 15:36:47 +0200</pubDate>
<content:encoded><![CDATA[Langflow 1.9.0 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></title>
<description><![CDATA[Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></description>
<link>https://tsecurity.de/de/3654472/poc/webapps-joomla-page-builder-ck-3510-arbitrary-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654472/poc/webapps-joomla-page-builder-ck-3510-arbitrary-file-upload/</guid>
<pubDate>Wed, 08 Jul 2026 15:36:46 +0200</pubDate>
<content:encoded><![CDATA[Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MCPJam Inspector - Remote Code Execution]]></title>
<description><![CDATA[MCPJam Inspector - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3651885/poc/webapps-mcpjam-inspector-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651885/poc/webapps-mcpjam-inspector-remote-code-execution/</guid>
<pubDate>Tue, 07 Jul 2026 16:39:54 +0200</pubDate>
<content:encoded><![CDATA[MCPJam Inspector - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ProtonVPN v4.4.1 - Unquoted Service Path]]></title>
<description><![CDATA[ProtonVPN v4.4.1 - Unquoted Service Path]]></description>
<link>https://tsecurity.de/de/3651801/poc/local-protonvpn-v441-unquoted-service-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651801/poc/local-protonvpn-v441-unquoted-service-path/</guid>
<pubDate>Tue, 07 Jul 2026 16:11:21 +0200</pubDate>
<content:encoded><![CDATA[ProtonVPN v4.4.1 - Unquoted Service Path]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Flowise  3.1.3 - arbitrary code execution]]></title>
<description><![CDATA[Flowise  3.1.3 - arbitrary code execution]]></description>
<link>https://tsecurity.de/de/3651737/poc/webapps-flowise-313-arbitrary-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651737/poc/webapps-flowise-313-arbitrary-code-execution/</guid>
<pubDate>Tue, 07 Jul 2026 15:52:40 +0200</pubDate>
<content:encoded><![CDATA[Flowise  3.1.3 - arbitrary code execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Discuz! X5.0 - Authentication Bypass]]></title>
<description><![CDATA[Discuz! X5.0 - Authentication Bypass]]></description>
<link>https://tsecurity.de/de/3651709/poc/webapps-discuz-x50-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651709/poc/webapps-discuz-x50-authentication-bypass/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:50 +0200</pubDate>
<content:encoded><![CDATA[Discuz! X5.0 - Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Bricks Builder Theme  -  RCE]]></title>
<description><![CDATA[WordPress Bricks Builder Theme  -  RCE]]></description>
<link>https://tsecurity.de/de/3651708/poc/webapps-wordpress-bricks-builder-theme-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651708/poc/webapps-wordpress-bricks-builder-theme-rce/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:48 +0200</pubDate>
<content:encoded><![CDATA[WordPress Bricks Builder Theme  -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Tenable Nessus 10.12.1 - SQL Injection]]></title>
<description><![CDATA[Tenable Nessus 10.12.1 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3651707/poc/webapps-tenable-nessus-10121-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651707/poc/webapps-tenable-nessus-10121-sql-injection/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:47 +0200</pubDate>
<content:encoded><![CDATA[Tenable Nessus 10.12.1 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter]]></title>
<description><![CDATA[iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter]]></description>
<link>https://tsecurity.de/de/3651706/poc/remote-ios-bluetooth-pan-exploit-ethernet-gateway-without-adapter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651706/poc/remote-ios-bluetooth-pan-exploit-ethernet-gateway-without-adapter/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:46 +0200</pubDate>
<content:encoded><![CDATA[iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Hydra - Stack Buffer Overflow]]></title>
<description><![CDATA[Hydra - Stack Buffer Overflow]]></description>
<link>https://tsecurity.de/de/3651705/poc/remote-hydra-stack-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651705/poc/remote-hydra-stack-buffer-overflow/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:45 +0200</pubDate>
<content:encoded><![CDATA[Hydra - Stack Buffer Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] KeepInMind 0.8.4.2 -  Stored XSS]]></title>
<description><![CDATA[KeepInMind 0.8.4.2 -  Stored XSS]]></description>
<link>https://tsecurity.de/de/3648885/poc/webapps-keepinmind-0842-stored-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648885/poc/webapps-keepinmind-0842-stored-xss/</guid>
<pubDate>Mon, 06 Jul 2026 15:40:50 +0200</pubDate>
<content:encoded><![CDATA[KeepInMind 0.8.4.2 -  Stored XSS]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation]]></title>
<description><![CDATA[MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3648884/poc/local-memu-android-emulator-9270-local-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648884/poc/local-memu-android-emulator-9270-local-privilege-escalation/</guid>
<pubDate>Mon, 06 Jul 2026 15:40:49 +0200</pubDate>
<content:encoded><![CDATA[MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla Extension 4.1.4 - PHP Object injection]]></title>
<description><![CDATA[Joomla Extension 4.1.4 - PHP Object injection]]></description>
<link>https://tsecurity.de/de/3648883/poc/webapps-joomla-extension-414-php-object-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648883/poc/webapps-joomla-extension-414-php-object-injection/</guid>
<pubDate>Mon, 06 Jul 2026 15:40:48 +0200</pubDate>
<content:encoded><![CDATA[Joomla Extension 4.1.4 - PHP Object injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></title>
<description><![CDATA[Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></description>
<link>https://tsecurity.de/de/3648882/poc/webapps-pulpy-011-beta-filesystem-sandbox-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648882/poc/webapps-pulpy-011-beta-filesystem-sandbox-bypass/</guid>
<pubDate>Mon, 06 Jul 2026 15:40:47 +0200</pubDate>
<content:encoded><![CDATA[Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3648832/poc/webapps-wordpress-plugin-wpzoom-portfolio-1421-reflected-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648832/poc/webapps-wordpress-plugin-wpzoom-portfolio-1421-reflected-cross-site-scripting-xss/</guid>
<pubDate>Mon, 06 Jul 2026 15:21:28 +0200</pubDate>
<content:encoded><![CDATA[WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] KNX visualisering - Broken Access Control]]></title>
<description><![CDATA[KNX visualisering - Broken Access Control]]></description>
<link>https://tsecurity.de/de/3648831/poc/webapps-knx-visualisering-broken-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648831/poc/webapps-knx-visualisering-broken-access-control/</guid>
<pubDate>Mon, 06 Jul 2026 15:21:27 +0200</pubDate>
<content:encoded><![CDATA[KNX visualisering - Broken Access Control]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows Defender (MsMpEng.exe) - Race Condition]]></title>
<description><![CDATA[Windows Defender (MsMpEng.exe) - Race Condition]]></description>
<link>https://tsecurity.de/de/3648830/poc/local-windows-defender-msmpengexe-race-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648830/poc/local-windows-defender-msmpengexe-race-condition/</guid>
<pubDate>Mon, 06 Jul 2026 15:21:25 +0200</pubDate>
<content:encoded><![CDATA[Windows Defender (MsMpEng.exe) - Race Condition]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenEMR 7.0.2 - Arbitrary File Read]]></title>
<description><![CDATA[OpenEMR 7.0.2 - Arbitrary File Read]]></description>
<link>https://tsecurity.de/de/3581651/poc/webapps-openemr-702-arbitrary-file-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581651/poc/webapps-openemr-702-arbitrary-file-read/</guid>
<pubDate>Mon, 08 Jun 2026 15:53:41 +0200</pubDate>
<content:encoded><![CDATA[OpenEMR 7.0.2 - Arbitrary File Read]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></title>
<description><![CDATA[WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></description>
<link>https://tsecurity.de/de/3575179/poc/webapps-wordpress-contest-gallery-2814-unauthenticated-blind-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575179/poc/webapps-wordpress-contest-gallery-2814-unauthenticated-blind-sql-injection/</guid>
<pubDate>Fri, 05 Jun 2026 13:21:16 +0200</pubDate>
<content:encoded><![CDATA[WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress OrderConvo 14 - Path Traversal]]></title>
<description><![CDATA[WordPress OrderConvo 14 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3563956/poc/webapps-wordpress-orderconvo-14-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563956/poc/webapps-wordpress-orderconvo-14-path-traversal/</guid>
<pubDate>Mon, 01 Jun 2026 19:52:20 +0200</pubDate>
<content:encoded><![CDATA[WordPress OrderConvo 14 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection]]></title>
<description><![CDATA[Drupal Core 10.5.5 - Error-Based SQL Injection]]></description>
<link>https://tsecurity.de/de/3563955/poc/webapps-drupal-core-1055-error-based-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563955/poc/webapps-drupal-core-1055-error-based-sql-injection/</guid>
<pubDate>Mon, 01 Jun 2026 19:52:18 +0200</pubDate>
<content:encoded><![CDATA[Drupal Core 10.5.5 - Error-Based SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></description>
<link>https://tsecurity.de/de/3559127/poc/webapps-yamcs-yamcs-core-5127-no-rate-limiting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559127/poc/webapps-yamcs-yamcs-core-5127-no-rate-limiting/</guid>
<pubDate>Sat, 30 May 2026 15:39:01 +0200</pubDate>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - User Enumeration]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - User Enumeration]]></description>
<link>https://tsecurity.de/de/3559126/poc/webapps-yamcs-yamcs-core-5127-user-enumeration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559126/poc/webapps-yamcs-yamcs-core-5127-user-enumeration/</guid>
<pubDate>Sat, 30 May 2026 15:39:00 +0200</pubDate>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - User Enumeration]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Notepad++ 8.9.6 - Arbitrary Code Execution]]></title>
<description><![CDATA[Notepad++ 8.9.6 - Arbitrary Code Execution]]></description>
<link>https://tsecurity.de/de/3559125/poc/remote-notepad-896-arbitrary-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559125/poc/remote-notepad-896-arbitrary-code-execution/</guid>
<pubDate>Sat, 30 May 2026 15:38:58 +0200</pubDate>
<content:encoded><![CDATA[Notepad++ 8.9.6 - Arbitrary Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - LDAP Injection]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - LDAP Injection]]></description>
<link>https://tsecurity.de/de/3559111/poc/webapps-yamcs-yamcs-core-5127-ldap-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559111/poc/webapps-yamcs-yamcs-core-5127-ldap-injection/</guid>
<pubDate>Sat, 30 May 2026 15:23:23 +0200</pubDate>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - LDAP Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Microsoft - NTLMv2 Hash Capture]]></title>
<description><![CDATA[Microsoft - NTLMv2 Hash Capture]]></description>
<link>https://tsecurity.de/de/3556532/poc/remote-microsoft-ntlmv2-hash-capture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556532/poc/remote-microsoft-ntlmv2-hash-capture/</guid>
<pubDate>Fri, 29 May 2026 10:38:16 +0200</pubDate>
<content:encoded><![CDATA[Microsoft - NTLMv2 Hash Capture]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MikroORM   7.0.13 - SQL Injection]]></title>
<description><![CDATA[MikroORM   7.0.13 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3556531/poc/webapps-mikroorm-7013-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556531/poc/webapps-mikroorm-7013-sql-injection/</guid>
<pubDate>Fri, 29 May 2026 10:38:15 +0200</pubDate>
<content:encoded><![CDATA[MikroORM   7.0.13 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ZTE H298A / H108N - Unauthenticated Credential Exposure]]></title>
<description><![CDATA[ZTE H298A / H108N - Unauthenticated Credential Exposure]]></description>
<link>https://tsecurity.de/de/3556485/poc/local-zte-h298a-h108n-unauthenticated-credential-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556485/poc/local-zte-h298a-h108n-unauthenticated-credential-exposure/</guid>
<pubDate>Fri, 29 May 2026 10:22:07 +0200</pubDate>
<content:encoded><![CDATA[ZTE H298A / H108N - Unauthenticated Credential Exposure]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ZTE ZXHN H188A V6 - Authentication Bypass]]></title>
<description><![CDATA[ZTE ZXHN H188A V6 - Authentication Bypass]]></description>
<link>https://tsecurity.de/de/3556484/poc/local-zte-zxhn-h188a-v6-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556484/poc/local-zte-zxhn-h188a-v6-authentication-bypass/</guid>
<pubDate>Fri, 29 May 2026 10:22:06 +0200</pubDate>
<content:encoded><![CDATA[ZTE ZXHN H188A V6 - Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion]]></title>
<description><![CDATA[ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion]]></description>
<link>https://tsecurity.de/de/3556483/poc/local-imagemagick-infinite-loop-in-the-miff-decoder-can-lead-to-cpu-exhaustion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556483/poc/local-imagemagick-infinite-loop-in-the-miff-decoder-can-lead-to-cpu-exhaustion/</guid>
<pubDate>Fri, 29 May 2026 10:22:05 +0200</pubDate>
<content:encoded><![CDATA[ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ZTE Routers  - Unauthenticated Denial of Service]]></title>
<description><![CDATA[ZTE Routers  - Unauthenticated Denial of Service]]></description>
<link>https://tsecurity.de/de/3556482/poc/local-zte-routers-unauthenticated-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556482/poc/local-zte-routers-unauthenticated-denial-of-service/</guid>
<pubDate>Fri, 29 May 2026 10:22:04 +0200</pubDate>
<content:encoded><![CDATA[ZTE Routers  - Unauthenticated Denial of Service]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Langflow 1.3.0 - Remote Code Execution]]></title>
<description><![CDATA[Langflow 1.3.0 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556481/poc/webapps-langflow-130-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556481/poc/webapps-langflow-130-remote-code-execution/</guid>
<pubDate>Fri, 29 May 2026 10:22:03 +0200</pubDate>
<content:encoded><![CDATA[Langflow 1.3.0 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556480/poc/webapps-quick-playground-for-wordpress-131-unauthenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556480/poc/webapps-quick-playground-for-wordpress-131-unauthenticated-remote-code-execution/</guid>
<pubDate>Fri, 29 May 2026 10:22:01 +0200</pubDate>
<content:encoded><![CDATA[Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion]]></title>
<description><![CDATA[Prodigy Commerce 3.3.0 - Local File Inclusion]]></description>
<link>https://tsecurity.de/de/3556479/poc/webapps-prodigy-commerce-330-local-file-inclusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556479/poc/webapps-prodigy-commerce-330-local-file-inclusion/</guid>
<pubDate>Fri, 29 May 2026 10:22:00 +0200</pubDate>
<content:encoded><![CDATA[Prodigy Commerce 3.3.0 - Local File Inclusion]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></title>
<description><![CDATA[MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556414/poc/webapps-mixphp-framework-2217-unsafe-deserialization-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556414/poc/webapps-mixphp-framework-2217-unsafe-deserialization-remote-code-execution/</guid>
<pubDate>Fri, 29 May 2026 09:54:52 +0200</pubDate>
<content:encoded><![CDATA[MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux Kernel -  Local Privilege Escalation]]></title>
<description><![CDATA[Linux Kernel -  Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3556413/poc/local-linux-kernel-local-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556413/poc/local-linux-kernel-local-privilege-escalation/</guid>
<pubDate>Fri, 29 May 2026 09:54:51 +0200</pubDate>
<content:encoded><![CDATA[Linux Kernel -  Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></title>
<description><![CDATA[CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></description>
<link>https://tsecurity.de/de/3556273/poc/webapps-cubecart-670-reflected-cross-site-scripting-xss-unauthenticated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556273/poc/webapps-cubecart-670-reflected-cross-site-scripting-xss-unauthenticated/</guid>
<pubDate>Fri, 29 May 2026 08:35:49 +0200</pubDate>
<content:encoded><![CDATA[CubeCart &lt; 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution]]></title>
<description><![CDATA[Wing FTP Server 8.1.3 - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556272/poc/remote-wing-ftp-server-813-authenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556272/poc/remote-wing-ftp-server-813-authenticated-remote-code-execution/</guid>
<pubDate>Fri, 29 May 2026 08:35:48 +0200</pubDate>
<content:encoded><![CDATA[Wing FTP Server 8.1.3 - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[dos] strongSwan 5.9.13 - DoS]]></title>
<description><![CDATA[strongSwan 5.9.13 - DoS]]></description>
<link>https://tsecurity.de/de/3556255/poc/dos-strongswan-5913-dos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556255/poc/dos-strongswan-5913-dos/</guid>
<pubDate>Fri, 29 May 2026 08:23:20 +0200</pubDate>
<content:encoded><![CDATA[strongSwan 5.9.13 - DoS]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow]]></title>
<description><![CDATA[strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow]]></description>
<link>https://tsecurity.de/de/3556254/poc/remote-strongswan-5913-libsimaka-eap-simaka-heap-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556254/poc/remote-strongswan-5913-libsimaka-eap-simaka-heap-buffer-overflow/</guid>
<pubDate>Fri, 29 May 2026 08:23:19 +0200</pubDate>
<content:encoded><![CDATA[strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux Kernel - Local Privilege Escalation]]></title>
<description><![CDATA[Linux Kernel - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3551243/poc/local-linux-kernel-local-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551243/poc/local-linux-kernel-local-privilege-escalation/</guid>
<pubDate>Wed, 27 May 2026 15:27:14 +0200</pubDate>
<content:encoded><![CDATA[Linux Kernel - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] EspoCRM 9.3.3 -  SSRF]]></title>
<description><![CDATA[EspoCRM 9.3.3 -  SSRF]]></description>
<link>https://tsecurity.de/de/3551242/poc/webapps-espocrm-933-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551242/poc/webapps-espocrm-933-ssrf/</guid>
<pubDate>Wed, 27 May 2026 15:27:12 +0200</pubDate>
<content:encoded><![CDATA[EspoCRM 9.3.3 -  SSRF]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></title>
<description><![CDATA[Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></description>
<link>https://tsecurity.de/de/3551241/poc/webapps-casdoor-3541-arbitrary-file-write-via-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551241/poc/webapps-casdoor-3541-arbitrary-file-write-via-path-traversal/</guid>
<pubDate>Wed, 27 May 2026 15:27:10 +0200</pubDate>
<content:encoded><![CDATA[Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] scramble - Remote Code Execution]]></title>
<description><![CDATA[scramble - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3551185/poc/webapps-scramble-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551185/poc/webapps-scramble-remote-code-execution/</guid>
<pubDate>Wed, 27 May 2026 15:09:36 +0200</pubDate>
<content:encoded><![CDATA[scramble - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Realtek rtl819x  - Local Privilege]]></title>
<description><![CDATA[Realtek rtl819x  - Local Privilege]]></description>
<link>https://tsecurity.de/de/3551119/poc/local-realtek-rtl819x-local-privilege/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551119/poc/local-realtek-rtl819x-local-privilege/</guid>
<pubDate>Wed, 27 May 2026 14:55:18 +0200</pubDate>
<content:encoded><![CDATA[Realtek rtl819x  - Local Privilege]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenCATS 0.9.7.4 - SQL Injection]]></title>
<description><![CDATA[OpenCATS 0.9.7.4 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3551118/poc/webapps-opencats-0974-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551118/poc/webapps-opencats-0974-sql-injection/</guid>
<pubDate>Wed, 27 May 2026 14:55:17 +0200</pubDate>
<content:encoded><![CDATA[OpenCATS 0.9.7.4 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[hardware] MeiG Smart FORGE_SLT711 - OS Command Injection]]></title>
<description><![CDATA[MeiG Smart FORGE_SLT711 - OS Command Injection]]></description>
<link>https://tsecurity.de/de/3551117/poc/hardware-meig-smart-forgeslt711-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551117/poc/hardware-meig-smart-forgeslt711-os-command-injection/</guid>
<pubDate>Wed, 27 May 2026 14:55:16 +0200</pubDate>
<content:encoded><![CDATA[MeiG Smart FORGE_SLT711 - OS Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></title>
<description><![CDATA[Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3548506/poc/webapps-grav-cms-200-beta2-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548506/poc/webapps-grav-cms-200-beta2-remote-code-execution/</guid>
<pubDate>Tue, 26 May 2026 17:26:55 +0200</pubDate>
<content:encoded><![CDATA[Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] cPanel - CRLF Injection]]></title>
<description><![CDATA[cPanel - CRLF Injection]]></description>
<link>https://tsecurity.de/de/3548445/poc/webapps-cpanel-crlf-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548445/poc/webapps-cpanel-crlf-injection/</guid>
<pubDate>Tue, 26 May 2026 17:10:30 +0200</pubDate>
<content:encoded><![CDATA[cPanel - CRLF Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></title>
<description><![CDATA[Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></description>
<link>https://tsecurity.de/de/3548444/poc/webapps-wordpress-temporary-login-plugin-100-temp-login-token-authentication-bypass-to-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548444/poc/webapps-wordpress-temporary-login-plugin-100-temp-login-token-authentication-bypass-to-account-takeover/</guid>
<pubDate>Tue, 26 May 2026 17:10:28 +0200</pubDate>
<content:encoded><![CDATA[Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></content:encoded>
</item>
<item>
<title><![CDATA[[hardware] D-Link DSL2600U - 'rom-0' Admin Password Disclosure]]></title>
<description><![CDATA[D-Link DSL2600U - 'rom-0' Admin Password Disclosure]]></description>
<link>https://tsecurity.de/de/3548443/poc/hardware-d-link-dsl2600u-rom-0-admin-password-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548443/poc/hardware-d-link-dsl2600u-rom-0-admin-password-disclosure/</guid>
<pubDate>Tue, 26 May 2026 17:10:26 +0200</pubDate>
<content:encoded><![CDATA[D-Link DSL2600U - 'rom-0' Admin Password Disclosure]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></title>
<description><![CDATA[Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></description>
<link>https://tsecurity.de/de/3548442/poc/webapps-apache-http-server-2466-modhttp2-double-free-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548442/poc/webapps-apache-http-server-2466-modhttp2-double-free-denial-of-service/</guid>
<pubDate>Tue, 26 May 2026 17:10:25 +0200</pubDate>
<content:encoded><![CDATA[Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux Kernel 6.8 - Local Privilege Escalation]]></title>
<description><![CDATA[Linux Kernel 6.8 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3548368/poc/local-linux-kernel-68-local-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548368/poc/local-linux-kernel-68-local-privilege-escalation/</guid>
<pubDate>Tue, 26 May 2026 16:56:24 +0200</pubDate>
<content:encoded><![CDATA[Linux Kernel 6.8 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] BookStack 25.12.1 - Denial of Service]]></title>
<description><![CDATA[BookStack 25.12.1 - Denial of Service]]></description>
<link>https://tsecurity.de/de/3536562/poc/webapps-bookstack-25121-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536562/poc/webapps-bookstack-25121-denial-of-service/</guid>
<pubDate>Thu, 21 May 2026 15:40:57 +0200</pubDate>
<content:encoded><![CDATA[BookStack 25.12.1 - Denial of Service]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FUXA  1.2.9 -  RCE]]></title>
<description><![CDATA[FUXA  1.2.9 -  RCE]]></description>
<link>https://tsecurity.de/de/3536561/poc/webapps-fuxa-129-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536561/poc/webapps-fuxa-129-rce/</guid>
<pubDate>Thu, 21 May 2026 15:40:55 +0200</pubDate>
<content:encoded><![CDATA[FUXA  1.2.9 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] solaredge - (CSRF-OOB-Injection)]]></title>
<description><![CDATA[solaredge - (CSRF-OOB-Injection)]]></description>
<link>https://tsecurity.de/de/3536560/poc/webapps-solaredge-csrf-oob-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536560/poc/webapps-solaredge-csrf-oob-injection/</guid>
<pubDate>Thu, 21 May 2026 15:40:53 +0200</pubDate>
<content:encoded><![CDATA[solaredge - (CSRF-OOB-Injection)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Cockpit 359 - RCE]]></title>
<description><![CDATA[Cockpit 359 - RCE]]></description>
<link>https://tsecurity.de/de/3536559/poc/webapps-cockpit-359-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536559/poc/webapps-cockpit-359-rce/</guid>
<pubDate>Thu, 21 May 2026 15:40:51 +0200</pubDate>
<content:encoded><![CDATA[Cockpit 359 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path]]></title>
<description><![CDATA[Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path]]></description>
<link>https://tsecurity.de/de/3536558/poc/local-lenovo-legionspace-17112-daservice-unquoted-service-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536558/poc/local-lenovo-legionspace-17112-daservice-unquoted-service-path/</guid>
<pubDate>Thu, 21 May 2026 15:40:48 +0200</pubDate>
<content:encoded><![CDATA[Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows Snipping Tool - NTLMv2 Hash Hijack]]></title>
<description><![CDATA[Windows Snipping Tool - NTLMv2 Hash Hijack]]></description>
<link>https://tsecurity.de/de/3520103/poc/local-windows-snipping-tool-ntlmv2-hash-hijack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520103/poc/local-windows-snipping-tool-ntlmv2-hash-hijack/</guid>
<pubDate>Fri, 15 May 2026 16:54:14 +0200</pubDate>
<content:encoded><![CDATA[Windows Snipping Tool - NTLMv2 Hash Hijack]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing]]></title>
<description><![CDATA[Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing]]></description>
<link>https://tsecurity.de/de/3519738/poc/local-remote-sunrise-helper-for-windows-202614-unauthenticated-filedirectory-listing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519738/poc/local-remote-sunrise-helper-for-windows-202614-unauthenticated-filedirectory-listing/</guid>
<pubDate>Fri, 15 May 2026 14:55:37 +0200</pubDate>
<content:encoded><![CDATA[Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution]]></title>
<description><![CDATA[Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3519737/poc/local-remote-sunrise-helper-for-windows-202614-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519737/poc/local-remote-sunrise-helper-for-windows-202614-remote-code-execution/</guid>
<pubDate>Fri, 15 May 2026 14:55:35 +0200</pubDate>
<content:encoded><![CDATA[Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></title>
<description><![CDATA[WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></description>
<link>https://tsecurity.de/de/3517059/poc/webapps-wordpress-plugin-supsystic-contact-form-1736-ssti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517059/poc/webapps-wordpress-plugin-supsystic-contact-form-1736-ssti/</guid>
<pubDate>Thu, 14 May 2026 16:39:46 +0200</pubDate>
<content:encoded><![CDATA[WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></title>
<description><![CDATA[ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></description>
<link>https://tsecurity.de/de/3516826/poc/webapps-epati-antikor-ngfw-201301-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516826/poc/webapps-epati-antikor-ngfw-201301-authentication-bypass/</guid>
<pubDate>Thu, 14 May 2026 15:12:27 +0200</pubDate>
<content:encoded><![CDATA[ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] PJPROJECT 2.16 - Heap Bufferoverflow]]></title>
<description><![CDATA[PJPROJECT 2.16 - Heap Bufferoverflow]]></description>
<link>https://tsecurity.de/de/3516825/poc/webapps-pjproject-216-heap-bufferoverflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516825/poc/webapps-pjproject-216-heap-bufferoverflow/</guid>
<pubDate>Thu, 14 May 2026 15:12:25 +0200</pubDate>
<content:encoded><![CDATA[PJPROJECT 2.16 - Heap Bufferoverflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Apache HertzBeat 1.8.0 - Remote Code Execution]]></title>
<description><![CDATA[Apache HertzBeat 1.8.0 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3516824/poc/webapps-apache-hertzbeat-180-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516824/poc/webapps-apache-hertzbeat-180-remote-code-execution/</guid>
<pubDate>Thu, 14 May 2026 15:12:22 +0200</pubDate>
<content:encoded><![CDATA[Apache HertzBeat 1.8.0 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] glances 4.5.2 - command injection]]></title>
<description><![CDATA[glances 4.5.2 - command injection]]></description>
<link>https://tsecurity.de/de/3513847/poc/webapps-glances-452-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513847/poc/webapps-glances-452-command-injection/</guid>
<pubDate>Wed, 13 May 2026 15:25:55 +0200</pubDate>
<content:encoded><![CDATA[glances 4.5.2 - command injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ninja Forms Uploads - Unauthenticated PHP File Upload]]></title>
<description><![CDATA[Ninja Forms Uploads - Unauthenticated PHP File Upload]]></description>
<link>https://tsecurity.de/de/3513846/poc/webapps-ninja-forms-uploads-unauthenticated-php-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513846/poc/webapps-ninja-forms-uploads-unauthenticated-php-file-upload/</guid>
<pubDate>Wed, 13 May 2026 15:25:53 +0200</pubDate>
<content:encoded><![CDATA[Ninja Forms Uploads - Unauthenticated PHP File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Flowise < 3.0.5 - Missing Authentication for Critical Function]]></title>
<description><![CDATA[Flowise < 3.0.5 - Missing Authentication for Critical Function]]></description>
<link>https://tsecurity.de/de/3513772/poc/webapps-flowise-305-missing-authentication-for-critical-function/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513772/poc/webapps-flowise-305-missing-authentication-for-critical-function/</guid>
<pubDate>Wed, 13 May 2026 15:07:27 +0200</pubDate>
<content:encoded><![CDATA[Flowise &lt; 3.0.5 - Missing Authentication for Critical Function]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] coreruleset 4.21.0 - Firewall Bypass]]></title>
<description><![CDATA[coreruleset 4.21.0 - Firewall Bypass]]></description>
<link>https://tsecurity.de/de/3513771/poc/webapps-coreruleset-4210-firewall-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513771/poc/webapps-coreruleset-4210-firewall-bypass/</guid>
<pubDate>Wed, 13 May 2026 15:07:25 +0200</pubDate>
<content:encoded><![CDATA[coreruleset 4.21.0 - Firewall Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] telnetd 2.7 - Buffer Overflow]]></title>
<description><![CDATA[telnetd 2.7 - Buffer Overflow]]></description>
<link>https://tsecurity.de/de/3496405/poc/remote-telnetd-27-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496405/poc/remote-telnetd-27-buffer-overflow/</guid>
<pubDate>Thu, 07 May 2026 16:42:01 +0200</pubDate>
<content:encoded><![CDATA[telnetd 2.7 - Buffer Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Bludit CMS 3.18.4 -  RCE]]></title>
<description><![CDATA[Bludit CMS 3.18.4 -  RCE]]></description>
<link>https://tsecurity.de/de/3496349/poc/webapps-bludit-cms-3184-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496349/poc/webapps-bludit-cms-3184-rce/</guid>
<pubDate>Thu, 07 May 2026 16:25:32 +0200</pubDate>
<content:encoded><![CDATA[Bludit CMS 3.18.4 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></title>
<description><![CDATA[LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></description>
<link>https://tsecurity.de/de/3496348/poc/webapps-luajit-211774638290-arbitrary-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496348/poc/webapps-luajit-211774638290-arbitrary-code-execution/</guid>
<pubDate>Thu, 07 May 2026 16:25:31 +0200</pubDate>
<content:encoded><![CDATA[LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ghost CMS 6.19.0 - SQLi]]></title>
<description><![CDATA[Ghost CMS 6.19.0 - SQLi]]></description>
<link>https://tsecurity.de/de/3496347/poc/webapps-ghost-cms-6190-sqli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496347/poc/webapps-ghost-cms-6190-sqli/</guid>
<pubDate>Thu, 07 May 2026 16:25:28 +0200</pubDate>
<content:encoded><![CDATA[Ghost CMS 6.19.0 - SQLi]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] NocoBase  2.0.27 - VM Sandbox Escape]]></title>
<description><![CDATA[NocoBase  2.0.27 - VM Sandbox Escape]]></description>
<link>https://tsecurity.de/de/3496276/poc/local-nocobase-2027-vm-sandbox-escape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496276/poc/local-nocobase-2027-vm-sandbox-escape/</guid>
<pubDate>Thu, 07 May 2026 16:11:12 +0200</pubDate>
<content:encoded><![CDATA[NocoBase  2.0.27 - VM Sandbox Escape]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></title>
<description><![CDATA[ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></description>
<link>https://tsecurity.de/de/3496275/poc/webapps-thingsboard-iot-platform-420-server-side-request-forgery-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496275/poc/webapps-thingsboard-iot-platform-420-server-side-request-forgery-ssrf/</guid>
<pubDate>Thu, 07 May 2026 16:11:11 +0200</pubDate>
<content:encoded><![CDATA[ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux nf_tables 6.19.3 - Local Privilege Escalation]]></title>
<description><![CDATA[Linux nf_tables 6.19.3 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3486371/poc/local-linux-nftables-6193-local-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486371/poc/local-linux-nftables-6193-local-privilege-escalation/</guid>
<pubDate>Mon, 04 May 2026 16:10:16 +0200</pubDate>
<content:encoded><![CDATA[Linux nf_tables 6.19.3 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation]]></title>
<description><![CDATA[Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3486370/poc/local-linux-kernel-procreaddirde-618-rc5-local-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486370/poc/local-linux-kernel-procreaddirde-618-rc5-local-privilege-escalation/</guid>
<pubDate>Mon, 04 May 2026 16:10:14 +0200</pubDate>
<content:encoded><![CDATA[Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[hardware] Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)]]></title>
<description><![CDATA[Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)]]></description>
<link>https://tsecurity.de/de/3486328/poc/hardware-linksys-e1200-2004-authenticated-stack-buffer-overflow-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486328/poc/hardware-linksys-e1200-2004-authenticated-stack-buffer-overflow-rce/</guid>
<pubDate>Mon, 04 May 2026 15:54:19 +0200</pubDate>
<content:encoded><![CDATA[Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></title>
<description><![CDATA[Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></description>
<link>https://tsecurity.de/de/3486282/poc/webapps-traccar-gps-tracking-system-6111-cross-site-websocket-hijacking-cswsh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486282/poc/webapps-traccar-gps-tracking-system-6111-cross-site-websocket-hijacking-cswsh/</guid>
<pubDate>Mon, 04 May 2026 15:40:50 +0200</pubDate>
<content:encoded><![CDATA[Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows 11 24H2 - Local Privilege Escalation]]></title>
<description><![CDATA[Windows 11 24H2 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3486281/poc/local-windows-11-24h2-local-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486281/poc/local-windows-11-24h2-local-privilege-escalation/</guid>
<pubDate>Mon, 04 May 2026 15:40:48 +0200</pubDate>
<content:encoded><![CDATA[Windows 11 24H2 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MindsDB  25.9.1.1 - Path Traversal]]></title>
<description><![CDATA[MindsDB  25.9.1.1 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3486280/poc/webapps-mindsdb-25911-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486280/poc/webapps-mindsdb-25911-path-traversal/</guid>
<pubDate>Mon, 04 May 2026 15:40:47 +0200</pubDate>
<content:encoded><![CDATA[MindsDB  25.9.1.1 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></title>
<description><![CDATA[FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></description>
<link>https://tsecurity.de/de/3477228/poc/webapps-fuxa-128-authentication-bypass-rce-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477228/poc/webapps-fuxa-128-authentication-bypass-rce-exploit/</guid>
<pubDate>Thu, 30 Apr 2026 12:38:57 +0200</pubDate>
<content:encoded><![CDATA[FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Python-Multipart 0.0.22 - Path Traversal]]></title>
<description><![CDATA[Python-Multipart 0.0.22 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3477117/poc/webapps-python-multipart-0022-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477117/poc/webapps-python-multipart-0022-path-traversal/</guid>
<pubDate>Thu, 30 Apr 2026 12:08:39 +0200</pubDate>
<content:encoded><![CDATA[Python-Multipart 0.0.22 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows 11 23H2 - Denial of Service (DoS)]]></title>
<description><![CDATA[Windows 11 23H2 - Denial of Service (DoS)]]></description>
<link>https://tsecurity.de/de/3477072/poc/local-windows-11-23h2-denial-of-service-dos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477072/poc/local-windows-11-23h2-denial-of-service-dos/</guid>
<pubDate>Thu, 30 Apr 2026 11:51:20 +0200</pubDate>
<content:encoded><![CDATA[Windows 11 23H2 - Denial of Service (DoS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Google Chrome  145.0.7632.75 - CSSFontFeatureValuesMap]]></title>
<description><![CDATA[Google Chrome  145.0.7632.75 - CSSFontFeatureValuesMap]]></description>
<link>https://tsecurity.de/de/3477071/poc/local-google-chrome-1450763275-cssfontfeaturevaluesmap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477071/poc/local-google-chrome-1450763275-cssfontfeaturevaluesmap/</guid>
<pubDate>Thu, 30 Apr 2026 11:51:19 +0200</pubDate>
<content:encoded><![CDATA[Google Chrome  145.0.7632.75 - CSSFontFeatureValuesMap]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Repetier-Server 1.4.10 - Path Traversal]]></title>
<description><![CDATA[Repetier-Server 1.4.10 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3477070/poc/webapps-repetier-server-1410-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477070/poc/webapps-repetier-server-1410-path-traversal/</guid>
<pubDate>Thu, 30 Apr 2026 11:51:18 +0200</pubDate>
<content:encoded><![CDATA[Repetier-Server 1.4.10 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] HUSTOJ Zip-Slip v26.01.24 -  RCE]]></title>
<description><![CDATA[HUSTOJ Zip-Slip v26.01.24 -  RCE]]></description>
<link>https://tsecurity.de/de/3477069/poc/webapps-hustoj-zip-slip-v260124-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477069/poc/webapps-hustoj-zip-slip-v260124-rce/</guid>
<pubDate>Thu, 30 Apr 2026 11:51:16 +0200</pubDate>
<content:encoded><![CDATA[HUSTOJ Zip-Slip v26.01.24 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows 11 25H2  - Heap Overflow]]></title>
<description><![CDATA[Windows 11 25H2  - Heap Overflow]]></description>
<link>https://tsecurity.de/de/3476886/poc/local-windows-11-25h2-heap-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476886/poc/local-windows-11-25h2-heap-overflow/</guid>
<pubDate>Thu, 30 Apr 2026 10:53:18 +0200</pubDate>
<content:encoded><![CDATA[Windows 11 25H2  - Heap Overflow]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,39ms -->