<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - ⚠️ PoC]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/poc.xml]]></link>
<description><![CDATA[Das Informationsportal für Proof of Concept Sicherheitslücken und Bedrohungen ist eine zentrale Anlaufstelle für IT-Sicherheitsexperten, Administratoren und alle Interessierten, die sich über die neuesten Entwicklungen und Nachrichten im Bereich der Cybersicherheit informieren möchten. Das Portal bietet einen umfassenden Überblick über aktuelle Sicherheitslücken, Proof of Concept Exploits und die damit verbundenen Bedrohungen.

Die Bedeutung eines solchen Portals kann nicht hoch genug eingeschätzt werden, da es ermöglicht, schnell auf neue Schwachstellen zu reagieren und entsprechende Gegenmaßnahmen zu ergreifen. In einer Zeit, in der die Anzahl und Komplexität von Cyberangriffen stetig zunimmt, ist es entscheidend, auf dem neuesten Stand der Sicherheitstechnik zu bleiben und sich über potenzielle Bedrohungen zu informieren.

Das Portal bietet detaillierte Informationen zu verschiedenen Sicherheitslücken und den dazugehörigen Exploits, die von Forschern entdeckt und veröffentlicht werden. Diese Informationen sind von unschätzbarem Wert, da sie es IT-Profis ermöglichen, ihre Systeme zu überprüfen und zu schützen, bevor diese Schwachstellen von bösartigen Akteuren ausgenutzt werden können. Darüber hinaus werden regelmäßige Updates und Patches bereitgestellt, die zur Behebung dieser Sicherheitslücken beitragen.

Neben der Bereitstellung von Informationen über Schwachstellen und Exploits, bietet das Portal auch Ressourcen für Bildung und Weiterbildung im Bereich der Cybersicherheit. Artikel, Leitfäden und Best Practices helfen dabei, das Bewusstsein für Sicherheitsrisiken zu schärfen und das Wissen über die Abwehr von Cyberbedrohungen zu vertiefen.

Verwenden Sie Exploits nur auf Systemen, die Sie besitzen oder kontrollieren.
Erstellen Sie vor der Verwendung von Exploits ein Backup Ihrer Daten.
Verwenden Sie Exploits nur auf einem isolierten System, das nicht mit dem Internet verbunden ist.
Halten Sie Ihr Betriebssystem und Ihre Software auf dem neuesten Stand.
Reverse Engineering ist die Kunst, technologische Produkte oder Systeme rückwärts zu analysieren, um ihre Funktionen, Komponenten und Herstellungsverfahren zu verstehen. Reverse Engineering kann sowohl für Innovation und Wettbewerb als auch für Sicherheit und Schutz eingesetzt werden. Auf tsecurity.de finden Sie aktuelle Informationen und Ressourcen zu Reverse Engineering.]]></description>
<language>de-DE</language>
<lastBuildDate>Sun, 26 Jul 2026 12:59:44 +0200</lastBuildDate>
<pubDate>Sun, 26 Jul 2026 12:59:44 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>⚠️ PoC</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - ⚠️ PoC]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/poc.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/poc.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Microsoft Excel LTSC 2024 Remote Code Execution]]></title>
<description><![CDATA[Topic: Microsoft Excel LTSC 2024 Remote Code Execution Risk: High Text:# Titles: Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)  # Author: nu11secur1ty  # Date: 06/16/2025  # Vendor: Micros...]]></description>
<link>https://tsecurity.de/de/3693433/it+reverse+engineering/sicherheitsluecken/proof+of+concept/microsoft+excel+ltsc+2024+remote+code+execution/</link>
<pubDate>Sat, 25 Jul 2026 10:05:05 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Microsoft Excel LTSC 2024 Remote Code Execution Risk: High Text:# Titles: Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)  # Author: nu11secur1ty  # Date: 06/16/2025  # Vendor: Micros...]]></content:encoded>
</item>
<item>
<title><![CDATA[Langflow 1.2.x Remote Code Execution (RCE)]]></title>
<description><![CDATA[Topic: Langflow 1.2.x Remote Code Execution (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Langflow 1.2.x - Remote Code Execution (RCE)  # Date: 2025-07-11  # Exploit Author: Ra...]]></description>
<link>https://tsecurity.de/de/3693432/it+reverse+engineering/sicherheitsluecken/proof+of+concept/langflow+12x+remote+code+execution+rce/</link>
<pubDate>Sat, 25 Jul 2026 10:05:03 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Langflow 1.2.x Remote Code Execution (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Langflow 1.2.x - Remote Code Execution (RCE)  # Date: 2025-07-11  # Exploit Author: Ra...]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious XDG Desktop File]]></title>
<description><![CDATA[Topic: Malicious XDG Desktop File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693431/it+reverse+engineering/sicherheitsluecken/proof+of+concept/malicious+xdg+desktop+file/</link>
<pubDate>Sat, 25 Jul 2026 10:05:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Malicious XDG Desktop File Risk: Medium Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE]]></title>
<description><![CDATA[Topic: Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE Risk: High Text:package main    import (  	"flag"  	"fmt"  	"io"  	"net/http"  	"net/url"  	"os"  	"strings"  )    /*  Shenzhen Aitemi M300 Wi-...]]></description>
<link>https://tsecurity.de/de/3693430/it+reverse+engineering/sicherheitsluecken/proof+of+concept/shenzhen+aitemi+m300+wi-fi+repeater+unauthenticated+rce/</link>
<pubDate>Sat, 25 Jul 2026 10:05:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE Risk: High Text:package main    import (  	"flag"  	"fmt"  	"io"  	"net/http"  	"net/url"  	"os"  	"strings"  )    /*  Shenzhen Aitemi M300 Wi-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Pandora ITSM Authenticated Command Injection]]></title>
<description><![CDATA[Topic: Pandora ITSM Authenticated Command Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693429/it+reverse+engineering/sicherheitsluecken/proof+of+concept/pandora+itsm+authenticated+command+injection/</link>
<pubDate>Sat, 25 Jul 2026 10:04:59 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Pandora ITSM Authenticated Command Injection Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco ISE 3.0 Remote Code Execution]]></title>
<description><![CDATA[Topic: Cisco ISE 3.0 Remote Code Execution Risk: High Text:# Exploit Title: Cisco ISE 3.0 - Remote Code Execution (RCE)  # Exploit Author: @ibrahimsql ibrahimsql.com  # Exploit Author's ...]]></description>
<link>https://tsecurity.de/de/3693428/it+reverse+engineering/sicherheitsluecken/proof+of+concept/cisco+ise+30+remote+code+execution/</link>
<pubDate>Sat, 25 Jul 2026 10:04:57 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Cisco ISE 3.0 Remote Code Execution Risk: High Text:# Exploit Title: Cisco ISE 3.0 - Remote Code Execution (RCE)  # Exploit Author: @ibrahimsql ibrahimsql.com  # Exploit Author's ...]]></content:encoded>
</item>
<item>
<title><![CDATA[JetBrains TeamCity 2023.11.4 Authentication Bypass]]></title>
<description><![CDATA[Topic: JetBrains TeamCity 2023.11.4 Authentication Bypass Risk: High Text:#!/usr/bin/env python3  # -*- coding: utf-8 -*-  """  # Exploit Title: JetBrains TeamCity 2023.11.4 - Authentication Bypass  # ...]]></description>
<link>https://tsecurity.de/de/3693427/it+reverse+engineering/sicherheitsluecken/proof+of+concept/jetbrains+teamcity+2023114+authentication+bypass/</link>
<pubDate>Sat, 25 Jul 2026 10:04:56 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: JetBrains TeamCity 2023.11.4 Authentication Bypass Risk: High Text:#!/usr/bin/env python3  # -*- coding: utf-8 -*-  """  # Exploit Title: JetBrains TeamCity 2023.11.4 - Authentication Bypass  # ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Projectworlds Online Admission System 1.0 SQL Injection]]></title>
<description><![CDATA[Topic: Projectworlds Online Admission System 1.0 SQL Injection Risk: Medium Text:/*   * Title           : projectworlds Online Admission System 1.0 - SQL Injection   * Author       : Byte Reaper   * CVE      ...]]></description>
<link>https://tsecurity.de/de/3693426/it+reverse+engineering/sicherheitsluecken/proof+of+concept/projectworlds+online+admission+system+10+sql+injection/</link>
<pubDate>Sat, 25 Jul 2026 10:04:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Projectworlds Online Admission System 1.0 SQL Injection Risk: Medium Text:/*   * Title           : projectworlds Online Admission System 1.0 - SQL Injection   * Author       : Byte Reaper   * CVE      ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Tenda AC20 16.03.08.12 Command Injection]]></title>
<description><![CDATA[Topic: Tenda AC20 16.03.08.12 Command Injection Risk: Medium Text:/*   * Exploit Title : Tenda AC20 16.03.08.12 - Command Injection   * Author       : Byte Reaper   * CVE          : CVE-2025-90...]]></description>
<link>https://tsecurity.de/de/3693425/it+reverse+engineering/sicherheitsluecken/proof+of+concept/tenda+ac20+16030812+command+injection/</link>
<pubDate>Sat, 25 Jul 2026 10:04:53 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Tenda AC20 16.03.08.12 Command Injection Risk: Medium Text:/*   * Exploit Title : Tenda AC20 16.03.08.12 - Command Injection   * Author       : Byte Reaper   * CVE          : CVE-2025-90...]]></content:encoded>
</item>
<item>
<title><![CDATA[DOS Baby POP3 Server 1.04]]></title>
<description><![CDATA[Topic: DOS Baby POP3 Server 1.04 Risk: Medium Text:# Exploit Title: DOS Baby POP3 Server 1.04  # Date: 12/08/2025  # Exploit Author: Érick Sousa (https://www.linkedin.com/in/eri...]]></description>
<link>https://tsecurity.de/de/3693424/it+reverse+engineering/sicherheitsluecken/proof+of+concept/dos+baby+pop3+server+104/</link>
<pubDate>Sat, 25 Jul 2026 10:04:52 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: DOS Baby POP3 Server 1.04 Risk: Medium Text:# Exploit Title: DOS Baby POP3 Server 1.04  # Date: 12/08/2025  # Exploit Author: Érick Sousa (https://www.linkedin.com/in/eri...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ghost CMS 5.59.1 Arbitrary File Read]]></title>
<description><![CDATA[Topic: Ghost CMS 5.59.1 Arbitrary File Read Risk: Medium Text:#!/usr/bin/env python3  # -*- coding: utf-8 -*-  """  # Exploit Title: Ghost CMS 5.59.1 - Arbitrary File Read  # Date: 2023-09-...]]></description>
<link>https://tsecurity.de/de/3693423/it+reverse+engineering/sicherheitsluecken/proof+of+concept/ghost+cms+5591+arbitrary+file+read/</link>
<pubDate>Sat, 25 Jul 2026 10:04:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Ghost CMS 5.59.1 Arbitrary File Read Risk: Medium Text:#!/usr/bin/env python3  # -*- coding: utf-8 -*-  """  # Exploit Title: Ghost CMS 5.59.1 - Arbitrary File Read  # Date: 2023-09-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ultimate Member WordPress Plugin 2.6.6 Privilege Escalation]]></title>
<description><![CDATA[Topic: Ultimate Member WordPress Plugin 2.6.6 Privilege Escalation Risk: Medium Text:#!/usr/bin/env python3    # Exploit Title: Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation  # Exploit Author: Gur...]]></description>
<link>https://tsecurity.de/de/3693422/it+reverse+engineering/sicherheitsluecken/proof+of+concept/ultimate+member+wordpress+plugin+266+privilege+escalation/</link>
<pubDate>Sat, 25 Jul 2026 10:04:49 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Ultimate Member WordPress Plugin 2.6.6 Privilege Escalation Risk: Medium Text:#!/usr/bin/env python3    # Exploit Title: Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation  # Exploit Author: Gur...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sitecore XP Post-Authentication File Upload]]></title>
<description><![CDATA[Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693421/it+reverse+engineering/sicherheitsluecken/proof+of+concept/sitecore+xp+post-authentication+file+upload/</link>
<pubDate>Sat, 25 Jul 2026 10:04:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Commvault CLI Argument Injection / Traversal / Remote Code Execution]]></title>
<description><![CDATA[Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693420/it+reverse+engineering/sicherheitsluecken/proof+of+concept/commvault+cli+argument+injection+traversal+remote+code+execution/</link>
<pubDate>Sat, 25 Jul 2026 10:04:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Belkin F9K1009 F9K1010 2.00.04/2.00.09 Hard Coded Credentials]]></title>
<description><![CDATA[Topic: Belkin F9K1009 F9K1010 2.00.04/2.00.09 Hard Coded Credentials Risk: High Text:/*   * Title           : Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials   * Author       : Byte Reaper   * CVE...]]></description>
<link>https://tsecurity.de/de/3693419/it+reverse+engineering/sicherheitsluecken/proof+of+concept/belkin+f9k1009+f9k1010+2000420009+hard+coded+credentials/</link>
<pubDate>Sat, 25 Jul 2026 10:04:45 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Belkin F9K1009 F9K1010 2.00.04/2.00.09 Hard Coded Credentials Risk: High Text:/*   * Title           : Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials   * Author       : Byte Reaper   * CVE...]]></content:encoded>
</item>
<item>
<title><![CDATA[SugarCRM unauthenticated Remote Code Execution (RCE)]]></title>
<description><![CDATA[Topic: SugarCRM unauthenticated Remote Code Execution (RCE) Risk: High Text:# Exploit Title: SugarCRM unauthenticated Remote Code Execution (RCE)  # Exploit Author: DANG  # Vendor Homepage: https://www.s...]]></description>
<link>https://tsecurity.de/de/3693418/it+reverse+engineering/sicherheitsluecken/proof+of+concept/sugarcrm+unauthenticated+remote+code+execution+rce/</link>
<pubDate>Sat, 25 Jul 2026 10:04:43 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: SugarCRM unauthenticated Remote Code Execution (RCE) Risk: High Text:# Exploit Title: SugarCRM unauthenticated Remote Code Execution (RCE)  # Exploit Author: DANG  # Vendor Homepage: https://www.s...]]></content:encoded>
</item>
<item>
<title><![CDATA[Vvveb CMS 1.0.5 Remote Code Execution]]></title>
<description><![CDATA[Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3693417/it+reverse+engineering/sicherheitsluecken/proof+of+concept/vvveb+cms+105+remote+code+execution/</link>
<pubDate>Sat, 25 Jul 2026 10:04:42 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Swagger UI 1.0.3 Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[Topic: Swagger UI 1.0.3 Cross-Site Scripting (XSS) Risk: Low Text:/*   * Author       : Byte Reaper   * Telegram     : @ByteReaper0   * CVE          : CVE-2025-8191   * Title : Swagger UI 1.0.3...]]></description>
<link>https://tsecurity.de/de/3693416/it+reverse+engineering/sicherheitsluecken/proof+of+concept/swagger+ui+103+cross-site+scripting+xss/</link>
<pubDate>Sat, 25 Jul 2026 10:04:41 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Swagger UI 1.0.3 Cross-Site Scripting (XSS) Risk: Low Text:/*   * Author       : Byte Reaper   * Telegram     : @ByteReaper0   * CVE          : CVE-2025-8191   * Title : Swagger UI 1.0.3...]]></content:encoded>
</item>
<item>
<title><![CDATA[Flowise 3.0.4 Remote Code Execution]]></title>
<description><![CDATA[Topic: Flowise 3.0.4 Remote Code Execution Risk: High Text:# Exploit Title: Flowise 3.0.4 - Remote Code Execution (RCE)  # Date: 10/11/2025  # Exploit Author: [nltt0] (https://github.com...]]></description>
<link>https://tsecurity.de/de/3693415/it+reverse+engineering/sicherheitsluecken/proof+of+concept/flowise+304+remote+code+execution/</link>
<pubDate>Sat, 25 Jul 2026 10:04:39 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Flowise 3.0.4 Remote Code Execution Risk: High Text:# Exploit Title: Flowise 3.0.4 - Remote Code Execution (RCE)  # Date: 10/11/2025  # Exploit Author: [nltt0] (https://github.com...]]></content:encoded>
</item>
<item>
<title><![CDATA[MonstaFTP Unauthenticated File Upload]]></title>
<description><![CDATA[Topic: MonstaFTP Unauthenticated File Upload Risk: Medium Text:# Titles: MonstaFTP Unauthenticated File Upload CVE-2025-34299  # Author: ibrahimsql  # Date: 11/21/2025  # Vendor: https://www...]]></description>
<link>https://tsecurity.de/de/3693414/it+reverse+engineering/sicherheitsluecken/proof+of+concept/monstaftp+unauthenticated+file+upload/</link>
<pubDate>Sat, 25 Jul 2026 10:04:38 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: MonstaFTP Unauthenticated File Upload Risk: Medium Text:# Titles: MonstaFTP Unauthenticated File Upload CVE-2025-34299  # Author: ibrahimsql  # Date: 11/21/2025  # Vendor: https://www...]]></content:encoded>
</item>
<item>
<title><![CDATA[Mbed TLS 3.6.4 Use-After-Free]]></title>
<description><![CDATA[Topic: Mbed TLS 3.6.4 Use-After-Free Risk: High Text:/*   * Exploit Title: Mbed TLS 3.6.4 - Use-After-Free   * Google Dork: N/A   * Date: 2025-08-29   * Exploit Author: Byte Reaper...]]></description>
<link>https://tsecurity.de/de/3693413/it+reverse+engineering/sicherheitsluecken/proof+of+concept/mbed+tls+364+use-after-free/</link>
<pubDate>Sat, 25 Jul 2026 10:04:36 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Mbed TLS 3.6.4 Use-After-Free Risk: High Text:/*   * Exploit Title: Mbed TLS 3.6.4 - Use-After-Free   * Google Dork: N/A   * Date: 2025-08-29   * Exploit Author: Byte Reaper...]]></content:encoded>
</item>
<item>
<title><![CDATA[dotCMS 25.07.02-1 Authenticated Blind SQL Injection]]></title>
<description><![CDATA[Topic: dotCMS 25.07.02-1 Authenticated Blind SQL Injection Risk: Medium Text:#!/usr/bin/env python3    # Exploit Title: dotCMS 25.07.02-1 - Authenticated Blind SQL Injection  # Google Dork: N/A  # Date: 2...]]></description>
<link>https://tsecurity.de/de/3693412/it+reverse+engineering/sicherheitsluecken/proof+of+concept/dotcms+250702-1+authenticated+blind+sql+injection/</link>
<pubDate>Sat, 25 Jul 2026 10:04:35 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: dotCMS 25.07.02-1 Authenticated Blind SQL Injection Risk: Medium Text:#!/usr/bin/env python3    # Exploit Title: dotCMS 25.07.02-1 - Authenticated Blind SQL Injection  # Google Dork: N/A  # Date: 2...]]></content:encoded>
</item>
<item>
<title><![CDATA[Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure]]></title>
<description><![CDATA[Topic: Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure Risk: Low Text:/*   * Exploit Title : Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure   * Author       : Byte Reaper   *...]]></description>
<link>https://tsecurity.de/de/3693411/it+reverse+engineering/sicherheitsluecken/proof+of+concept/birth+chart+compatibility+wordpress+plugin+20+full+path+disclosure/</link>
<pubDate>Sat, 25 Jul 2026 10:04:33 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure Risk: Low Text:/*   * Exploit Title : Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure   * Author       : Byte Reaper   *...]]></content:encoded>
</item>
<item>
<title><![CDATA[LangChain Core - Serialization Injection to Jinja2 SSTI/RCE]]></title>
<description><![CDATA[Topic: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE  Risk: High Text:# Exploit Title: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE   # Date: 2025-12-29  # Exploit Author: Mohammed I...]]></description>
<link>https://tsecurity.de/de/3693410/it+reverse+engineering/sicherheitsluecken/proof+of+concept/langchain+core+-+serialization+injection+to+jinja2+sstirce/</link>
<pubDate>Sat, 25 Jul 2026 10:04:32 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE  Risk: High Text:# Exploit Title: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE   # Date: 2025-12-29  # Exploit Author: Mohammed I...]]></content:encoded>
</item>
<item>
<title><![CDATA[deephas < = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS]]></title>
<description><![CDATA[Topic: deephas < = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS Risk: High Text:#!/usr/bin/env python3  #  # Exploit Title: deephas < = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS  #...]]></description>
<link>https://tsecurity.de/de/3693409/it+reverse+engineering/sicherheitsluecken/proof+of+concept/deephas+107+-+prototype+pollution+leading+to+arbitrary+code+execution+dos/</link>
<pubDate>Sat, 25 Jul 2026 10:04:31 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: deephas &lt; = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS Risk: High Text:#!/usr/bin/env python3  #  # Exploit Title: deephas &lt; = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS  #...]]></content:encoded>
</item>
<item>
<title><![CDATA[aiohttp 3.9.1 Directory Traversal]]></title>
<description><![CDATA[Topic: aiohttp 3.9.1 Directory Traversal Risk: Medium Text:# Exploit Title: Python aiohttp directory traversal PoC (CVE-2024-23334)  # Google Dork: N/A  # Date: 2025-10-06  # Exploit Aut...]]></description>
<link>https://tsecurity.de/de/3693408/it+reverse+engineering/sicherheitsluecken/proof+of+concept/aiohttp+391+directory+traversal/</link>
<pubDate>Sat, 25 Jul 2026 10:04:29 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: aiohttp 3.9.1 Directory Traversal Risk: Medium Text:# Exploit Title: Python aiohttp directory traversal PoC (CVE-2024-23334)  # Google Dork: N/A  # Date: 2025-10-06  # Exploit Aut...]]></content:encoded>
</item>
<item>
<title><![CDATA[Siklu EtherHaul Series EH-8010 Remote Command Execution]]></title>
<description><![CDATA[Topic: Siklu EtherHaul Series EH-8010 Remote Command Execution Risk: High Text:# Exploit Title:Siklu EtherHaul Series EH-8010 - Remote Command Execution  # Shodan Dork: "EH-8010" or "EH-1200"  # Date: 2025-...]]></description>
<link>https://tsecurity.de/de/3693407/it+reverse+engineering/sicherheitsluecken/proof+of+concept/siklu+etherhaul+series+eh-8010+remote+command+execution/</link>
<pubDate>Sat, 25 Jul 2026 10:04:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Siklu EtherHaul Series EH-8010 Remote Command Execution Risk: High Text:# Exploit Title:Siklu EtherHaul Series EH-8010 - Remote Command Execution  # Shodan Dork: "EH-8010" or "EH-1200"  # Date: 2025-...]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Chrome <  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free]]></title>
<description><![CDATA[Topic: Google Chrome <  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free Risk: High Text:# Exploit Title: Google Chrome <  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free  # Date: 2026-02-23  # Exploit Author: ...]]></description>
<link>https://tsecurity.de/de/3693406/it+reverse+engineering/sicherheitsluecken/proof+of+concept/google+chrome+1450763275+-+cssfontfeaturevaluesmap+use-after-free/</link>
<pubDate>Sat, 25 Jul 2026 10:04:26 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Google Chrome &lt;  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free Risk: High Text:# Exploit Title: Google Chrome &lt;  145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free  # Date: 2026-02-23  # Exploit Author: ...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution]]></title>
<description><![CDATA[Topic: OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution  # CVE:             CV...]]></description>
<link>https://tsecurity.de/de/3693405/it+reverse+engineering/sicherheitsluecken/proof+of+concept/openclaw+toolsexecsafebins+2026222+remote+code+execution/</link>
<pubDate>Sat, 25 Jul 2026 10:04:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: OpenClaw tools.exec.safeBins &lt; = 2026.2.22 Remote Code Execution Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw tools.exec.safeBins &lt; = 2026.2.22 Remote Code Execution  # CVE:             CV...]]></content:encoded>
</item>
<item>
<title><![CDATA[Kanboard < = 1.2.50 Authenticated SQL Injection]]></title>
<description><![CDATA[Topic: Kanboard < = 1.2.50 Authenticated SQL Injection  Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        Kanboard Authenticated SQL Injection in ProjectPermissionController  # CVE:    ...]]></description>
<link>https://tsecurity.de/de/3693404/it+reverse+engineering/sicherheitsluecken/proof+of+concept/kanboard+1250+authenticated+sql+injection/</link>
<pubDate>Sat, 25 Jul 2026 10:04:24 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Kanboard &lt; = 1.2.50 Authenticated SQL Injection  Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        Kanboard Authenticated SQL Injection in ProjectPermissionController  # CVE:    ...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw <  2026.3.28 Discord Text Approval Authorization Bypass]]></title>
<description><![CDATA[Topic: OpenClaw <  2026.3.28 Discord Text Approval Authorization Bypass Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw Discord Text Approval Authorization Bypass  # CVE: CVE-2026-41303  # Date: 20...]]></description>
<link>https://tsecurity.de/de/3693403/it+reverse+engineering/sicherheitsluecken/proof+of+concept/openclaw+2026328+discord+text+approval+authorization+bypass/</link>
<pubDate>Sat, 25 Jul 2026 10:04:22 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: OpenClaw &lt;  2026.3.28 Discord Text Approval Authorization Bypass Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw Discord Text Approval Authorization Bypass  # CVE: CVE-2026-41303  # Date: 20...]]></content:encoded>
</item>
<item>
<title><![CDATA[Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Vulnerability - Realistic Full Chain Attack on F-16 Avionics (Ground]]></title>
<description><![CDATA[Topic: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Vulnerability - Realistic Full Chain Attack on F-16 Avionics (Ground Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Full Chain - Realistic F-16...]]></description>
<link>https://tsecurity.de/de/3693402/it+reverse+engineering/sicherheitsluecken/proof+of+concept/green+hills+integrity+rtos+ipcomshell+telnet+format+string+vulnerability+-+realistic+full+chain+attack+on+f-16+avionics+ground/</link>
<pubDate>Sat, 25 Jul 2026 10:04:21 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Vulnerability - Realistic Full Chain Attack on F-16 Avionics (Ground Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Full Chain - Realistic F-16...]]></content:encoded>
</item>
<item>
<title><![CDATA[NiceGUI 3.6.1 Path Traversal]]></title>
<description><![CDATA[Topic: NiceGUI 3.6.1 Path Traversal Risk: Medium Text:# Exploit Title: NiceGUI 3.6.1 - Path Traversal   # Author: Mohammed Idrees Banyamer  # Instagram: @banyamer_security  # GitHub...]]></description>
<link>https://tsecurity.de/de/3693401/it+reverse+engineering/sicherheitsluecken/proof+of+concept/nicegui+361+path+traversal/</link>
<pubDate>Sat, 25 Jul 2026 10:04:20 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: NiceGUI 3.6.1 Path Traversal Risk: Medium Text:# Exploit Title: NiceGUI 3.6.1 - Path Traversal   # Author: Mohammed Idrees Banyamer  # Instagram: @banyamer_security  # GitHub...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service]]></title>
<description><![CDATA[Topic: Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Risk: Medium Text:# Exploit Title: Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service  # Google Dork: intext:"Apache/2.4.66" "...]]></description>
<link>https://tsecurity.de/de/3693400/it+reverse+engineering/sicherheitsluecken/proof+of+concept/apache+http+server+2466+modhttp2+double-free+denial+of+service/</link>
<pubDate>Sat, 25 Jul 2026 10:04:17 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Risk: Medium Text:# Exploit Title: Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service  # Google Dork: intext:"Apache/2.4.66" "...]]></content:encoded>
</item>
<item>
<title><![CDATA[ePati Antikor NGFW 2.0.1301  Authentication Bypass]]></title>
<description><![CDATA[Topic: ePati Antikor NGFW 2.0.1301  Authentication Bypass Risk: Medium Text:# Exploit Title: ePati Antikor NGFW 2.0.1301 -  Authentication Bypass   # Date: 2026-04-13  # Exploit Author: [SADIK ERTÜRK]  ...]]></description>
<link>https://tsecurity.de/de/3693399/it+reverse+engineering/sicherheitsluecken/proof+of+concept/epati+antikor+ngfw+201301+authentication+bypass/</link>
<pubDate>Sat, 25 Jul 2026 10:04:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: ePati Antikor NGFW 2.0.1301  Authentication Bypass Risk: Medium Text:# Exploit Title: ePati Antikor NGFW 2.0.1301 -  Authentication Bypass   # Date: 2026-04-13  # Exploit Author: [SADIK ERTÜRK]  ...]]></content:encoded>
</item>
<item>
<title><![CDATA[XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057]]></title>
<description><![CDATA[Topic: XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 Risk: Low Text:#!/usr/bin/env python3  """  XenForo XSS CVE Scanner  Author: Xasthur    Passive detection for CVE-2026-35055, CVE-2026-35054, ...]]></description>
<link>https://tsecurity.de/de/3693398/it+reverse+engineering/sicherheitsluecken/proof+of+concept/xenforo+xss+cve+scanner+-+passive+detection+tool+for+cve-2026-35055+cve-2026-35054+cve-2026-35057/</link>
<pubDate>Sat, 25 Jul 2026 10:04:12 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 Risk: Low Text:#!/usr/bin/env python3  """  XenForo XSS CVE Scanner  Author: Xasthur    Passive detection for CVE-2026-35055, CVE-2026-35054, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[PraisonAI CodeAgent < = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution]]></title>
<description><![CDATA[Topic: PraisonAI CodeAgent < = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution Risk: High Text:#!/usr/bin/env python3  # Exploit Title:         PraisonAI CodeAgent < = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM ...]]></description>
<link>https://tsecurity.de/de/3693397/it+reverse+engineering/sicherheitsluecken/proof+of+concept/praisonai+codeagent+1677+remote+code+execution+rce+via+unsandboxed+llm+code+execution/</link>
<pubDate>Sat, 25 Jul 2026 10:04:08 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: PraisonAI CodeAgent &lt; = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution Risk: High Text:#!/usr/bin/env python3  # Exploit Title:         PraisonAI CodeAgent &lt; = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Edge < = 150.0.4078.48 (Chromium-based) Type Confusion RCE]]></title>
<description><![CDATA[Topic: Microsoft Edge < = 150.0.4078.48 (Chromium-based) Type Confusion RCE Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        Microsoft Edge < = 150.0.4078.48 (Chromium-based) Type Confusion RCE  # CVE:    ...]]></description>
<link>https://tsecurity.de/de/3693396/it+reverse+engineering/sicherheitsluecken/proof+of+concept/microsoft+edge+1500407848+chromium-based+type+confusion+rce/</link>
<pubDate>Sat, 25 Jul 2026 10:04:07 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Microsoft Edge &lt; = 150.0.4078.48 (Chromium-based) Type Confusion RCE Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        Microsoft Edge &lt; = 150.0.4078.48 (Chromium-based) Type Confusion RCE  # CVE:    ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)]]></title>
<description><![CDATA[Topic: Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)  # Goog...]]></description>
<link>https://tsecurity.de/de/3679245/it+reverse+engineering/sicherheitsluecken/proof+of+concept/joomla+page+builder+ck+3510+-+unauthenticated+arbitrary+file+upload+rce/</link>
<pubDate>Sun, 19 Jul 2026 11:36:24 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Joomla Page Builder CK &lt; = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Joomla Page Builder CK &lt; = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)  # Goog...]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></title>
<description><![CDATA[Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></description>
<link>https://tsecurity.de/de/3654511/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+atarim+wordpress+plugin+422+-+sensitive+information+exposure/</link>
<pubDate>Wed, 08 Jul 2026 15:54:08 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></title>
<description><![CDATA[Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3654510/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+krayin+crm+v22x+-+authenticated+remote+code+execution/</link>
<pubDate>Wed, 08 Jul 2026 15:54:07 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Langflow 1.9.0 - RCE]]></title>
<description><![CDATA[Langflow 1.9.0 - RCE]]></description>
<link>https://tsecurity.de/de/3654473/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+langflow+190+-+rce/</link>
<pubDate>Wed, 08 Jul 2026 15:36:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Langflow 1.9.0 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></title>
<description><![CDATA[Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></description>
<link>https://tsecurity.de/de/3654472/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+joomla+page+builder+ck+3510+-+arbitrary+file+upload/</link>
<pubDate>Wed, 08 Jul 2026 15:36:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MCPJam Inspector - Remote Code Execution]]></title>
<description><![CDATA[MCPJam Inspector - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3651885/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+mcpjam+inspector+-+remote+code+execution/</link>
<pubDate>Tue, 07 Jul 2026 16:39:54 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MCPJam Inspector - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ProtonVPN v4.4.1 - Unquoted Service Path]]></title>
<description><![CDATA[ProtonVPN v4.4.1 - Unquoted Service Path]]></description>
<link>https://tsecurity.de/de/3651801/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+protonvpn+v441+-+unquoted+service+path/</link>
<pubDate>Tue, 07 Jul 2026 16:11:21 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ProtonVPN v4.4.1 - Unquoted Service Path]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Flowise  3.1.3 - arbitrary code execution]]></title>
<description><![CDATA[Flowise  3.1.3 - arbitrary code execution]]></description>
<link>https://tsecurity.de/de/3651737/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+flowise+313+-+arbitrary+code+execution/</link>
<pubDate>Tue, 07 Jul 2026 15:52:40 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Flowise  3.1.3 - arbitrary code execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Discuz! X5.0 - Authentication Bypass]]></title>
<description><![CDATA[Discuz! X5.0 - Authentication Bypass]]></description>
<link>https://tsecurity.de/de/3651709/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+discuz+x50+-+authentication+bypass/</link>
<pubDate>Tue, 07 Jul 2026 15:38:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Discuz! X5.0 - Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Bricks Builder Theme  -  RCE]]></title>
<description><![CDATA[WordPress Bricks Builder Theme  -  RCE]]></description>
<link>https://tsecurity.de/de/3651708/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+bricks+builder+theme+-+rce/</link>
<pubDate>Tue, 07 Jul 2026 15:38:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Bricks Builder Theme  -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Tenable Nessus 10.12.1 - SQL Injection]]></title>
<description><![CDATA[Tenable Nessus 10.12.1 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3651707/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+tenable+nessus+10121+-+sql+injection/</link>
<pubDate>Tue, 07 Jul 2026 15:38:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tenable Nessus 10.12.1 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter]]></title>
<description><![CDATA[iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter]]></description>
<link>https://tsecurity.de/de/3651706/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+ios+bluetooth+pan+exploit+-+ethernet+gateway+without+adapter/</link>
<pubDate>Tue, 07 Jul 2026 15:38:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Hydra - Stack Buffer Overflow]]></title>
<description><![CDATA[Hydra - Stack Buffer Overflow]]></description>
<link>https://tsecurity.de/de/3651705/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+hydra+-+stack+buffer+overflow/</link>
<pubDate>Tue, 07 Jul 2026 15:38:45 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hydra - Stack Buffer Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] KeepInMind 0.8.4.2 -  Stored XSS]]></title>
<description><![CDATA[KeepInMind 0.8.4.2 -  Stored XSS]]></description>
<link>https://tsecurity.de/de/3648885/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+keepinmind+0842+-+stored+xss/</link>
<pubDate>Mon, 06 Jul 2026 15:40:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KeepInMind 0.8.4.2 -  Stored XSS]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation]]></title>
<description><![CDATA[MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3648884/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+memu+android+emulator+9270+-+local+privilege+escalation/</link>
<pubDate>Mon, 06 Jul 2026 15:40:49 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla Extension 4.1.4 - PHP Object injection]]></title>
<description><![CDATA[Joomla Extension 4.1.4 - PHP Object injection]]></description>
<link>https://tsecurity.de/de/3648883/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+joomla+extension+414+-+php+object+injection/</link>
<pubDate>Mon, 06 Jul 2026 15:40:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Joomla Extension 4.1.4 - PHP Object injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></title>
<description><![CDATA[Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></description>
<link>https://tsecurity.de/de/3648882/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+pulpy+011-beta+-+filesystem+sandbox+bypass/</link>
<pubDate>Mon, 06 Jul 2026 15:40:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3648832/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+plugin+wpzoom+portfolio+1421+-+reflected+cross-site+scripting+xss/</link>
<pubDate>Mon, 06 Jul 2026 15:21:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] KNX visualisering - Broken Access Control]]></title>
<description><![CDATA[KNX visualisering - Broken Access Control]]></description>
<link>https://tsecurity.de/de/3648831/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+knx+visualisering+-+broken+access+control/</link>
<pubDate>Mon, 06 Jul 2026 15:21:27 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KNX visualisering - Broken Access Control]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows Defender (MsMpEng.exe) - Race Condition]]></title>
<description><![CDATA[Windows Defender (MsMpEng.exe) - Race Condition]]></description>
<link>https://tsecurity.de/de/3648830/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+windows+defender+msmpengexe+-+race+condition/</link>
<pubDate>Mon, 06 Jul 2026 15:21:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Windows Defender (MsMpEng.exe) - Race Condition]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenEMR 7.0.2 - Arbitrary File Read]]></title>
<description><![CDATA[OpenEMR 7.0.2 - Arbitrary File Read]]></description>
<link>https://tsecurity.de/de/3581651/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+openemr+702+-+arbitrary+file+read/</link>
<pubDate>Mon, 08 Jun 2026 15:53:41 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenEMR 7.0.2 - Arbitrary File Read]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></title>
<description><![CDATA[WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></description>
<link>https://tsecurity.de/de/3575179/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+contest+gallery+2814+-+unauthenticated+blind+sql+injection/</link>
<pubDate>Fri, 05 Jun 2026 13:21:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress OrderConvo 14 - Path Traversal]]></title>
<description><![CDATA[WordPress OrderConvo 14 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3563956/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+orderconvo+14+-+path+traversal/</link>
<pubDate>Mon, 01 Jun 2026 19:52:20 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress OrderConvo 14 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection]]></title>
<description><![CDATA[Drupal Core 10.5.5 - Error-Based SQL Injection]]></description>
<link>https://tsecurity.de/de/3563955/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+drupal+core+1055+-+error-based+sql+injection/</link>
<pubDate>Mon, 01 Jun 2026 19:52:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Drupal Core 10.5.5 - Error-Based SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></description>
<link>https://tsecurity.de/de/3559127/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+yamcs+yamcs-core+5127+-+no+rate+limiting/</link>
<pubDate>Sat, 30 May 2026 15:39:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - User Enumeration]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - User Enumeration]]></description>
<link>https://tsecurity.de/de/3559126/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+yamcs+yamcs-core+5127+-+user+enumeration/</link>
<pubDate>Sat, 30 May 2026 15:39:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - User Enumeration]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Notepad++ 8.9.6 - Arbitrary Code Execution]]></title>
<description><![CDATA[Notepad++ 8.9.6 - Arbitrary Code Execution]]></description>
<link>https://tsecurity.de/de/3559125/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+notepad+896+-+arbitrary+code+execution/</link>
<pubDate>Sat, 30 May 2026 15:38:58 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notepad++ 8.9.6 - Arbitrary Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - LDAP Injection]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - LDAP Injection]]></description>
<link>https://tsecurity.de/de/3559111/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+yamcs+yamcs-core+5127+-+ldap+injection/</link>
<pubDate>Sat, 30 May 2026 15:23:23 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - LDAP Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Microsoft - NTLMv2 Hash Capture]]></title>
<description><![CDATA[Microsoft - NTLMv2 Hash Capture]]></description>
<link>https://tsecurity.de/de/3556532/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+microsoft+-+ntlmv2+hash+capture/</link>
<pubDate>Fri, 29 May 2026 10:38:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft - NTLMv2 Hash Capture]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MikroORM   7.0.13 - SQL Injection]]></title>
<description><![CDATA[MikroORM   7.0.13 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3556531/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+mikroorm+7013+-+sql+injection/</link>
<pubDate>Fri, 29 May 2026 10:38:15 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MikroORM   7.0.13 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ZTE H298A / H108N - Unauthenticated Credential Exposure]]></title>
<description><![CDATA[ZTE H298A / H108N - Unauthenticated Credential Exposure]]></description>
<link>https://tsecurity.de/de/3556485/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+zte+h298a+h108n+-+unauthenticated+credential+exposure/</link>
<pubDate>Fri, 29 May 2026 10:22:07 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ZTE H298A / H108N - Unauthenticated Credential Exposure]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ZTE ZXHN H188A V6 - Authentication Bypass]]></title>
<description><![CDATA[ZTE ZXHN H188A V6 - Authentication Bypass]]></description>
<link>https://tsecurity.de/de/3556484/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+zte+zxhn+h188a+v6+-+authentication+bypass/</link>
<pubDate>Fri, 29 May 2026 10:22:06 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ZTE ZXHN H188A V6 - Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion]]></title>
<description><![CDATA[ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion]]></description>
<link>https://tsecurity.de/de/3556483/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+imagemagick+-+infinite+loop+in+the+miff+decoder+can+lead+to+cpu+exhaustion/</link>
<pubDate>Fri, 29 May 2026 10:22:05 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ZTE Routers  - Unauthenticated Denial of Service]]></title>
<description><![CDATA[ZTE Routers  - Unauthenticated Denial of Service]]></description>
<link>https://tsecurity.de/de/3556482/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+zte+routers+-+unauthenticated+denial+of+service/</link>
<pubDate>Fri, 29 May 2026 10:22:04 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ZTE Routers  - Unauthenticated Denial of Service]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Langflow 1.3.0 - Remote Code Execution]]></title>
<description><![CDATA[Langflow 1.3.0 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556481/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+langflow+130+-+remote+code+execution/</link>
<pubDate>Fri, 29 May 2026 10:22:03 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Langflow 1.3.0 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556480/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+quick+playground+for+wordpress+131+-+unauthenticated+remote+code+execution/</link>
<pubDate>Fri, 29 May 2026 10:22:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion]]></title>
<description><![CDATA[Prodigy Commerce 3.3.0 - Local File Inclusion]]></description>
<link>https://tsecurity.de/de/3556479/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+prodigy+commerce+330+-+local+file+inclusion/</link>
<pubDate>Fri, 29 May 2026 10:22:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Prodigy Commerce 3.3.0 - Local File Inclusion]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></title>
<description><![CDATA[MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556414/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+mixphp+framework+2217+-+unsafe+deserialization+remote+code+execution/</link>
<pubDate>Fri, 29 May 2026 09:54:52 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux Kernel -  Local Privilege Escalation]]></title>
<description><![CDATA[Linux Kernel -  Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3556413/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+linux+kernel+-+local+privilege+escalation/</link>
<pubDate>Fri, 29 May 2026 09:54:51 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linux Kernel -  Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></title>
<description><![CDATA[CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></description>
<link>https://tsecurity.de/de/3556273/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+cubecart+670+-+reflected+cross-site+scripting+xss+unauthenticated/</link>
<pubDate>Fri, 29 May 2026 08:35:49 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CubeCart &lt; 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution]]></title>
<description><![CDATA[Wing FTP Server 8.1.3 - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556272/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+wing+ftp+server+813+-+authenticated+remote+code+execution/</link>
<pubDate>Fri, 29 May 2026 08:35:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wing FTP Server 8.1.3 - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[dos] strongSwan 5.9.13 - DoS]]></title>
<description><![CDATA[strongSwan 5.9.13 - DoS]]></description>
<link>https://tsecurity.de/de/3556255/it+reverse+engineering/sicherheitsluecken/proof+of+concept/dos+strongswan+5913+-+dos/</link>
<pubDate>Fri, 29 May 2026 08:23:20 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[strongSwan 5.9.13 - DoS]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow]]></title>
<description><![CDATA[strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow]]></description>
<link>https://tsecurity.de/de/3556254/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+strongswan+5913+-+libsimaka+eap-simaka+heap+buffer+overflow/</link>
<pubDate>Fri, 29 May 2026 08:23:19 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux Kernel - Local Privilege Escalation]]></title>
<description><![CDATA[Linux Kernel - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3551243/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+linux+kernel+-+local+privilege+escalation/</link>
<pubDate>Wed, 27 May 2026 15:27:14 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linux Kernel - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] EspoCRM 9.3.3 -  SSRF]]></title>
<description><![CDATA[EspoCRM 9.3.3 -  SSRF]]></description>
<link>https://tsecurity.de/de/3551242/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+espocrm+933+-+ssrf/</link>
<pubDate>Wed, 27 May 2026 15:27:12 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[EspoCRM 9.3.3 -  SSRF]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></title>
<description><![CDATA[Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></description>
<link>https://tsecurity.de/de/3551241/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+casdoor+3541+-+arbitrary+file+write+via+path+traversal/</link>
<pubDate>Wed, 27 May 2026 15:27:10 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] scramble - Remote Code Execution]]></title>
<description><![CDATA[scramble - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3551185/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+scramble+-+remote+code+execution/</link>
<pubDate>Wed, 27 May 2026 15:09:36 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[scramble - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Realtek rtl819x  - Local Privilege]]></title>
<description><![CDATA[Realtek rtl819x  - Local Privilege]]></description>
<link>https://tsecurity.de/de/3551119/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+realtek+rtl819x+-+local+privilege/</link>
<pubDate>Wed, 27 May 2026 14:55:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Realtek rtl819x  - Local Privilege]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenCATS 0.9.7.4 - SQL Injection]]></title>
<description><![CDATA[OpenCATS 0.9.7.4 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3551118/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+opencats+0974+-+sql+injection/</link>
<pubDate>Wed, 27 May 2026 14:55:17 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenCATS 0.9.7.4 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[hardware] MeiG Smart FORGE_SLT711 - OS Command Injection]]></title>
<description><![CDATA[MeiG Smart FORGE_SLT711 - OS Command Injection]]></description>
<link>https://tsecurity.de/de/3551117/it+reverse+engineering/sicherheitsluecken/proof+of+concept/hardware+meig+smart+forgeslt711+-+os+command+injection/</link>
<pubDate>Wed, 27 May 2026 14:55:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MeiG Smart FORGE_SLT711 - OS Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></title>
<description><![CDATA[Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3548506/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+grav+cms+200-beta2+-+remote+code+execution/</link>
<pubDate>Tue, 26 May 2026 17:26:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] cPanel - CRLF Injection]]></title>
<description><![CDATA[cPanel - CRLF Injection]]></description>
<link>https://tsecurity.de/de/3548445/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+cpanel+-+crlf+injection/</link>
<pubDate>Tue, 26 May 2026 17:10:30 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[cPanel - CRLF Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></title>
<description><![CDATA[Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></description>
<link>https://tsecurity.de/de/3548444/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+temporary+login+plugin+100+-+temp-login-token+authentication+bypass+to+account+takeover/</link>
<pubDate>Tue, 26 May 2026 17:10:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></content:encoded>
</item>
<item>
<title><![CDATA[[hardware] D-Link DSL2600U - 'rom-0' Admin Password Disclosure]]></title>
<description><![CDATA[D-Link DSL2600U - 'rom-0' Admin Password Disclosure]]></description>
<link>https://tsecurity.de/de/3548443/it+reverse+engineering/sicherheitsluecken/proof+of+concept/hardware+d-link+dsl2600u+-+rom-0+admin+password+disclosure/</link>
<pubDate>Tue, 26 May 2026 17:10:26 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[D-Link DSL2600U - 'rom-0' Admin Password Disclosure]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></title>
<description><![CDATA[Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></description>
<link>https://tsecurity.de/de/3548442/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+apache+http+server+2466+-+modhttp2+double-free+denial+of+service/</link>
<pubDate>Tue, 26 May 2026 17:10:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux Kernel 6.8 - Local Privilege Escalation]]></title>
<description><![CDATA[Linux Kernel 6.8 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3548368/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+linux+kernel+68+-+local+privilege+escalation/</link>
<pubDate>Tue, 26 May 2026 16:56:24 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linux Kernel 6.8 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] BookStack 25.12.1 - Denial of Service]]></title>
<description><![CDATA[BookStack 25.12.1 - Denial of Service]]></description>
<link>https://tsecurity.de/de/3536562/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+bookstack+25121+-+denial+of+service/</link>
<pubDate>Thu, 21 May 2026 15:40:57 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BookStack 25.12.1 - Denial of Service]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FUXA  1.2.9 -  RCE]]></title>
<description><![CDATA[FUXA  1.2.9 -  RCE]]></description>
<link>https://tsecurity.de/de/3536561/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+fuxa+129+-+rce/</link>
<pubDate>Thu, 21 May 2026 15:40:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FUXA  1.2.9 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] solaredge - (CSRF-OOB-Injection)]]></title>
<description><![CDATA[solaredge - (CSRF-OOB-Injection)]]></description>
<link>https://tsecurity.de/de/3536560/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+solaredge+-+csrf-oob-injection/</link>
<pubDate>Thu, 21 May 2026 15:40:53 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[solaredge - (CSRF-OOB-Injection)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Cockpit 359 - RCE]]></title>
<description><![CDATA[Cockpit 359 - RCE]]></description>
<link>https://tsecurity.de/de/3536559/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+cockpit+359+-+rce/</link>
<pubDate>Thu, 21 May 2026 15:40:51 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cockpit 359 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path]]></title>
<description><![CDATA[Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path]]></description>
<link>https://tsecurity.de/de/3536558/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+lenovo+legionspace+17112+-+daservice+unquoted+service+path/</link>
<pubDate>Thu, 21 May 2026 15:40:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows Snipping Tool - NTLMv2 Hash Hijack]]></title>
<description><![CDATA[Windows Snipping Tool - NTLMv2 Hash Hijack]]></description>
<link>https://tsecurity.de/de/3520103/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+windows+snipping+tool+-+ntlmv2+hash+hijack/</link>
<pubDate>Fri, 15 May 2026 16:54:14 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Windows Snipping Tool - NTLMv2 Hash Hijack]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing]]></title>
<description><![CDATA[Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing]]></description>
<link>https://tsecurity.de/de/3519738/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+remote+sunrise+helper+for+windows+202614+-+unauthenticated+filedirectory+listing/</link>
<pubDate>Fri, 15 May 2026 14:55:37 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution]]></title>
<description><![CDATA[Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3519737/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+remote+sunrise+helper+for+windows+202614+-+remote+code+execution/</link>
<pubDate>Fri, 15 May 2026 14:55:35 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></title>
<description><![CDATA[WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></description>
<link>https://tsecurity.de/de/3517059/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+plugin+supsystic+contact+form+1736+-+ssti/</link>
<pubDate>Thu, 14 May 2026 16:39:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></title>
<description><![CDATA[ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></description>
<link>https://tsecurity.de/de/3516826/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+epati+antikor+ngfw+201301+-+authentication+bypass/</link>
<pubDate>Thu, 14 May 2026 15:12:27 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] PJPROJECT 2.16 - Heap Bufferoverflow]]></title>
<description><![CDATA[PJPROJECT 2.16 - Heap Bufferoverflow]]></description>
<link>https://tsecurity.de/de/3516825/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+pjproject+216+-+heap+bufferoverflow/</link>
<pubDate>Thu, 14 May 2026 15:12:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PJPROJECT 2.16 - Heap Bufferoverflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Apache HertzBeat 1.8.0 - Remote Code Execution]]></title>
<description><![CDATA[Apache HertzBeat 1.8.0 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3516824/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+apache+hertzbeat+180+-+remote+code+execution/</link>
<pubDate>Thu, 14 May 2026 15:12:22 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apache HertzBeat 1.8.0 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] glances 4.5.2 - command injection]]></title>
<description><![CDATA[glances 4.5.2 - command injection]]></description>
<link>https://tsecurity.de/de/3513847/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+glances+452+-+command+injection/</link>
<pubDate>Wed, 13 May 2026 15:25:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[glances 4.5.2 - command injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ninja Forms Uploads - Unauthenticated PHP File Upload]]></title>
<description><![CDATA[Ninja Forms Uploads - Unauthenticated PHP File Upload]]></description>
<link>https://tsecurity.de/de/3513846/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+ninja+forms+uploads+-+unauthenticated+php+file+upload/</link>
<pubDate>Wed, 13 May 2026 15:25:53 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ninja Forms Uploads - Unauthenticated PHP File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Flowise < 3.0.5 - Missing Authentication for Critical Function]]></title>
<description><![CDATA[Flowise < 3.0.5 - Missing Authentication for Critical Function]]></description>
<link>https://tsecurity.de/de/3513772/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+flowise+305+-+missing+authentication+for+critical+function/</link>
<pubDate>Wed, 13 May 2026 15:07:27 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Flowise &lt; 3.0.5 - Missing Authentication for Critical Function]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] coreruleset 4.21.0 - Firewall Bypass]]></title>
<description><![CDATA[coreruleset 4.21.0 - Firewall Bypass]]></description>
<link>https://tsecurity.de/de/3513771/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+coreruleset+4210+-+firewall+bypass/</link>
<pubDate>Wed, 13 May 2026 15:07:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[coreruleset 4.21.0 - Firewall Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] telnetd 2.7 - Buffer Overflow]]></title>
<description><![CDATA[telnetd 2.7 - Buffer Overflow]]></description>
<link>https://tsecurity.de/de/3496405/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+telnetd+27+-+buffer+overflow/</link>
<pubDate>Thu, 07 May 2026 16:42:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[telnetd 2.7 - Buffer Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Bludit CMS 3.18.4 -  RCE]]></title>
<description><![CDATA[Bludit CMS 3.18.4 -  RCE]]></description>
<link>https://tsecurity.de/de/3496349/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+bludit+cms+3184+-+rce/</link>
<pubDate>Thu, 07 May 2026 16:25:32 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bludit CMS 3.18.4 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></title>
<description><![CDATA[LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></description>
<link>https://tsecurity.de/de/3496348/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+luajit+211774638290+-+arbitrary+code+execution/</link>
<pubDate>Thu, 07 May 2026 16:25:31 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ghost CMS 6.19.0 - SQLi]]></title>
<description><![CDATA[Ghost CMS 6.19.0 - SQLi]]></description>
<link>https://tsecurity.de/de/3496347/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+ghost+cms+6190+-+sqli/</link>
<pubDate>Thu, 07 May 2026 16:25:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ghost CMS 6.19.0 - SQLi]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] NocoBase  2.0.27 - VM Sandbox Escape]]></title>
<description><![CDATA[NocoBase  2.0.27 - VM Sandbox Escape]]></description>
<link>https://tsecurity.de/de/3496276/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+nocobase+2027+-+vm+sandbox+escape/</link>
<pubDate>Thu, 07 May 2026 16:11:12 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NocoBase  2.0.27 - VM Sandbox Escape]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></title>
<description><![CDATA[ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></description>
<link>https://tsecurity.de/de/3496275/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+thingsboard+iot+platform+420+-+server-side+request+forgery+ssrf/</link>
<pubDate>Thu, 07 May 2026 16:11:11 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux nf_tables 6.19.3 - Local Privilege Escalation]]></title>
<description><![CDATA[Linux nf_tables 6.19.3 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3486371/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+linux+nftables+6193+-+local+privilege+escalation/</link>
<pubDate>Mon, 04 May 2026 16:10:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linux nf_tables 6.19.3 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation]]></title>
<description><![CDATA[Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3486370/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+linux+kernel+procreaddirde+618-rc5+-+local+privilege+escalation/</link>
<pubDate>Mon, 04 May 2026 16:10:14 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[hardware] Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)]]></title>
<description><![CDATA[Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)]]></description>
<link>https://tsecurity.de/de/3486328/it+reverse+engineering/sicherheitsluecken/proof+of+concept/hardware+linksys+e1200+2004+-+authenticated+stack+buffer+overflow+rce/</link>
<pubDate>Mon, 04 May 2026 15:54:19 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></title>
<description><![CDATA[Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></description>
<link>https://tsecurity.de/de/3486282/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+traccar+gps+tracking+system+6111+-+cross-site+websocket+hijacking+cswsh/</link>
<pubDate>Mon, 04 May 2026 15:40:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows 11 24H2 - Local Privilege Escalation]]></title>
<description><![CDATA[Windows 11 24H2 - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3486281/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+windows+11+24h2+-+local+privilege+escalation/</link>
<pubDate>Mon, 04 May 2026 15:40:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Windows 11 24H2 - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MindsDB  25.9.1.1 - Path Traversal]]></title>
<description><![CDATA[MindsDB  25.9.1.1 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3486280/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+mindsdb+25911+-+path+traversal/</link>
<pubDate>Mon, 04 May 2026 15:40:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MindsDB  25.9.1.1 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></title>
<description><![CDATA[FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></description>
<link>https://tsecurity.de/de/3477228/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+fuxa+128+-+authentication+bypass+rce+exploit/</link>
<pubDate>Thu, 30 Apr 2026 12:38:57 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Python-Multipart 0.0.22 - Path Traversal]]></title>
<description><![CDATA[Python-Multipart 0.0.22 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3477117/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+python-multipart+0022+-+path+traversal/</link>
<pubDate>Thu, 30 Apr 2026 12:08:39 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Python-Multipart 0.0.22 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows 11 23H2 - Denial of Service (DoS)]]></title>
<description><![CDATA[Windows 11 23H2 - Denial of Service (DoS)]]></description>
<link>https://tsecurity.de/de/3477072/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+windows+11+23h2+-+denial+of+service+dos/</link>
<pubDate>Thu, 30 Apr 2026 11:51:20 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Windows 11 23H2 - Denial of Service (DoS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Google Chrome  145.0.7632.75 - CSSFontFeatureValuesMap]]></title>
<description><![CDATA[Google Chrome  145.0.7632.75 - CSSFontFeatureValuesMap]]></description>
<link>https://tsecurity.de/de/3477071/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+google+chrome+1450763275+-+cssfontfeaturevaluesmap/</link>
<pubDate>Thu, 30 Apr 2026 11:51:19 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google Chrome  145.0.7632.75 - CSSFontFeatureValuesMap]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Repetier-Server 1.4.10 - Path Traversal]]></title>
<description><![CDATA[Repetier-Server 1.4.10 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3477070/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+repetier-server+1410+-+path+traversal/</link>
<pubDate>Thu, 30 Apr 2026 11:51:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Repetier-Server 1.4.10 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] HUSTOJ Zip-Slip v26.01.24 -  RCE]]></title>
<description><![CDATA[HUSTOJ Zip-Slip v26.01.24 -  RCE]]></description>
<link>https://tsecurity.de/de/3477069/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+hustoj+zip-slip+v260124+-+rce/</link>
<pubDate>Thu, 30 Apr 2026 11:51:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[HUSTOJ Zip-Slip v26.01.24 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows 11 25H2  - Heap Overflow]]></title>
<description><![CDATA[Windows 11 25H2  - Heap Overflow]]></description>
<link>https://tsecurity.de/de/3476886/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+windows+11+25h2+-+heap+overflow/</link>
<pubDate>Thu, 30 Apr 2026 10:53:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Windows 11 25H2  - Heap Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] BusyBox 1.37.0 - Path Traversal]]></title>
<description><![CDATA[BusyBox 1.37.0 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3476885/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+busybox+1370+-+path+traversal/</link>
<pubDate>Thu, 30 Apr 2026 10:53:17 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BusyBox 1.37.0 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] JUNG Smart Visu Server 1.1.1050 - Dos]]></title>
<description><![CDATA[JUNG Smart Visu Server 1.1.1050 - Dos]]></description>
<link>https://tsecurity.de/de/3476884/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+jung+smart+visu+server+111050+-+dos/</link>
<pubDate>Thu, 30 Apr 2026 10:53:15 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JUNG Smart Visu Server 1.1.1050 - Dos]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] SumatraPDF 3.5.2 - Remote Code Execution]]></title>
<description><![CDATA[SumatraPDF 3.5.2 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3476828/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+sumatrapdf+352+-+remote+code+execution/</link>
<pubDate>Thu, 30 Apr 2026 10:23:08 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SumatraPDF 3.5.2 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Frigate NVR 0.16.3 - Remote Code Execution]]></title>
<description><![CDATA[Frigate NVR 0.16.3 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3476827/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+frigate+nvr+0163+-+remote+code+execution/</link>
<pubDate>Thu, 30 Apr 2026 10:23:06 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Frigate NVR 0.16.3 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] NiceGUI 3.6.1 - Path Traversal]]></title>
<description><![CDATA[NiceGUI 3.6.1 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3476826/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+nicegui+361+-+path+traversal/</link>
<pubDate>Thu, 30 Apr 2026 10:23:04 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NiceGUI 3.6.1 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Js2Py 0.74 -  RCE]]></title>
<description><![CDATA[Js2Py 0.74 -  RCE]]></description>
<link>https://tsecurity.de/de/3476785/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+js2py+074+-+rce/</link>
<pubDate>Thu, 30 Apr 2026 10:07:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Js2Py 0.74 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection]]></title>
<description><![CDATA[Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection]]></description>
<link>https://tsecurity.de/de/3476695/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+cybersecurity+ai+cai+framework+0510+-+command+injection/</link>
<pubDate>Thu, 30 Apr 2026 09:36:19 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Camaleon CMS  v2.9.0 - Path Traversal]]></title>
<description><![CDATA[Camaleon CMS  v2.9.0 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3476694/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+camaleon+cms+v290+-+path+traversal/</link>
<pubDate>Thu, 30 Apr 2026 09:36:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Camaleon CMS  v2.9.0 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] SUSE Manager 4.3.15 - Code Execution]]></title>
<description><![CDATA[SUSE Manager 4.3.15 - Code Execution]]></description>
<link>https://tsecurity.de/de/3476662/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+suse+manager+4315+-+code+execution/</link>
<pubDate>Thu, 30 Apr 2026 09:23:04 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SUSE Manager 4.3.15 - Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Erugo  0.2.14 - Remote Code Execution (RCE)]]></title>
<description><![CDATA[Erugo  0.2.14 - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/3476661/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+erugo+0214+-+remote+code+execution+rce/</link>
<pubDate>Thu, 30 Apr 2026 09:23:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erugo  0.2.14 - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] deephas 1.0.7 - Prototype Pollution]]></title>
<description><![CDATA[deephas 1.0.7 - Prototype Pollution]]></description>
<link>https://tsecurity.de/de/3476660/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+deephas+107+-+prototype+pollution/</link>
<pubDate>Thu, 30 Apr 2026 09:23:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[deephas 1.0.7 - Prototype Pollution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Craft CMS 5.6.16 - RCE]]></title>
<description><![CDATA[Craft CMS 5.6.16 - RCE]]></description>
<link>https://tsecurity.de/de/3474252/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+craft+cms+5616+-+rce/</link>
<pubDate>Wed, 29 Apr 2026 13:22:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Craft CMS 5.6.16 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation]]></title>
<description><![CDATA[GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3474251/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+gnu+inetutils+26+-+telnetd+remote+privilege+escalation/</link>
<pubDate>Wed, 29 Apr 2026 13:22:26 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] HAX CMS 24.x - Stored Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[HAX CMS 24.x - Stored Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3474250/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+hax+cms+24x+-+stored+cross-site+scripting+xss/</link>
<pubDate>Wed, 29 Apr 2026 13:22:24 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[HAX CMS 24.x - Stored Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] GeographicLib v2.5.1 - stack buffer overflow]]></title>
<description><![CDATA[GeographicLib v2.5.1 - stack buffer overflow]]></description>
<link>https://tsecurity.de/de/3474107/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+geographiclib+v251+-+stack+buffer+overflow/</link>
<pubDate>Wed, 29 Apr 2026 12:36:23 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GeographicLib v2.5.1 - stack buffer overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpMyFAQ  4.0.16 - Improper Authorization]]></title>
<description><![CDATA[phpMyFAQ  4.0.16 - Improper Authorization]]></description>
<link>https://tsecurity.de/de/3474106/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+phpmyfaq+4016+-+improper+authorization/</link>
<pubDate>Wed, 29 Apr 2026 12:36:21 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpMyFAQ  4.0.16 - Improper Authorization]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] OpenWrt 23.05 - Authenticated Remote Code Execution (RCE)]]></title>
<description><![CDATA[OpenWrt 23.05 - Authenticated Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/3473582/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+openwrt+2305+-+authenticated+remote+code+execution+rce/</link>
<pubDate>Wed, 29 Apr 2026 09:35:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenWrt 23.05 - Authenticated Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenKM 6.3.12 - Multiple]]></title>
<description><![CDATA[OpenKM 6.3.12 - Multiple]]></description>
<link>https://tsecurity.de/de/3473581/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+openkm+6312+-+multiple/</link>
<pubDate>Wed, 29 Apr 2026 09:35:44 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenKM 6.3.12 - Multiple]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FacturaScripts 2025.43 - XSS]]></title>
<description><![CDATA[FacturaScripts 2025.43 - XSS]]></description>
<link>https://tsecurity.de/de/3473554/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+facturascripts+202543+-+xss/</link>
<pubDate>Wed, 29 Apr 2026 09:23:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FacturaScripts 2025.43 - XSS]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)]]></title>
<description><![CDATA[GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/3473553/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+gunet+openeclass+e-learning+platform+42+-+remote+code+execution+rce/</link>
<pubDate>Wed, 29 Apr 2026 09:23:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GUnet OpenEclass E-learning platform &lt; 4.2 - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution]]></title>
<description><![CDATA[JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3473552/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+juzaweb+cms+342+-+authenticated+remote+code+execution/</link>
<pubDate>Wed, 29 Apr 2026 09:23:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Xibo CMS  4.3.0 - RCE via SSTI]]></title>
<description><![CDATA[Xibo CMS  4.3.0 - RCE via SSTI]]></description>
<link>https://tsecurity.de/de/3473340/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+xibo+cms+430+-+rce+via+ssti/</link>
<pubDate>Wed, 29 Apr 2026 07:52:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xibo CMS  4.3.0 - RCE via SSTI]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Atlona ATOMERX21 - Authenticated Command Injection]]></title>
<description><![CDATA[Atlona ATOMERX21 - Authenticated Command Injection]]></description>
<link>https://tsecurity.de/de/3473319/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+atlona+atomerx21+-+authenticated+command+injection/</link>
<pubDate>Wed, 29 Apr 2026 07:36:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Atlona ATOMERX21 - Authenticated Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LangChain Core 1.2.4 - SSTI/RCE]]></title>
<description><![CDATA[LangChain Core 1.2.4 - SSTI/RCE]]></description>
<link>https://tsecurity.de/de/3473318/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+langchain+core+124+-+sstirce/</link>
<pubDate>Wed, 29 Apr 2026 07:36:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LangChain Core 1.2.4 - SSTI/RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Fedora - Local Privilege Escalation]]></title>
<description><![CDATA[Fedora - Local Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3473317/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+fedora+-+local+privilege+escalation/</link>
<pubDate>Wed, 29 Apr 2026 07:36:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fedora - Local Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] AVAST Antivirus 25.11 - Unquoted Service Path]]></title>
<description><![CDATA[AVAST Antivirus 25.11 - Unquoted Service Path]]></description>
<link>https://tsecurity.de/de/3454926/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+avast+antivirus+2511+-+unquoted+service+path/</link>
<pubDate>Wed, 22 Apr 2026 15:05:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AVAST Antivirus 25.11 - Unquoted Service Path]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Plugin  5.2.0 - Broken Access Control]]></title>
<description><![CDATA[WordPress Plugin  5.2.0 - Broken Access Control]]></description>
<link>https://tsecurity.de/de/3454925/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+plugin+520+-+broken+access+control/</link>
<pubDate>Wed, 22 Apr 2026 15:05:21 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Plugin  5.2.0 - Broken Access Control]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Throttlestop Kernel Driver - Kernel Out-of-Bounds Write Privilege Escalation]]></title>
<description><![CDATA[Throttlestop Kernel Driver - Kernel Out-of-Bounds Write Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3454924/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+throttlestop+kernel+driver+-+kernel+out-of-bounds+write+privilege+escalation/</link>
<pubDate>Wed, 22 Apr 2026 15:05:17 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Throttlestop Kernel Driver - Kernel Out-of-Bounds Write Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] NetBT e-Fatura - Privilege Escalation]]></title>
<description><![CDATA[NetBT e-Fatura - Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3423893/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+netbt+e-fatura+-+privilege+escalation/</link>
<pubDate>Fri, 10 Apr 2026 16:11:06 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NetBT e-Fatura - Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] D-Link DIR-650IN - Authenticated Command Injection]]></title>
<description><![CDATA[D-Link DIR-650IN - Authenticated Command Injection]]></description>
<link>https://tsecurity.de/de/3423892/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+d-link+dir-650in+-+authenticated+command+injection/</link>
<pubDate>Fri, 10 Apr 2026 16:11:05 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[D-Link DIR-650IN - Authenticated Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RomM  4.4.0 -  XSS_CSRF Chain]]></title>
<description><![CDATA[RomM  4.4.0 -  XSS_CSRF Chain]]></description>
<link>https://tsecurity.de/de/3421405/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+romm+440+-+xsscsrf+chain/</link>
<pubDate>Thu, 09 Apr 2026 19:53:30 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RomM  4.4.0 -  XSS_CSRF Chain]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] React Server 19.2.0 - Remote Code Execution]]></title>
<description><![CDATA[React Server 19.2.0 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3421404/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+react+server+1920+-+remote+code+execution/</link>
<pubDate>Thu, 09 Apr 2026 19:53:29 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[React Server 19.2.0 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Jumbo Website Manager  - Remote Code Execution]]></title>
<description><![CDATA[Jumbo Website Manager  - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3421367/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+jumbo+website+manager+-+remote+code+execution/</link>
<pubDate>Thu, 09 Apr 2026 19:37:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jumbo Website Manager  - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] ZSH 5.9 - RCE]]></title>
<description><![CDATA[ZSH 5.9 - RCE]]></description>
<link>https://tsecurity.de/de/3421366/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+zsh+59+-+rce/</link>
<pubDate>Thu, 09 Apr 2026 19:37:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ZSH 5.9 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] xibocms 3.3.4 - RCE]]></title>
<description><![CDATA[xibocms 3.3.4 - RCE]]></description>
<link>https://tsecurity.de/de/3417853/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+xibocms+334+-+rce/</link>
<pubDate>Wed, 08 Apr 2026 17:22:15 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[xibocms 3.3.4 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] 7-Zip 24.00 - Directory Traversal]]></title>
<description><![CDATA[7-Zip 24.00 - Directory Traversal]]></description>
<link>https://tsecurity.de/de/3417852/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+7-zip+2400+-+directory+traversal/</link>
<pubDate>Wed, 08 Apr 2026 17:22:14 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[7-Zip 24.00 - Directory Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FortiWeb  8.0.2 - Remote Code Execution]]></title>
<description><![CDATA[FortiWeb  8.0.2 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3417851/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+fortiweb+802+-+remote+code+execution/</link>
<pubDate>Wed, 08 Apr 2026 17:22:12 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FortiWeb  8.0.2 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Horilla v1.3 - RCE]]></title>
<description><![CDATA[Horilla v1.3 - RCE]]></description>
<link>https://tsecurity.de/de/3417709/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+horilla+v13+-+rce/</link>
<pubDate>Wed, 08 Apr 2026 16:38:38 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Horilla v1.3 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Microsoft MMC MSC EvilTwin - Local Admin Creation]]></title>
<description><![CDATA[Microsoft MMC MSC EvilTwin - Local Admin Creation]]></description>
<link>https://tsecurity.de/de/3417708/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+microsoft+mmc+msc+eviltwin+-+local+admin+creation/</link>
<pubDate>Wed, 08 Apr 2026 16:38:37 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft MMC MSC EvilTwin - Local Admin Creation]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] SQLite 3.50.1 - Heap Overflow]]></title>
<description><![CDATA[SQLite 3.50.1 - Heap Overflow]]></description>
<link>https://tsecurity.de/de/3417707/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+sqlite+3501+-+heap+overflow/</link>
<pubDate>Wed, 08 Apr 2026 16:38:35 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SQLite 3.50.1 - Heap Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Fortinet FortiWeb v8.0.1 - Auth Bypass]]></title>
<description><![CDATA[Fortinet FortiWeb v8.0.1 - Auth Bypass]]></description>
<link>https://tsecurity.de/de/3411206/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+fortinet+fortiweb+v801+-+auth+bypass/</link>
<pubDate>Mon, 06 Apr 2026 15:22:41 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fortinet FortiWeb v8.0.1 - Auth Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Windows Kernel - Elevation of Privilege]]></title>
<description><![CDATA[Windows Kernel - Elevation of Privilege]]></description>
<link>https://tsecurity.de/de/3411205/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+windows+kernel+-+elevation+of+privilege/</link>
<pubDate>Mon, 06 Apr 2026 15:22:39 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Windows Kernel - Elevation of Privilege]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] is-localhost-ip 2.0.0 - SSRF]]></title>
<description><![CDATA[is-localhost-ip 2.0.0 - SSRF]]></description>
<link>https://tsecurity.de/de/3411204/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+is-localhost-ip+200+-+ssrf/</link>
<pubDate>Mon, 06 Apr 2026 15:22:37 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[is-localhost-ip 2.0.0 - SSRF]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ASP.net  8.0.10 - Bypass]]></title>
<description><![CDATA[ASP.net  8.0.10 - Bypass]]></description>
<link>https://tsecurity.de/de/3411175/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+aspnet+8010+-+bypass/</link>
<pubDate>Mon, 06 Apr 2026 15:09:37 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ASP.net  8.0.10 - Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation]]></title>
<description><![CDATA[Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation]]></description>
<link>https://tsecurity.de/de/3411174/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+desktop+window+manager+core+library+100102400+-+privilege+escalation/</link>
<pubDate>Mon, 06 Apr 2026 15:09:36 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress  Madara - Local File Inclusion]]></title>
<description><![CDATA[WordPress  Madara - Local File Inclusion]]></description>
<link>https://tsecurity.de/de/3411156/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+madara+-+local+file+inclusion/</link>
<pubDate>Mon, 06 Apr 2026 14:55:57 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress  Madara - Local File Inclusion]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WBCE CMS 1.6.4 - Remote Code Execution]]></title>
<description><![CDATA[WBCE CMS 1.6.4 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3411155/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wbce+cms+164+-+remote+code+execution/</link>
<pubDate>Mon, 06 Apr 2026 14:55:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WBCE CMS 1.6.4 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RiteCMS 3.1.0 - Authenticated Remote Code Execution]]></title>
<description><![CDATA[RiteCMS 3.1.0 - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3411154/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+ritecms+310+-+authenticated+remote+code+execution/</link>
<pubDate>Mon, 06 Apr 2026 14:55:54 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RiteCMS 3.1.0 - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Zhiyuan OA - arbitrary file upload leading]]></title>
<description><![CDATA[Zhiyuan OA - arbitrary file upload leading]]></description>
<link>https://tsecurity.de/de/3411153/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+zhiyuan+oa+-+arbitrary+file+upload+leading/</link>
<pubDate>Mon, 06 Apr 2026 14:55:52 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zhiyuan OA - arbitrary file upload leading]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Grafana 11.6.0 - SSRF]]></title>
<description><![CDATA[Grafana 11.6.0 - SSRF]]></description>
<link>https://tsecurity.de/de/3411152/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+grafana+1160+-+ssrf/</link>
<pubDate>Mon, 06 Apr 2026 14:55:51 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Grafana 11.6.0 - SSRF]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] mailcow 2025-01a - Host Header Password Reset Poisoning]]></title>
<description><![CDATA[mailcow 2025-01a - Host Header Password Reset Poisoning]]></description>
<link>https://tsecurity.de/de/3322361/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+mailcow+2025-01a+-+host+header+password+reset+poisoning/</link>
<pubDate>Tue, 03 Mar 2026 12:24:56 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[mailcow 2025-01a - Host Header Password Reset Poisoning]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Backup Migration 1.3.7 - Remote Command Execution]]></title>
<description><![CDATA[WordPress Backup Migration 1.3.7 - Remote Command Execution]]></description>
<link>https://tsecurity.de/de/3322360/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wordpress+backup+migration+137+-+remote+command+execution/</link>
<pubDate>Tue, 03 Mar 2026 12:24:54 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Backup Migration 1.3.7 - Remote Command Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Easy File Sharing Web Server v7.2 - Buffer Overflow]]></title>
<description><![CDATA[Easy File Sharing Web Server v7.2 - Buffer Overflow]]></description>
<link>https://tsecurity.de/de/3322332/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+easy+file+sharing+web+server+v72+-+buffer+overflow/</link>
<pubDate>Tue, 03 Mar 2026 12:08:51 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Easy File Sharing Web Server v7.2 - Buffer Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WeGIA 3.5.0 - SQL Injection]]></title>
<description><![CDATA[WeGIA 3.5.0 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3322187/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+wegia+350+-+sql+injection/</link>
<pubDate>Tue, 03 Mar 2026 11:08:45 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WeGIA 3.5.0 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Boss Mini v1.4.0 - Local File Inclusion (LFI)]]></title>
<description><![CDATA[Boss Mini v1.4.0 - Local File Inclusion (LFI)]]></description>
<link>https://tsecurity.de/de/3322186/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+boss+mini+v140+-+local+file+inclusion+lfi/</link>
<pubDate>Tue, 03 Mar 2026 11:08:43 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Boss Mini v1.4.0 - Local File Inclusion (LFI)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] motionEye 0.43.1b4 - RCE]]></title>
<description><![CDATA[motionEye 0.43.1b4 - RCE]]></description>
<link>https://tsecurity.de/de/3281323/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+motioneye+0431b4+-+rce/</link>
<pubDate>Wed, 11 Feb 2026 11:23:29 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[motionEye 0.43.1b4 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] glibc 2.38 - Buffer Overflow]]></title>
<description><![CDATA[glibc 2.38 - Buffer Overflow]]></description>
<link>https://tsecurity.de/de/3281277/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+glibc+238+-+buffer+overflow/</link>
<pubDate>Wed, 11 Feb 2026 11:09:11 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[glibc 2.38 - Buffer Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Windows 10.0.17763.7009 - spoofing vulnerability]]></title>
<description><![CDATA[Windows 10.0.17763.7009 - spoofing vulnerability]]></description>
<link>https://tsecurity.de/de/3281276/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+windows+100177637009+-+spoofing+vulnerability/</link>
<pubDate>Wed, 11 Feb 2026 11:09:09 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Windows 10.0.17763.7009 - spoofing vulnerability]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] windows 10/11 - NTLM Hash Disclosure Spoofing]]></title>
<description><![CDATA[windows 10/11 - NTLM Hash Disclosure Spoofing]]></description>
<link>https://tsecurity.de/de/3252860/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+windows+1011+-+ntlm+hash+disclosure+spoofing/</link>
<pubDate>Wed, 04 Feb 2026 14:52:15 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[windows 10/11 - NTLM Hash Disclosure Spoofing]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Redis 8.0.2 - RCE]]></title>
<description><![CDATA[Redis 8.0.2 - RCE]]></description>
<link>https://tsecurity.de/de/3252859/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+redis+802+-+rce/</link>
<pubDate>Wed, 04 Feb 2026 14:52:13 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Redis 8.0.2 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OctoPrint 1.11.2 - File Upload]]></title>
<description><![CDATA[OctoPrint 1.11.2 - File Upload]]></description>
<link>https://tsecurity.de/de/3252813/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+octoprint+1112+-+file+upload/</link>
<pubDate>Wed, 04 Feb 2026 14:34:41 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OctoPrint 1.11.2 - File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution]]></title>
<description><![CDATA[FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3252795/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+fortiweb+fabric+connector+76x+-+sql+injection+to+remote+code+execution/</link>
<pubDate>Wed, 04 Feb 2026 14:21:33 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[local] Docker Desktop 4.44.3 - Unauthenticated  API Exposure]]></title>
<description><![CDATA[Docker Desktop 4.44.3 - Unauthenticated  API Exposure]]></description>
<link>https://tsecurity.de/de/3252794/it+reverse+engineering/sicherheitsluecken/proof+of+concept/local+docker+desktop+4443+-+unauthenticated+api+exposure/</link>
<pubDate>Wed, 04 Feb 2026 14:21:32 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Docker Desktop 4.44.3 - Unauthenticated  API Exposure]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] aiohttp 3.9.1 - directory traversal PoC]]></title>
<description><![CDATA[aiohttp 3.9.1 - directory traversal PoC]]></description>
<link>https://tsecurity.de/de/3252793/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+aiohttp+391+-+directory+traversal+poc/</link>
<pubDate>Wed, 04 Feb 2026 14:21:30 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[aiohttp 3.9.1 - directory traversal PoC]]></content:encoded>
</item>
<item>
<title><![CDATA[[remote] Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE]]></title>
<description><![CDATA[Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE]]></description>
<link>https://tsecurity.de/de/3252792/it+reverse+engineering/sicherheitsluecken/proof+of+concept/remote+ingress-nginx+admission+controller+v1111+-+fd+injection+to+rce/</link>
<pubDate>Wed, 04 Feb 2026 14:21:29 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[hardware] D-Link DIR-825 Rev.B 2.10 - Stack Buffer Overflow (DoS)]]></title>
<description><![CDATA[D-Link DIR-825 Rev.B 2.10 - Stack Buffer Overflow (DoS)]]></description>
<link>https://tsecurity.de/de/3247786/it+reverse+engineering/sicherheitsluecken/proof+of+concept/hardware+d-link+dir-825+revb+210+-+stack+buffer+overflow+dos/</link>
<pubDate>Mon, 02 Feb 2026 10:11:35 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[D-Link DIR-825 Rev.B 2.10 - Stack Buffer Overflow (DoS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3247785/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+rpi-jukebox-rfid+280+-+stored+cross-site+scripting+xss/</link>
<pubDate>Mon, 02 Feb 2026 10:11:34 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Piranha CMS 12.0 - Stored XSS in Text Block]]></title>
<description><![CDATA[Piranha CMS 12.0 - Stored XSS in Text Block]]></description>
<link>https://tsecurity.de/de/3247784/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+piranha+cms+120+-+stored+xss+in+text+block/</link>
<pubDate>Mon, 02 Feb 2026 10:11:32 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Piranha CMS 12.0 - Stored XSS in Text Block]]></content:encoded>
</item>
<item>
<title><![CDATA[AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[Topic: AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/3220315/it+reverse+engineering/sicherheitsluecken/proof+of+concept/avideo+notifyffmpegjsonphp+unauthenticated+remote+code+execution/</link>
<pubDate>Sun, 18 Jan 2026 22:49:25 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RPi-Jukebox-RFID 2.8.0 - Remote Command Execution]]></title>
<description><![CDATA[RPi-Jukebox-RFID 2.8.0 - Remote Command Execution]]></description>
<link>https://tsecurity.de/de/3218789/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+rpi-jukebox-rfid+280+-+remote+command+execution/</link>
<pubDate>Sat, 17 Jan 2026 15:06:21 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RPi-Jukebox-RFID 2.8.0 - Remote Command Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Siklu EtherHaul Series EH-8010 - Remote Command Execution]]></title>
<description><![CDATA[Siklu EtherHaul Series EH-8010 - Remote Command Execution]]></description>
<link>https://tsecurity.de/de/3218769/it+reverse+engineering/sicherheitsluecken/proof+of+concept/webapps+siklu+etherhaul+series+eh-8010+-+remote+command+execution/</link>
<pubDate>Sat, 17 Jan 2026 14:50:32 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Siklu EtherHaul Series EH-8010 - Remote Command Execution]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,16ms -->