es
Feedback
CVE

CVE

Ir al canal en Telegram

🔐 CVE | Cyber ​​Vulnerabilities Exchange Group dedicated to sharing and discussing CVEs, zero-days, critical vulnerabilities, exploits, PoCs, and technical analyses of offensive and defensive security. 🟢 Think. Break. Secure. BY: @Mm_fit #cve

Mostrar más
El país no está especificadoTecnologías y Aplicaciones20 429
4 290
Suscriptores
+924 horas
+627 días
+18530 días
Archivo de publicaciones
CVE
4 290
CVE-2026-41179 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint operations/fsinfo is exposed without AuthRequired: true and accepts attacker-controlled fs input. Because rc.GetFs(...) supports inline backend definitions, an unauthenticated attacker can instantiate an attacker-controlled backend on demand. For the WebDAV backend, bearer_token_command is executed during backend initialization, making single-request unauthenticated local command execution possible on reachable RC deployments without global HTTP authentication. Version 1.73.5 patches the issue.

CVE
4 290
Hey Hunter's, DarkShadow is here back again! 💀File upload extension bypass new method✅ in media upload section you can uploa
+3
Hey Hunter's, DarkShadow is here back again! 💀File upload extension bypass new method✅ in media upload section you can upload files like: .png .jpg .txt .mov but if you upload any php file it block: .php .jpg.php .php7 .shtml The bypass is: ".php " (just add a simple space after .php) This is a very effective and simple way to bypass file upload vulnerbaility. so guy's if you really enjoy to read my methods show your love ❤️ Don't forget to follow me: x.com/darkshadow2bd #bugbountytips #bypass

CVE
4 290
CVE-2026-52813 Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE). This vulnerability is fixed in 0.14.3.

CVE
4 290
CVE-2025-32432 Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

CVE
4 290
CVE-2025-8110 Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

CVE
4 290
CVE-2026-6875

CVE
4 290
CVE-2026-41940 cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVE
4 290
CVE-2026-41940 Author: soverineg cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. GitHub Link: https://github.com/soverineg/cve-2026-41940-PoC

CVE
4 290
A new exploit that works on over 50 WordPress themes is launching soon! 🔥 🚀 For sale only ⭐️ Channel= https://t.me/cve0day
A new exploit that works on over 50 WordPress themes is launching soon! 🔥 🚀 For sale only ⭐️ Channel= https://t.me/cve0day

CVE
4 290
CVE-2026-63030

CVE
4 290
CVE-2026-43074

CVE
4 290
CVE-2025-54793 Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to arbitrary external domains by crafting URLs such as https://mydomain.com//malicious-site.com/. This increases the risk of phishing and other social engineering attacks. This affects sites that use on-demand rendering (SSR) with the Node or Cloudflare adapters. It does not affect static sites, or sites deployed to Netlify or Vercel. This issue is fixed in version 5.12.8. To work around this issue at the network level, block outgoing redirect responses with a Location header value that starts with //.

CVE
4 290
Shells disponibles ✅ Joomla Shells ✅ WordPress Shells Contact: @Mm_fit
Shells disponibles ✅ Joomla Shells ✅ WordPress Shells Contact: @Mm_fit

CVE
4 290
CVE-2026-15410

CVE
4 290
Hey Hunter's, DarkShadow is here back again! (Sorry for the long delay, I was really too busy with my projects) you can find vulnerabilities in chrome extensions!
All of your Chrome extensions are downloaded to your local storage. You can analyze them to find various vulnerabilities, and sometimes they contain sensitive API keys and tokens.
even you can use this dork to find you target company extensions:
site:chromewebstore.google.com "nasa.gov"
replace the nasa.gov to your target domain. so guy's if you really love to read my methods follow me x.com/darkshadow2bd #bugbountytips

CVE
4 290
Available SHells — any number and any quantity , any amount you want, any domain, and any country — everything is available.
Available SHells — any number and any quantity , any amount you want, any domain, and any country — everything is available. DM=> @Mm_fit

CVE
4 290
CVE-2025-69212 OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding functionality. An authenticated attacker can upload a ZIP file containing a .p7m file with a malicious filename to execute arbitrary system commands on the server.

CVE
4 290
CVE-2026-36214

CVE
4 290
CVE-2026-35204

CVE
4 290
CVE-2026-40047