Code Injection
Attacker-controlled data reaching an interpreter, template engine or shell.
Published work on this topic
| 2026-09-22 | CVE-2026-60004 | CVE-2026-60004 Exploit: Gitea RCE via Hook | PoC | |
| 2026-08-24 | CVE-2026-77647 | CVE-2026-77647: SPIP Pre-Auth RCE | PoC | |
| 2026-08-13 | CVE-2026-67282 | CVE-2026-67282: Fabrik Unauthenticated RCE | PoC | |
| 2026-08-11 | CVE-2026-66915 | CVE-2026-66915: Fabrik Calc Element RCE | PoC | |
| 2026-08-04 | CVE-2026-69251 | CVE-2026-69251: Flowise Authenticated RCE | PoC | |
| 2026-07-22 | CVE-2026-47668 | CVE-2026-47668: DbGate Unauthenticated RCE | PoC |
Other topics
remote code execution38authentication bypass19wordpress14php13authorization bypass9java9path traversal9sql injection8privilege escalation7denial of service6heap overflow6insecure deserialization5information disclosure5qemu5apache tomcat4go4node.js4python4cross-site scripting4buffer overflow3gitea3gitlab3javascript3
