Experts, Qualified Security Team
CVE-2024-5932. GiveWP PHP Object Injection exploit
78CVE-2024-46538. PfSense Stored XSS lead to Arbitrary Code Execution exploit
51CVE-2025-1302. JSONPath-plus Remote Code Execution
21CVE-2024-53677. File upload logic flaw in Apache Struts2 exploit
17CVE-2026-49975. HTTP/2 Bomb
13CVE-2024-8353. GiveWP PHP Object Injection exploit
12CVE-2024-9014. Pgadmin4 Sensitive Information Exposure
8git_rce. Git clone Remote Code Execution exploit
5CVE-2024-48914. Arbitrary File Read and DoS in vendure-ecommerce exploit
5CVE-2024-34102. Adobe Commerce XXE exploit
4CVE-2026-5027. Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal
3CVE-2026-33017. Langflow RCE
3CVE-2026-26980. Ghost Content API SQL Injection
3CVE-2024-25292. XSS to RCE in RenderTune v1.1.4 exploit
2Race_Condition. Exercise for the race condition attack
2CVE-2025-29927. Next.js middleware bypass exploit
2CVE-2025-3248. Langflow Remote Code Execution
2CVE-2026-25253. OpenClaw Authentication Token Exfiltration
2CVE-2026-40897. Math.js Expression Parser RCE
2CVE-2026-42048. Langflow Arbitrary Directory Deletion
2CVE-2025-26788. Strongkey FIDO Server Authorization Bypass
1CVE-2025-55182. React2Shell
1CVE-2026-21858. Ni8mare, n8n RCE
1CVE-2025-24813. Apache Tomcat RCE
1CVE-2026-30951. Sequelize JSON Cast SQL Injection
1CVE-2026-0603. Hibernate ORM Second-Order SQL Injection
1CVE-2026-33937. Handlebars.js AST Injection Remote Code Execution Vulnerability
1CVE-2026-34220. SQL Injection vulnerability in MikroORM
1