Recent Security research
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
Find out more
Breaking Oracle’s Identity Manager: Pre-Auth RCE (CVE-2025-61757)
Find out more
Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236)
Find out more
Finding Critical Bugs in Adobe Experience Manager
Find out more
Secondary Context Path Traversal in Omnissa Workspace ONE UEM
Find out more
Struts Devmode in 2025? Critical Pre-Auth Vulnerabilities in Adobe Experience Manager Forms
Find out more
How We Accidentally Discovered a Remote Code Execution Vulnerability in ETQ Reliance
Find out more
A Novel Technique for SQL Injection in PDO’s Prepared Statements
Find out more
RCE in the Most Popular Survey Software You’ve Never Heard Of
Find out more
Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)
Find out more
How we got persistent XSS on every AEM cloud site, thrice
Find out more
Novel SSRF Technique Involving HTTP Redirect Loops
Find out more
Loose Types Sink Ships: Pre-Authentication SQL Injection in Halo ITSM
Find out more
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
Find out more
Sitecore: Unsafe Deserialisation Again! (CVE-2025-27218)
Find out more
Nginx/Apache Path Confusion to Auth Bypass in PAN-OS (CVE-2025-0108)
Find out more