writeups.xyz writeups.xyz / Maxwell Garrett (@TheGrandPew)

Title Vulnerabilities Programs Authors
Chaining our way to Pre-Auth RCE in Metabase (CVE-2023-38646)
Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails
Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI
Breaking Bitbucket: Pre Auth Remote Command Execution (CVE-2022-36804)
Remote Code Execution on Element Desktop Application using Node Integration in Sub Frames Bypass - CVE-2022-23597
Visual Studio Code - Remote Code Execution in Restricted Mode (CVE-2021-43908)