writeups.xyz writeups.xyz / RCE

Title Vulnerabilities Programs Authors
Jumpserver Preauth RCE Exploit Chain
Relution Remote Code Execution via Java Deserialization Vulnerability
Analysis Of Multiple Vulnerabilities In Ofbiz
CVE-2023-5372 - Post-auth blind Python code injection vulnerabilities in Zyxel’s NAS326 and NAS542 devices
Hunting for Unauthenticated n-days in Asus Routers
Who are you? The Importance of Verifying Message Origins
SSD Advisory – Zyxel VPN Series Pre-auth Remote Command Execution
*nix libX11: Uncovering and exploiting a 35-year-old vulnerability – Part 2 of 2
Multiple vulnerabilities in Cisco Unified Communications Manager version 11.5.1
A christmas tale: pwning GTB Central Console (CVE-2024-22107 & CVE-2024-22108)
Atlassian Confluence - Remote Code Execution (CVE-2023-22527)
Gambio 4.9.2.0 - Insecure Deserialization
High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE (CVE-2023-46805 & CVE-2024-21887)
Nokia vBMC — BMC Log Scanner Remote Code Execution
I found 2 Zero-Days in popular Linux distros that includes Mint, Kali, Parrot
Multiple vulnerabilities in Ivanti Connect Secure
“MyFlaw” — Cross Platform 0-Day RCE Vulnerability Discovered in Opera’s Browser
Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability
CVE-2023–50220 — Inductive Automation Ignition XML Deserialization to RCE
Unauthenticated RCE in Adobe Coldfusion – CVE-2023-26360
MobSF Remote code execution (via CVE-2024-21633)
Panic!! At the YAML
Technical Advisory – Multiple Vulnerabilities in PandoraFMS Enterprise
How I made 7K on Epic Games Bug Bounty
Finding Insecure TrustManagers and Disabled Hostname Verification with CodeQL