31. Nextcloud CVE-2026-45281 Cross-Account Calendar Takeover vulnerability | High | 2026-07-17 00:00 | CVE-2026-45281 | ethiack.com | original ↗ | #vulnerability-research | #access-control | #calendar-security
32. Exploitation in the Wild of wp2shell blog | 2026-07-20 18:00 | wiz.io | original ↗ | #rce | #wordpress | #vulnerability
33. CVE-2026-42980 PoC: Windows kernel WMI integer underflow local privilege escalation vulnerability | High | 2026-07-07 03:52 | CVE-2026-42980 | github.com | original ↗ | #public-poc | #kernel-security | #privilege-escalation
34. HestiaCP Admin Takeover & RCE research | 2026-07-04 12:00 | CVE-2026-12196 | projectblack.io | original ↗ | #rce | #vulnerability-research | #access-control
35. CVE-2026-48907: Unauthenticated RCE in the Joomla Content Editor extension vulnerability | Critical | Actively exploited | 2026-06-12 13:16 | CVE-2026-48907 | yeswehack.com | original ↗ | #active-exploitation | #rce | #public-poc
36. The goldmine of insecure WebView integrations blog | 2026-06-18 12:00 | osec.io | original ↗ | #web3 | #vulnerability | #mobile
37. Circuit Breaker: The Missing Constraint That Compromised RISC Zero’s zkVM blog | 2026-06-11 10:03 | hackenproof.com | original ↗ | #bug-bounty | #web3 | #vulnerability-research
38. How OLTs may have exposed entire ISP networks research | 2026-05-18 22:00 | blog.quarkslab.com | original ↗ | #cloud | #cloud-security | #attack-chains
39. Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP vulnerability | 2026-05-13 12:13 | wiz.io | original ↗ | #privilege-escalation | #linux-kernel | #vulnerability
40. Dirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPC vulnerability | 2026-05-08 08:57 | CVE-2026-43284 | wiz.io | original ↗ | #privilege-escalation | #linux-kernel | #vulnerability
41. Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild vulnerability | 2026-05-06 12:33 | CVE-2026-0300 | wiz.io | original ↗ | #rce | #vulnerability | #palo-alto-networks
42. Copy Fail: Universal Linux Local Privilege Escalation Vulnerability vulnerability | 2026-05-01 12:38 | CVE-2026-31431 | wiz.io | original ↗ | #privilege-escalation | #linux-kernel | #vulnerability
43. Unverified evaluations in Dusk’s PLONK blog | 2026-04-30 12:00 | osec.io | original ↗ | #web3 | #vulnerability-research | #vulnerability
44. Milking the last drop of Intego - Time for Windows to get its LPE research | 2026-04-06 22:00 | blog.quarkslab.com | original ↗ | #vulnerability-research | #privilege-escalation | #windows-security
45. Intego X9: Never trust my updates research | 2026-03-19 23:00 | blog.quarkslab.com | original ↗ | #vulnerability-research | #privilege-escalation | #macos
46. Unfaithful claims: breaking 6 zkVMs blog | 2026-03-03 12:00 | osec.io | original ↗ | #web3 | #vulnerability-research | #cryptography
47. February 2026 vulnerability: What happened? blog | 2026-03-02 12:10 | metabase.com | original ↗ | #vulnerability | #metabase | #postmortem
48. Intego X9: When your macOS antivirus becomes your enemy research | 2026-02-09 23:00 | blog.quarkslab.com | original ↗ | #vulnerability-research | #privilege-escalation | #macos
49. Hunting OpenClaw Exposures: CVE-2026-25253 in Internet-Facing AI Agent Gateways vulnerability | High | 2026-02-03 00:00 | CVE-2026-25253 | hunt.io | original ↗ | #ai-security | #vulnerability | #ai-agents
50. EVerest security audit research | 2026-01-19 23:00 | blog.quarkslab.com | original ↗ | #appsec | #vulnerability-research | #vulnerability
51. CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild blog | 2026-01-15 15:00 | wiz.io | original ↗ | #cloud | #supply-chain | #aws
52. IDOR Vulnerabilities Explained: Why They Persist in Modern Applications blog | 2026-01-02 00:00 | aikido.dev | original ↗ | #appsec | #access-control | #web-security
53. MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know vulnerability | 2025-12-28 09:24 | CVE-2025-14847 | wiz.io | original ↗ | #cloud | #memory-safety | #information-disclosure
54. React2Shell (CVE-2025-55182): Node.js RCE Against a Production Next.js App vulnerability | Critical | Actively exploited | 2025-12-10 00:00 | CVE-2025-55182 | hunt.io | original ↗ | #rce | #vulnerability | #nextjs
55. Gogs 0-Day Exploited in the Wild vulnerability | 2025-12-10 15:00 | CVE-2025-8110 | wiz.io | original ↗ | #rce | #zero-day | #vulnerability
56. CVE-2025-55182 and CVE-2025-66478 (“React2Shell”): All you need to know – UPDATED vulnerability | 2025-12-09 14:15 | jfrog.com | original ↗ | #rce | #vulnerability | #react2shell
57. Orthanc 1.12.9 User Impersonation research | 2025-12-09 00:53 | CVE-2025-15581 | projectblack.io | original ↗ | #appsec | #vulnerability-research | #vulnerability
58. Kubevirt security audit research | 2025-11-06 23:00 | blog.quarkslab.com | original ↗ | #kubernetes | #virtualization | #vulnerability
59. How we broke exchanges: a deep dive into authentication and client-side bugs research | 2025-10-16 12:00 | osec.io | original ↗ | #web3 | #account-takeover | #authentication
60. RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score vulnerability | 2025-10-06 21:00 | CVE-2025-49844 | wiz.io | original ↗ | #rce | #cloud-security | #vulnerability