rce

105 articles
Sort: New Top Best
clear filter
0
bug-bounty

A bug bounty researcher discovered RCE on an abandoned staging web service via an unauthenticated PUT HTTP method that allowed arbitrary file uploads, enabling PHP web shell deployment and subsequent internal network traversal with privilege escalation through credential reuse and weak security practices.

nmap ncat netcat PHP Python SSH RDP SMB DNS zone transfer
blog.zsec.uk · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0 1/10

A brief mention of a $36,000 bug bounty for a remote code execution vulnerability in Google App Engine, but with no technical details provided.

Google Google App Engine
sites.google.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0

An RCE vulnerability was discovered via Rack's ShowExceptions middleware being enabled in production, which leaked the Rails secret token used to sign cookies. The attacker used this token to forge authenticated cookies and execute arbitrary commands on the server.

Rack Rails ShowExceptions action_dispatch.secret_token secret_token.rb robertheaton.com
sites.google.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
rce
blog.orange.tw · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0

A researcher discovered an unauthenticated Apache Solr instance running on a Microsoft subdomain vulnerable to CVE-2019-17558, exploitable via velocity template injection to achieve RCE. The attack requires modifying the params.Resource.Loader.Enabled configuration and then sending a malicious velocity template payload.

CVE-2019-17558 Microsoft Apache Solr tide90.microsoft.com Muhammad Khizer Javed
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
rce
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
rcesecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
vulnerability
blog.ripstech.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
ysx.me.uk · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
noobe.io · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
vulnerability
matatall.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
vulnerability
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
rcesecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details
0
CVE-2026-21666 CVE-2026-21667 CVE-2026-21669 CVE-2026-21708
bleepingcomputer.com · Sergiu Gatlan · 6 hours ago · details
0
blog.langchain.com · gmays · 8 hours ago · details · hn
0
arxiv.org · mdelmundo · 8 hours ago · details · hn
0
CVE-2023-41974 CVE-2023-43000 CVE-2023-43010 CVE-2024-23222 CVE-2026-20700
bleepingcomputer.com · Sergiu Gatlan · 9 hours ago · details
0 5/10

Educational article covering file upload vulnerability techniques, attack vectors (such as shell.php.jpg bypasses), and defensive hardening strategies to prevent unauthorized file uploads and remote code execution.

medium.com · Very Lazy Tech · 12 hours ago · details
0
CVE-2025-68613
thehackernews.com · [email protected] (The Hacker News) · 17 hours ago · details
0
CVE-2023-41974 CVE-2023-43000 CVE-2023-43010 CVE-2024-23222
support.apple.com · seam_carver · 21 hours ago · details · hn
0 4/10

Monthly security patch review covering March 2026 releases from Adobe (80 CVEs across 8 bulletins) and Microsoft (94 CVEs total including third-party updates), with detailed analysis of critical vulnerabilities including Office RCE via Preview Pane, Windows Print Spooler RCE, Excel XSS enabling Copilot data exfiltration, and Windows Graphics elevation-of-privilege bugs.

CVE-2026-26144 CVE-2026-26110 CVE-2026-26113 CVE-2026-23669 CVE-2026-23668 TrendAI ZDI Adobe Microsoft Marcin Wiązowski PrintNightmare
thezdi.com · Dustin Childs · 2 days ago · details
0
CVE-2026-0651 CVE-2026-0652 CVE-2026-0653
spaceraccoon.dev · spaceraccoon · 6 days ago · details
0
CVE-2025-4143 CVE-2025-4144 CVE-2025-53100 CVE-2025-53818 CVE-2025-6514
blog.doyensec.com · doyensec · 8 days ago · details
0
bishopfox.com · bishopfox · 9 days ago · details
0
blog.securelayer7.net · securelayer7 · 10 days ago · details
0
horizon3.ai · Daniel Limanowski · 13 days ago · details
0
rce
bishopfox.com · bishopfox · 16 days ago · details
More