remote-code-execution

Tag

Cards List
#remote-code-execution

@Dinosn: Dnsmasq DNS Remote Heap Buffer Overflow

X AI KOLs Timeline · 3d ago Cached

A heap buffer overflow vulnerability in Dnsmasq (CVE-2026-2291) allows remote code execution via a malicious upstream DNS server. The issue was introduced in version 2.73 and fixed in 2.92rel2 and 2.93.

0 favorites 0 likes
#remote-code-execution

Hacking Apple - SQL Injection to Remote Code Execution — ProjectDiscovery Blog

Lobsters Hottest · 2026-07-12 Cached

A detailed write-up from ProjectDiscovery detailing how they discovered a critical SQL injection vulnerability in Apple's Book Travel portal via Masa/Mura CMS and achieved Remote Code Execution.

0 favorites 0 likes
#remote-code-execution

Hackers are exploiting a critical WordPress form plugin flaw to take over websites

Reddit r/ArtificialInteligence · 2026-06-05

Hackers are actively exploiting a critical remote code execution vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, affecting versions up to 1.9.12. The flaw allows unescaped form values to be passed to eval(), enabling full site compromise. Wordfence urges immediate plugin updates.

0 favorites 0 likes
#remote-code-execution

New Nginx Exploit

Hacker News Top · 2026-05-14 Cached

A critical heap buffer overflow vulnerability in Nginx's rewrite module (CVE-2026-42945) allows unauthenticated remote code execution, with a proof-of-concept exploit released. The bug affects Nginx versions from 0.6.27 to 1.30.0 and various Nginx Plus releases.

0 favorites 0 likes
#remote-code-execution

Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability

Lobsters Hottest · 2026-05-13 Cached

Researchers used an autonomous system to discover a critical heap buffer overflow vulnerability in NGINX's rewrite module (CVE-2026-42945), present since 2008, enabling remote code execution. Multiple CVEs were confirmed by NGINX.

0 favorites 0 likes
#remote-code-execution

Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection

Lobsters Hottest · 2026-05-13 Cached

A security researcher discovered a Remote Code Execution (RCE) vulnerability in Claude Code caused by improper parsing of deeplink settings, allowing arbitrary command injection via hooks. The issue has been resolved in version 2.1.118.

0 favorites 0 likes
#remote-code-execution

The React2Shell Story and What Happened Next.js

Lobsters Hottest · 2026-05-09 Cached

This article details the discovery and disclosure of CVE-2025-5518 (React2Shell), a critical remote code execution vulnerability in React Server Components, explaining how researchers bypassed Flight protocol validations to access object prototypes.

0 favorites 0 likes
#remote-code-execution

The React2Shell Story

Hacker News Top · 2026-05-08 Cached

Security researcher Lachlan discovered and reported a critical remote code execution vulnerability dubbed "React2Shell" in React's Server Components protocol to Meta on November 30, 2025. Meta released a fix and public advisory (CVE-2025-55182) on December 3, urging developers to update immediately as the vulnerability affected millions of websites built with React/Next.js.

0 favorites 0 likes
← Back to home

Submit Feedback