⤷ Title: Plant Photographer TryHackMe Writeup
════════════════════════
𐀪 Author: Amimerayoub
════════════════════════
ⴵ Time: Sun, 29 Mar 2026 15:21:24 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #cybersecurity #ssrf #tryhackme
════════════════════════
𐀪 Author: Amimerayoub
════════════════════════
ⴵ Time: Sun, 29 Mar 2026 15:21:24 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #cybersecurity #ssrf #tryhackme
Medium
Plant Photographer TryHackMe Writeup
Chaining SSRF, File Read & Werkzeug RCE
⤷ Title: WIZ Bug Bounty Master Class: SSRF Vulnerability on Major Gaming Company
════════════════════════
𐀪 Author: Jared Douville
════════════════════════
ⴵ Time: Fri, 27 Mar 2026 14:27:07 GMT
════════════════════════
⌗ Tags: #hackerone #web_app_security #ssrf #bug_bounty
════════════════════════
𐀪 Author: Jared Douville
════════════════════════
ⴵ Time: Fri, 27 Mar 2026 14:27:07 GMT
════════════════════════
⌗ Tags: #hackerone #web_app_security #ssrf #bug_bounty
Medium
WIZ Bug Bounty Master Class: SSRF Vulnerability on Major Gaming Company
URL: https://content-service.bugbountymasterclass.com
⤷ Title: CVE-2025–4123 Grafana Open Redirect & SSRF — Full PoC — CVSS 7.6 HIGH
════════════════════════
𐀪 Author: Dharanis
════════════════════════
ⴵ Time: Thu, 26 Mar 2026 18:22:21 GMT
════════════════════════
⌗ Tags: #ssrf #bug_bounty #cybersecurity #grafana #vapt
════════════════════════
𐀪 Author: Dharanis
════════════════════════
ⴵ Time: Thu, 26 Mar 2026 18:22:21 GMT
════════════════════════
⌗ Tags: #ssrf #bug_bounty #cybersecurity #grafana #vapt
Medium
CVE-2025–4123 Grafana Open Redirect & SSRF — Full PoC — CVSS 7.6 HIGH
Client-Side Path Traversal in /public/ · No Auth Required · Grafana < 12.0.0
⤷ Title: Modern SSRF — Part 4 (Expert Edition): How to Write High-Impact SSRF Reports ThWWW at Earn 5×…
════════════════════════
𐀪 Author: ◦•●◉✿ ¥ຮ₰ ʜc ✿◉●•◦
════════════════════════
ⴵ Time: Thu, 26 Mar 2026 09:09:22 GMT
════════════════════════
⌗ Tags: #bug_bounty #ssrf #cyber_security_awareness #cybersecurity #bug_bounty_tips
════════════════════════
𐀪 Author: ◦•●◉✿ ¥ຮ₰ ʜc ✿◉●•◦
════════════════════════
ⴵ Time: Thu, 26 Mar 2026 09:09:22 GMT
════════════════════════
⌗ Tags: #bug_bounty #ssrf #cyber_security_awareness #cybersecurity #bug_bounty_tips
Medium
🚀 Modern SSRF — Part 4 (Expert Edition): How to Write High-Impact SSRF Reports ThWWW at Earn 5× Bigger Bounties
जय श्री राम 🚩🕉️ , Readers
⤷ Title: Server-Side Request Forgery (SSRF) - When Attackers Use Your Own Server as Their Personal Messenger
════════════════════════
𐀪 Author: Rufus Kehinde
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 18:17:58 GMT
════════════════════════
⌗ Tags: #ai #information_security #cybersecurity #ssrf #serverless
════════════════════════
𐀪 Author: Rufus Kehinde
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 18:17:58 GMT
════════════════════════
⌗ Tags: #ai #information_security #cybersecurity #ssrf #serverless
Medium
Server-Side Request Forgery (SSRF) - When Attackers Use Your Own Server as Their Personal Messenger
The most dangerous position an attacker can reach is not outside your system throwing attacks at it. It is inside your network, making…
⤷ Title: From Exposure to RCE: Inside the Wing FTP Server Attack Chain
════════════════════════
𐀪 Author: Criminal IP
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 08:44:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #server_attack_chain #it_security #wing_ftp #rce
════════════════════════
𐀪 Author: Criminal IP
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 08:44:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #server_attack_chain #it_security #wing_ftp #rce
Medium
From Exposure to RCE: Inside the Wing FTP Server Attack Chain
A recently discovered information disclosure vulnerability in Wing FTP Server (CVE-2025–47813) has been confirmed to be actively exploited…
⤷ Title: F5 BIG‑IP RCE Exploited: Why You Must Patch Now — Actionable Security
════════════════════════
𐀪 Author: Frank Marano
════════════════════════
ⴵ Time: Mon, 30 Mar 2026 00:00:20 GMT
════════════════════════
⌗ Tags: #cyberattack #rce #f5_big_ip #cybersecurity #f5
════════════════════════
𐀪 Author: Frank Marano
════════════════════════
ⴵ Time: Mon, 30 Mar 2026 00:00:20 GMT
════════════════════════
⌗ Tags: #cyberattack #rce #f5_big_ip #cybersecurity #f5
Medium
F5 BIG‑IP RCE Exploited: Why You Must Patch Now — Actionable Security
Every few months, the cybersecurity world gifts us a new reminder that the internet is basically a haunted house full of unpatched…
⤷ Title: CVE-2026–24061 GNU InetUtils Telnetd Authentication Bypass Vulnerability — RCE as Root
════════════════════════
𐀪 Author: Eternal Edge
════════════════════════
ⴵ Time: Sat, 28 Mar 2026 12:23:40 GMT
════════════════════════
⌗ Tags: #linux #rce #cve #telnet #vulnerability_research
════════════════════════
𐀪 Author: Eternal Edge
════════════════════════
ⴵ Time: Sat, 28 Mar 2026 12:23:40 GMT
════════════════════════
⌗ Tags: #linux #rce #cve #telnet #vulnerability_research
Medium
CVE-2026–24061 GNU InetUtils Telnetd Authentication Bypass Vulnerability — RCE as Root
11 yıl boyunca keşfedilmeyen bu açık, tek bir ortam değişkeni manipülasyonu ile root shell elde etmenizi sağlıyor.
⤷ Title: I Thought It Was a Container… It Was a Whole Azure VM (RCE Story)
════════════════════════
𐀪 Author: Utkarsh Srivastava
════════════════════════
ⴵ Time: Mon, 23 Mar 2026 19:43:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #rce_vulnerability #rce
════════════════════════
𐀪 Author: Utkarsh Srivastava
════════════════════════
ⴵ Time: Mon, 23 Mar 2026 19:43:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #rce_vulnerability #rce
Medium
I Thought It Was a Container… It Was a Whole Azure VM (RCE Story)
Escaping the IDE: From Code Execution to Root on Azure VM
⤷ Title: File Upload by RCE: Apache Tomcat Manager Exploit
════════════════════════
𐀪 Author: Digvijaysingh
════════════════════════
ⴵ Time: Mon, 23 Mar 2026 11:04:28 GMT
════════════════════════
⌗ Tags: #shell #reverse_shell #rce_vulnerability #rce #remote_code_execution
════════════════════════
𐀪 Author: Digvijaysingh
════════════════════════
ⴵ Time: Mon, 23 Mar 2026 11:04:28 GMT
════════════════════════
⌗ Tags: #shell #reverse_shell #rce_vulnerability #rce #remote_code_execution
Medium
🧠 File Upload by RCE: Apache Tomcat Manager Exploit
🔎 1. Recon
⤷ Title: CVE-2026–22812: How I Got RCE on a 71k-Star AI Coding Tool With Zero Authentication
════════════════════════
𐀪 Author: Dharanis
════════════════════════
ⴵ Time: Sat, 21 Mar 2026 17:10:46 GMT
════════════════════════
⌗ Tags: #open_code #bug_bounty #cybersecurity #rce #vulnerability
════════════════════════
𐀪 Author: Dharanis
════════════════════════
ⴵ Time: Sat, 21 Mar 2026 17:10:46 GMT
════════════════════════
⌗ Tags: #open_code #bug_bounty #cybersecurity #rce #vulnerability
Medium
CVE-2026–22812: How I Got RCE on a 71k-Star AI Coding Tool With Zero Authentication
Unauthenticated Remote Code Execution in OpenCode — CVSS 8.8 (High)
⤷ Title: Cross Site Scripting (XSS):
════════════════════════
𐀪 Author: Sandeeppavan
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 07:24:26 GMT
════════════════════════
⌗ Tags: #dom_xss #xss_attack #stored_xss #xss_vulnerability #reflected_xss
════════════════════════
𐀪 Author: Sandeeppavan
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 07:24:26 GMT
════════════════════════
⌗ Tags: #dom_xss #xss_attack #stored_xss #xss_vulnerability #reflected_xss
Medium
Cross Site Scripting (XSS):
Introduction:
⤷ Title: An Open Door for Attackers. Lock It with CSP.
════════════════════════
𐀪 Author: Asrarul Hoque Eusha
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 13:09:06 GMT
════════════════════════
⌗ Tags: #content_security_policy #xss_vulnerability #web_security #clickjacking
════════════════════════
𐀪 Author: Asrarul Hoque Eusha
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 13:09:06 GMT
════════════════════════
⌗ Tags: #content_security_policy #xss_vulnerability #web_security #clickjacking
Medium
An Open Door for Attackers. Lock It with CSP.
A complete guide to Content Security Policy — from your first header to a production-hardened, violation-reporting policy.
⤷ Title: Robots CTF | TryHackMe Walkthrough
════════════════════════
𐀪 Author: Yoel Yosief [ Orit01 ]
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 13:05:08 GMT
════════════════════════
⌗ Tags: #web_exploitation #xss_vulnerability #tryhackme_walkthrough #ssrf_attack #rce_vulnerability
════════════════════════
𐀪 Author: Yoel Yosief [ Orit01 ]
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 13:05:08 GMT
════════════════════════
⌗ Tags: #web_exploitation #xss_vulnerability #tryhackme_walkthrough #ssrf_attack #rce_vulnerability
Medium
Robots CTF | TryHackMe Walkthrough
A (small) tribute to I. Asimov.
⤷ Title: Securing the Edges: A Practical Way to Handle XSS in Modern Apps
════════════════════════
𐀪 Author: Dogukan Batal
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 09:02:27 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #javascript #xss_attack #cross_site_scripting #web_security
════════════════════════
𐀪 Author: Dogukan Batal
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 09:02:27 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #javascript #xss_attack #cross_site_scripting #web_security
Medium
Securing the Edges: A Practical Way to Handle XSS in Modern Apps
Modern frameworks like React or Vue protect us from many XSS attacks by default. They escape values automatically and make common mistakes…
⤷ Title: XSS (Cross site scripting)
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 26 Mar 2026 05:34:51 GMT
════════════════════════
⌗ Tags: #xss_vulnerability
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 26 Mar 2026 05:34:51 GMT
════════════════════════
⌗ Tags: #xss_vulnerability
Medium
XSS (Cross site scripting)
Cross-site scripting (also known as XSS) is a web security vulnerability that allows an attacker to compromise the interactions that users…
⤷ Title: Why location.href Isn’t Just a Redirect:
════════════════════════
𐀪 Author: Marduk I Am
════════════════════════
ⴵ Time: Tue, 24 Mar 2026 17:38:54 GMT
════════════════════════
⌗ Tags: #bug_bounty #xss_vulnerability #web_security #information_security #cybersecurity
════════════════════════
𐀪 Author: Marduk I Am
════════════════════════
ⴵ Time: Tue, 24 Mar 2026 17:38:54 GMT
════════════════════════
⌗ Tags: #bug_bounty #xss_vulnerability #web_security #information_security #cybersecurity
Medium
Why location.href Isn’t Just a Redirect:
Understanding Navigation-Based XSS
⤷ Title: From iframe Injection to Account Takeover (Full Exploit Chain)
════════════════════════
𐀪 Author: 0xRedFox29
════════════════════════
ⴵ Time: Mon, 23 Mar 2026 06:24:04 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #xss_vulnerability #bug_bounty_writeup #bug_bounty #account_takeover_attacks
════════════════════════
𐀪 Author: 0xRedFox29
════════════════════════
ⴵ Time: Mon, 23 Mar 2026 06:24:04 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #xss_vulnerability #bug_bounty_writeup #bug_bounty #account_takeover_attacks
Medium
From iframe Injection to Account Takeover (Full Exploit Chain)🔥
How can I escalate the impact of an iframe injection vulnerability to account takeover via XSS?
⤷ Title: Stored DOM XSS to Account Takeover
════════════════════════
𐀪 Author: 0xRedFox29
════════════════════════
ⴵ Time: Sat, 21 Mar 2026 13:15:25 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #account_takeover #bug_bounty_writeup #xss_attack #bug_bounty_tips
════════════════════════
𐀪 Author: 0xRedFox29
════════════════════════
ⴵ Time: Sat, 21 Mar 2026 13:15:25 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #account_takeover #bug_bounty_writeup #xss_attack #bug_bounty_tips
Medium
Stored DOM XSS to Account Takeover
bagaimana teknik melewati XSS filter dengan payload yang whitelist untuk memaksimalkan fitur dan menaikan dampaknya ke account takeover
⤷ Title: How Do Concrete Vaults Actually Work?
════════════════════════
𐀪 Author: Hirabauldas
════════════════════════
ⴵ Time: Fri, 27 Mar 2026 03:49:06 GMT
════════════════════════
⌗ Tags: #zcf #rce_vulnerability #werewolves #book_recommendations #c
════════════════════════
𐀪 Author: Hirabauldas
════════════════════════
ⴵ Time: Fri, 27 Mar 2026 03:49:06 GMT
════════════════════════
⌗ Tags: #zcf #rce_vulnerability #werewolves #book_recommendations #c
Medium
How Do Concrete Vaults Actually Work?
You open a DeFi app, deposit your funds into a vault, and suddenly you see new terms appear — vault shares, eRate, and NAV. Your balance…
⤷ Title: CVE-2026–33139 How I Found My First CVE: Bypassing PySpector’s Plugin Security Sandbox
════════════════════════
𐀪 Author: Shinigami81
════════════════════════
ⴵ Time: Wed, 25 Mar 2026 17:00:00 GMT
════════════════════════
⌗ Tags: #python #cybersecurity #security_research #pyspector #rce_vulnerability
════════════════════════
𐀪 Author: Shinigami81
════════════════════════
ⴵ Time: Wed, 25 Mar 2026 17:00:00 GMT
════════════════════════
⌗ Tags: #python #cybersecurity #security_research #pyspector #rce_vulnerability
Medium
CVE-2026–33139 How I Found My First CVE: Bypassing PySpector’s Plugin Security Sandbox
Where it started