⤷ Title: Langflow File Upload Flaw: Details and PoC Exploit Publicly Disclosed (CVE-2026-55450)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 01:00:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI workflow security #API security #CVE_2026_55450 #CWE_306 #CWE_400 #Denial of Service #File Upload Vulnerability #Information Disclosure #Langflow #unauthenticated upload
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 01:00:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI workflow security #API security #CVE_2026_55450 #CWE_306 #CWE_400 #Denial of Service #File Upload Vulnerability #Information Disclosure #Langflow #unauthenticated upload
Daily CyberSecurity
Langflow File Upload Flaw: Details and PoC Exploit Publicly Disclosed (CVE-2026-55450)
A critical Langflow file upload flaw (CVE-2026-55450) is public with a PoC, enabling unauthenticated denial-of-service and path disclosure. Patch 1.9.1.
⤷ Title: “byp4ss3d” | picoCTF | Obtain RCE by abusing .htaccess in Apache servers | Web Exploitation
════════════════════════
𐀪 Author: Dr_ro0t
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 19:30:03 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #ctf #picoctf #rce_vulnerability
════════════════════════
𐀪 Author: Dr_ro0t
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 19:30:03 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #ctf #picoctf #rce_vulnerability
Medium
“byp4ss3d” | picoCTF | Obtain RCE by abusing .htaccess in Apache servers | Web Exploitation
Achieving Remote Code Execution (RCE) by abusing apache .htaccess to upload a php payload.
⤷ Title: Testing File Upload Vulnerability in web applications part-2
════════════════════════
𐀪 Author: cyb3r_Rs
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 07:30:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #xxe #csrf #file_upload_vulnerability
════════════════════════
𐀪 Author: cyb3r_Rs
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 07:30:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #xxe #csrf #file_upload_vulnerability
Medium
Testing File Upload Vulnerability in web applications part-2
Hii hunters Cyb3r_Rs is here with one more informative & knowledgeable Article. I hope you find this helpful.
This is 2nd part of my last…
This is 2nd part of my last…
⤷ Title: Stored XSS via SVG File Upload in a Project Management Application
════════════════════════
𐀪 Author: 0xPinocchioSec
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:05:53 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #bug_bounty #file_upload #seurity #xss_attack
════════════════════════
𐀪 Author: 0xPinocchioSec
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:05:53 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #bug_bounty #file_upload #seurity #xss_attack
Medium
Stored XSS via SVG File Upload in a Project Management Application
Bug Bounty Write-up | Stored XSS | File Upload Security
⤷ Title: Windows to Linux — 5 File Transfer Techniques for Pentesting Exams
════════════════════════
𐀪 Author: Aman Chauhan
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 16:36:44 GMT
════════════════════════
⌗ Tags: #pentesting #file_transfer #ethical_hacking #oscp #cybersecurity
════════════════════════
𐀪 Author: Aman Chauhan
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 16:36:44 GMT
════════════════════════
⌗ Tags: #pentesting #file_transfer #ethical_hacking #oscp #cybersecurity
Medium
Windows to Linux — 5 File Transfer Techniques for Pentesting Exams
Hey guys, in this writeup we’re going to look at 5 file transfer techniques that will help you transfer files from Windows to Linux. These…
⤷ Title: Unauthenticated RCE in CKFinder via Null Byte Injection Vulnerability
════════════════════════
𐀪 Author: Ali İltizar
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 21:44:30 GMT
════════════════════════
⌗ Tags: #file_upload_bypass #rce #misconfiguration
════════════════════════
𐀪 Author: Ali İltizar
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 21:44:30 GMT
════════════════════════
⌗ Tags: #file_upload_bypass #rce #misconfiguration
Medium
Unauthenticated RCE in CKFinder via Null Byte Injection Vulnerability
During an authorized penetration test on a corporate web application, I was performing directory enumeration against the target when I came…
⤷ Title: From File Upload to Admin Account Takeover: Exploring Blind XSS via Malicious File Content
════════════════════════
𐀪 Author: Orion
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 14:16:54 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #penetration_testing #xss_attack #bug_bounty #web_application_security
════════════════════════
𐀪 Author: Orion
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 14:16:54 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #penetration_testing #xss_attack #bug_bounty #web_application_security
Medium
From File Upload to Admin Account Takeover: Exploring Blind XSS via Malicious File Content
Hi, I’m Hashem Ali Kahil , Orion7715
⤷ Title: HTB Machine Walkthrough: Magic
════════════════════════
𐀪 Author: Balachandar Gowrisankar
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 16:56:07 GMT
════════════════════════
⌗ Tags: #htb_writeup #sql_injection #file_upload_vulnerability #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Balachandar Gowrisankar
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 16:56:07 GMT
════════════════════════
⌗ Tags: #htb_writeup #sql_injection #file_upload_vulnerability #cybersecurity #penetration_testing
Medium
HTB Machine Walkthrough: Magic
Magic is a medium difficulty HTB machine which involves SQL injection attack, arbitrary file upload and SUID binary exploitation.
⤷ Title: The File That Answered Back — XXE Hidden in Cell A2
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:28:59 GMT
════════════════════════
⌗ Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:28:59 GMT
════════════════════════
⌗ Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
Medium
The File That Answered Back — XXE Hidden in Cell A2
Most people know XXE. Few think to look for it inside a spreadsheet upload. But beneath every .xlsx is really a ZIP archive full of XML…
⤷ Title: From SQL Injection to Remote Code Execution: A Complete Security Assessment of the NovaCRM CTF
════════════════════════
𐀪 Author: Rajkumaryarra
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:11:30 GMT
════════════════════════
⌗ Tags: #vulnerability #rce_vulnerability #login_bypass #sql_injection #file_upload_vulnerability
════════════════════════
𐀪 Author: Rajkumaryarra
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:11:30 GMT
════════════════════════
⌗ Tags: #vulnerability #rce_vulnerability #login_bypass #sql_injection #file_upload_vulnerability
Medium
From SQL Injection to Remote Code Execution: A Complete Security Assessment of the NovaCRM CTF
By Raj Kumar
⤷ Title: File Inclusion Challenge (TryHackMe)
════════════════════════
𐀪 Author: Никита Ивашенюта
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 17:10:47 GMT
════════════════════════
⌗ Tags: #tryhackme #pentesting #file_inclusion
════════════════════════
𐀪 Author: Никита Ивашенюта
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 17:10:47 GMT
════════════════════════
⌗ Tags: #tryhackme #pentesting #file_inclusion
Medium
File Inclusion Challenge (TryHackMe)
How I Cracked the TryHackMe File Inclusion Challenges: A Deep Dive into LFI, Cookies, and $_REQUEST Bypasses
⤷ Title: File Upload Bypass On Indrive
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
Medium
File Upload Bypass Using a Pre-Signed S3 URL
welcome to my first write-up. I started bug hunting about 3 months ago, and this was one of my first findings, so I would love to share it.
⤷ Title: The Unseen Share: How I Downloaded Every File on 9 Tail Fox
════════════════════════
𐀪 Author: 0B1To_X_ucH!h4
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 09:18:44 GMT
════════════════════════
⌗ Tags: #abc #file_sharing #idor #bug_bounty
════════════════════════
𐀪 Author: 0B1To_X_ucH!h4
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 09:18:44 GMT
════════════════════════
⌗ Tags: #abc #file_sharing #idor #bug_bounty
Medium
The Unseen Share: How I Downloaded Every File on 9 Tail Fox
An IDOR vulnerability in shared links, a $700 bounty, and the invisible permission that wasn’t there
⤷ Title: File Upload Bypass Using a Pre-Signed S3 URL
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
Medium
File Upload Bypass Using a Pre-Signed S3 URL
welcome to my first write-up. I started bug hunting about 3 months ago, and this was one of my first findings, so I would love to share it.
⤷ Title: HackTheBox Walkthrough — Nexus
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 05:51:01 GMT
════════════════════════
⌗ Tags: #git_repo_escape #ethical_hacking #htb_walkthrough_nexus #file_upload_vulnerability #git_objects
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 05:51:01 GMT
════════════════════════
⌗ Tags: #git_repo_escape #ethical_hacking #htb_walkthrough_nexus #file_upload_vulnerability #git_objects
Medium
HackTheBox Walkthrough — Nexus
#Linux #HTBWalkthrough #HTBNexus #FileUpload #Gitea #Gobuster #fuff #subdomainEnumeration #GitPathTraversal #GitObjects
⤷ Title: SolarWinds Patches Three Critical Serv-U Vulnerabilities Enabling RCE
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 17:21:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #broken access control #CVE_2026_28307 #CVE_2026_28308 #CVE_2026_28321 #File Transfer #IDOR #privilege escalation #rce #SolarWinds #SolarWinds Serv_U
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 17:21:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #broken access control #CVE_2026_28307 #CVE_2026_28308 #CVE_2026_28321 #File Transfer #IDOR #privilege escalation #rce #SolarWinds #SolarWinds Serv_U
Daily CyberSecurity
SolarWinds Patches Three Critical Serv-U Vulnerabilities Enabling RCE
TL;DR SolarWinds fixed three critical SolarWinds Serv-U vulnerabilities on July 21, 2026. They allow privilege escalation and remote code execution on the file transfer server. SolarWinds rates ea…
⤷ Title: SolarWinds Patches 15 Critical Serv-U Vulnerabilities Enabling Root Access
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 17:21:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #broken access control #CVE_2026_28307 #CVE_2026_28308 #CVE_2026_28321 #File Transfer #IDOR #privilege escalation #rce #SolarWinds #SolarWinds Serv_U
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 17:21:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #broken access control #CVE_2026_28307 #CVE_2026_28308 #CVE_2026_28321 #File Transfer #IDOR #privilege escalation #rce #SolarWinds #SolarWinds Serv_U
Daily CyberSecurity
SolarWinds Patches Three Critical Serv-U Vulnerabilities Enabling RCE
TL;DR SolarWinds fixed three critical SolarWinds Serv-U vulnerabilities on July 21, 2026. They allow privilege escalation and remote code execution on the file transfer server. SolarWinds rates ea…
⤷ Title: CTF: Expose TryhackMe Room
════════════════════════
𐀪 Author: Duong
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 19:34:29 GMT
════════════════════════
⌗ Tags: #tryhackme #privilege_escalation #ctf #sqlmap #file_upload
════════════════════════
𐀪 Author: Duong
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 19:34:29 GMT
════════════════════════
⌗ Tags: #tryhackme #privilege_escalation #ctf #sqlmap #file_upload
Medium
CTF: Expose TryhackMe Room
Nmap, sqlmap, wordlists, PHP shell
⤷ Title: How I Found a Bug Worth $3,500 — In a Feature Nobody Was Watching.
════════════════════════
𐀪 Author: Vishw Bhatt
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:52:09 GMT
════════════════════════
⌗ Tags: #admin_panel #file_upload #bug_bounty
════════════════════════
𐀪 Author: Vishw Bhatt
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:52:09 GMT
════════════════════════
⌗ Tags: #admin_panel #file_upload #bug_bounty
Medium
How I Found a Bug Worth $3,500 — In a Feature Nobody Was Watching.
A storage-exhaustion flaw. A stored XSS that waited for an admin. Both hiding in the same “boring” file upload form that hadn’t been…
⤷ Title: Upload de arquivos não é apenas uma funcionalidade: é uma fronteira de segurança
════════════════════════
𐀪 Author: Cristiano Junior
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 12:58:03 GMT
════════════════════════
⌗ Tags: #application_security #secure_coding #file_upload_security #cybersecurity #web_security
════════════════════════
𐀪 Author: Cristiano Junior
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 12:58:03 GMT
════════════════════════
⌗ Tags: #application_security #secure_coding #file_upload_security #cybersecurity #web_security