CVE-2019-9506
Author: BrainsBook

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

GitHub Link:
https://github.com/BrainsBook/knob
🍾1
CVE-2018-15133
Author: flame-11

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.

GitHub Link:
https://github.com/flame-11/CVE-2018-15133-laravel-framework
🍾1
CVE-2025-22777.zip
2.5 KB
CVE-2025-22777
Author: SevDMG

Deserialization of Untrusted Data vulnerability in GiveWP GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.19.3.

GitHub Link:
https://github.com/SevDMG/CVE-2025-22777-GiveWP-Plugin-PHP-Object-Injection-Point-PoC-
🍾1
CVE-2024-44083.zip
2.3 KB
CVE-2024-44083
Author: dynamicx64

ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry point will be invoked. NOTE: in many use cases, this is an inconvenience but not a security issue.

GitHub Link:
https://github.com/dynamicx64/CVE-2024-44083
🍾1