CVE-2026-42533 is a critical heap buffer overflow in the NGINX script engine reached through the map directive, with weaponized public exploit code that defeats…
CVE-2026-42945, known as NGINX Rift, is a critical heap buffer overflow in ngx_http_rewrite_module reachable from a single unauthenticated request, with exploitation reported in the…
CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a…
CVE-2026-50522 is a critical, actively-exploited unauthenticated RCE in on-prem Microsoft SharePoint Server (2016, 2019, Subscription Edition). A plain-English advisory, a ready-to-run non-destructive Nuclei detection…
wp2shell (CVE-2026-63030) is an unauthenticated pre-auth RCE in WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1. A plain-English advisory, a ready-to-run Nuclei detection template, remediation, and how…
Our security research team recently discovered a critical “0day” vulnerability which was assigned CVE-2024-21733. The vulnerability was discovered by xer0dayz from Sn1perSecurity LLC and…
A critical vulnerability affecting the Atlassian Confluence was disclosed and designated CVE-2022-26134 which allows an un-authenticated attacker to execute arbitrary code on vulnerable servers.…
A critical vulnerability affecting the F5 BIG-IP devices was disclosed and designated CVE-2022-1388 which allows an un-authenticated attacker to execute arbitrary code on vulnerable…
Information regarding a critical 0-day vulnerability affecting the VMware Workspace ONE Access and Identity Manager was disclosed and designated CVE-2022-22954 which allows an un-authenticated…
xer0dayz·1 min read
Try it free
See your attack surface like a pentester would.
Sn1per finds, ranks, and exploits real vulnerabilities autonomously — the same way attackers do.