XSS2Shell (CVE-2026-64638) is a pre-authentication reflected XSS on the WordPress login screen that escalates to PHP code execution against a logged-in administrator. A plain-English…
CVE-2026-42533 is a critical heap buffer overflow in the NGINX script engine reached through the map directive, with weaponized public exploit code that defeats…
CVE-2026-42945, known as NGINX Rift, is a critical heap buffer overflow in ngx_http_rewrite_module reachable from a single unauthenticated request, with exploitation reported in the…
CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a…
CVE-2026-50522 is a critical, actively-exploited unauthenticated RCE in on-prem Microsoft SharePoint Server (2016, 2019, Subscription Edition). A plain-English advisory, a ready-to-run non-destructive Nuclei detection…
wp2shell (CVE-2026-63030) is an unauthenticated pre-auth RCE in WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1. A plain-English advisory, a ready-to-run Nuclei detection template, remediation, and how…
Sn1per Professional 2026 is here — Docker-first deployment, a fully modernized Bootstrap 5 web UI, Workspace Navigator, JSON API v1.0, comprehensive scan modes, an…
We’re excited to announce the official release of SILENTCHAIN AI™ Community Edition v1.1.3 — a free, AI-powered Burp Suite extension that brings intelligent vulnerability…
We’re excited to announce the release of Sn1per SE v11.0, a major update that delivers a fully refactored codebase, new reconnaissance and vulnerability scanning…
xer0dayz·3 min read
Try it free
See your attack surface like a pentester would.
Sn1per finds, ranks, and exploits real vulnerabilities autonomously — the same way attackers do.