CVE-2026-42533 is a critical heap buffer overflow in the NGINX script engine reached through the map directive, with weaponized public exploit code that defeats…
CVE-2026-42945, known as NGINX Rift, is a critical heap buffer overflow in ngx_http_rewrite_module reachable from a single unauthenticated request, with exploitation reported in the…
CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a…
CVE-2026-50522 is a critical, actively-exploited unauthenticated RCE in on-prem Microsoft SharePoint Server (2016, 2019, Subscription Edition). A plain-English advisory, a ready-to-run non-destructive Nuclei detection…
wp2shell (CVE-2026-63030) is an unauthenticated pre-auth RCE in WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1. A plain-English advisory, a ready-to-run Nuclei detection template, remediation, and how…
Discover live hosts, open ports, services, and connected devices across your internal subnets with Sn1per Professional 2026 - a self-hosted, automated network and subnet…
Active reconnaissance explained for 2026 - port scanning, service and technology fingerprinting, screenshots and endpoint discovery - the tools, the scope rules, and how…
How to enumerate subdomains in 2026 - passive sources, active brute force and permutation, DNS resolution, virtual hosts and takeover checks - with the…
A phased reconnaissance methodology for bug bounty, red team and external attack surface management. Every recon stage from OSINT to reporting - and how…
xer0dayz·13 min read
Try it free
See your attack surface like a pentester would.
Sn1per finds, ranks, and exploits real vulnerabilities autonomously — the same way attackers do.