XSS2Shell (CVE-2026-64638) is a pre-authentication reflected XSS on the WordPress login screen that escalates to PHP code execution against a logged-in administrator. A plain-English…
CVE-2026-42533 is a critical heap buffer overflow in the NGINX script engine reached through the map directive, with weaponized public exploit code that defeats…
CVE-2026-42945, known as NGINX Rift, is a critical heap buffer overflow in ngx_http_rewrite_module reachable from a single unauthenticated request, with exploitation reported in the…
CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a…
CVE-2026-50522 is a critical, actively-exploited unauthenticated RCE in on-prem Microsoft SharePoint Server (2016, 2019, Subscription Edition). A plain-English advisory, a ready-to-run non-destructive Nuclei detection…
wp2shell (CVE-2026-63030) is an unauthenticated pre-auth RCE in WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1. A plain-English advisory, a ready-to-run Nuclei detection template, remediation, and how…
Discover live hosts, open ports, services, and connected devices across your internal subnets with Sn1per Professional 2026 - a self-hosted, automated network and subnet…
Automated penetration testing, explained without the hype. What it is, automated vs manual (and why you need both), what automation can and cannot do,…
xer0dayz·9 min read
Try it free
See your attack surface like a pentester would.
Sn1per finds, ranks, and exploits real vulnerabilities autonomously — the same way attackers do.