user@siberalem:~$ cat manifesto.txt
> Information wants to be free.
> We exist in the spaces between the lines of code.
> This archive is a testament to the eternal cat-and-mouse game.
MyBB <= 1.4.6 Remote Code Execution Exploit
By Autopilot
2009-06-22 00:00:00
| DATE | DESCRIPTION | PLATFORM | HITS | AUTHOR |
|---|---|---|---|---|
| 2026-06-18 |
CVE-2026-25865 - Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec
ID: 207
Verified
|
161 |
|
|
| 2026-06-18 |
CVE-2026-48983 - pam_usb: TOCTOU race condition in pad directory creation allows symlink substitution
ID: 211
Verified
|
215 |
|
|
| 2026-06-18 |
CVE-2026-48982 - pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race
ID: 212
Verified
|
241 |
|
|
| 2026-06-18 |
CVE-2026-48981 - pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c
ID: 213
Verified
|
121 |
|
|
| 2026-06-18 |
CVE-2026-2842
ID: 214
Verified
|
140 |
|
|
| 2026-06-18 |
CVE-2026-47846 - Bitnami Cassandra Default Superuser Vulnerability
ID: 216
Verified
|
188 |
|
|
| 2026-06-18 |
CVE-2026-47847 - Bitnami MariaDB Galera: Hardcoded Credentials
ID: 217
Verified
|
228 |
|
| DATE | DESCRIPTION | PLATFORM | HITS | AUTHOR |
|---|---|---|---|---|
| 2026-06-18 |
CVE-2026-56099 - OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input
ID: 209
Verified
|
OpenBSD | 190 |
|
| 2026-06-18 |
CVE-2026-48980 - pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
ID: 210
Verified
|
128 |
|
|
| 2026-06-18 |
CVE-2026-47833 - BPM: Container-to-Host Privilege Escalation via Symlink Following
ID: 219
Verified
|
212 |
|
|
| 2026-06-18 |
CVE-2026-48985 - pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote Field
ID: 122
Verified
|
Generic | 83 |
|
| 2026-06-18 |
CVE-2026-54104 - U.S. GAO EPDS and CBCA EDS client-based privilege escalation
ID: 135
Verified
|
Generic | 85 |
|
| DATE | DESCRIPTION | PLATFORM | HITS | AUTHOR |
|---|---|---|---|---|
| 2026-06-18 |
CVE-2026-43915 - Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username
ID: 208
Verified
|
66 |
|
|
| 2026-06-18 |
CVE-2026-48716 - nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file write
ID: 215
Verified
|
108 |
|
|
| 2026-06-18 |
CVE-2026-48937 - Node.js HTTP/2 Denial of Service
ID: 220
Verified
|
Node.js | 206 |
|
| 2026-06-18 |
CVE-2026-48986 - pam_usb: Infinite loop DoS in process-tree walk when parent process exits during authentication
ID: 123
Verified
|
Generic | 152 |
|
| 2026-06-18 |
CVE-2026-11982 - Stored XSS via missing XSS safety check in Admin2 Pages API partial validation
ID: 127
Verified
|
Generic | 232 |
|
| 2026-06-18 |
CVE-2026-55237 - AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
ID: 128
Verified
|
Generic | 73 |
|
| 2026-06-18 |
CVE-2025-32424 - AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock
ID: 132
Verified
|
Generic | 178 |
|
| DATE | DESCRIPTION | PLATFORM | HITS | AUTHOR |
|---|---|---|---|---|
| 2026-06-18 |
CVE-2025-32437 - AutoGPT has a DoS vulnerability in MediaDurationBlock
ID: 130
Verified
|
Generic | 139 |
|
| 2026-06-18 |
CVE-2025-32436 - AutoGPT has a DoS vulnerability in AddAudioToVideoBlock
ID: 131
Verified
|
Generic | 76 |
|
| 2026-06-18 |
CVE-2025-32422 - AutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlock
ID: 136
Verified
|
Generic | 72 |
|
| 2026-06-18 |
CVE-2025-32392 - AutoGPT has a DoS vulnerability in LoopVideoBlock
ID: 141
Verified
|
Generic | 172 |
|