Langflow 1.2.x – Remote Code Execution (RCE)

#!/usr/bin/env python3 # Exploit Title: Langflow 1.2.x – Remote Code Execution (RCE) # Date: 2025-07-11 # Exploit Author: Raghad Abdallah Al-syouf # Vendor Homepage: https://github.com/logspace-ai/langflow # Software Link: https://github.com/logspace-ai/langflow/releases # Version: <= 1.2.x # Tested on: Ubuntu / Docker # CVE: CVE-2025-3248 # Description: #Langflow exposes a vulnerable endpoint `/api/v1/validate/code` that improperly evaluates arbitrary…

Read More

Microsoft Graphics Component Windows 11 Pro (Build 26100+) – Local Elevation of Privileges

**Exploit Title : Microsoft Graphics Component Windows 11 Pro (Build 26100+) – Local Elevation of Privileges **Author:** nu11secur1ty **Date:** 07/11/2025 — ## Overview This repository contains a PowerShell script to **validate whether a Windows 11 system is vulnerable to CVE-2025-49744**—a critical local privilege escalation vulnerability involving the `gdi32.dll` and `win32kfull.sys` system components. …

Read More

Keras 2.15 – Remote Code Execution (RCE)

#!/usr/bin/env python3 # Exploit Title: Keras 2.15 – Remote Code Execution (RCE) # Author: Mohammed Idrees Banyamer # Instagram: @banyamer_security # GitHub: https://github.com/mbanyamer # Date: 2025-07-09 # Tested on: Ubuntu 22.04 LTS, Python 3.10, TensorFlow/Keras <= 2.15 # CVE: CVE-2025-1550 # Type: Remote Code Execution (RCE) # Platform: Python / Machine Learning (Keras) # Author…

Read More

Fiji ant plant builds tiny condos that stop ant wars

Odd plants from a remote Pacific island reveal new insights into an important ecological question: how unrelated and antagonistic partners can form long-term mutualistic relationships with the same host. Scientists studying ant plants in Fiji have discovered one way that a host plant can keep the peace among residents that might otherwise kill each other….

Read More