| 2015-05-05 | Android Native API Hooking with Library Injection and ELF Introspection | MD | 8726 | |
| 2015-05-05 | Forcing XXE Reflection through Server Error Messages | MD | 2556 | |
| 2015-05-04 | Fuzzing nginx - Hunting vulnerabilities with afl-fuzz | MD | 9800 | |
| 2015-05-04 | XSS via window.stop() - Google Safen Up | MD | 8698 | |
| 2015-05-04 | Dynamically inject a shared library into a running process on Android/ARM | MD | 2159 | |
| 2015-04-30 | Automated Data Exfiltration With XXE | MD | 7125 | |
| 2015-04-27 | Race conditions on Facebook, DigitalOcean and others (fixed) | MD | 2573 | |
| 2015-04-27 | WordPress 4.2 Stored XSS | MD | 3707 | |
| 2015-04-25 | WordPress < 4.1.2 Stored XSS vulnerability | MD | 2559 | |
| 2015-04-24 | Java Obfuscator - Lite | MD | 8291 | |
| 2015-04-23 | Analyzing the Magento Vulnerability | MD | 3406 | |
| 2015-04-23 | plupload - Same-Origin Method Execution [Wordpress 3.9 - 4.1.1] | MD | 8845 | |
| 2015-04-22 | CRLF injection on Twitter or why blacklists fail | MD | 2480 | |