- [webapps] Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass
- [dos] Windows TCP/IP - RCE Checker and Denial of Service
- [webapps] NoteMark < 0.13.0 - Stored XSS
- [webapps] Gitea 1.22.0 - Stored XSS
- [webapps] Invesalius3 - Remote Code Execution
- [webapps] reNgine 2.2.0 - Command Injection (Authenticated)
- [webapps] openSIS 9.1 - SQLi (Authenticated)
- [webapps] dizqueTV 1.5.3 - Remote Code Execution (RCE)
- [webapps] SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (R
- [webapps] Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
- [webapps] TeamPass 3.0.0.21 - SQL Injection
- [remote] Aztech DSL5005EN Router - 'sysAccess.asp' Admin Password Change (Unauthentic
- [remote] Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
- [webapps] Jasmin Ransomware - SQL Injection Login Bypass
- [webapps] FluxBB 1.5.11 - Stored Cross-Site Scripting (XSS)
- [webapps] JUX Real Estate 3.4.0 - SQL Injection
- [local] VeeVPN 1.6.1 - Unquoted Service Path
- [webapps] Gitea 1.24.0 - HTML Injection
- [webapps] TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)
- [webapps] Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution
- [webapps] Loaded Commerce 6.6 - Client-Side Template Injection(CSTI)
- [webapps] Sonatype Nexus Repository 3.53.0-01 - Path Traversal
- [webapps] CodeCanyon RISE CRM 3.7.0 - SQL Injection
- [webapps] Litespeed Cache 6.5.0.1 - Authentication Bypass
- [webapps] X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
- [webapps] KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
- [webapps] MoziloCMS 3.0 - Remote Code Execution (RCE)
- [local] NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
- [webapps] XWiki Standard 14.10 - Remote Code Execution (RCE)
- [local] Solstice Pod 6.2 - API Session Key Extraction via API Endpoint
- [webapps] Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypas
- [webapps] Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
- [webapps] Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary Fil
- [webapps] Exclusive Addons for Elementor 2.6.9 - Stored Cross-Site Scripting (XSS)
- [webapps] Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
- [webapps] Next.js Middleware 15.2.2 - Authorization Bypass
- [webapps] IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
- [remote] Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Inje
- [remote] Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
- [remote] Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stor
- [remote] Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injec
- [webapps] AppSmith 1.47 - Remote Code Execution (RCE)
- [webapps] Nagios Log Server 2024R1.3.1 - Stored XSS
- [local] ollama 0.6.4 - Server Side Request Forgery (SSRF)
- [webapps] ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)
- [webapps] Webmin Usermin 2.100 - Username Enumeration
- [remote] Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
- [webapps] ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
- [remote] Vite 6.2.2 - Arbitrary File Read
- [remote] SAP NetWeaver - 7.53 - HTTP Request Smuggling
- [webapps] ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
- [webapps] ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
- [webapps] Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
- [webapps] DocsGPT 0.12.0 - Remote Code Execution
- [webapps] GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
- [remote] Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE
- [remote] InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
- [webapps] jQuery 3.3.1 - Prototype Pollution & XSS Exploit
- [webapps] Jasmin Ransomware - Arbitrary File Download (Authenticated)
- [webapps] UNA CMS 14.0.0-RC - PHP Object Injection
- [webapps] Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
- [webapps] WordPress User Registration & Membership Plugin 4.1.1 - Unauthenticated Pri
- [webapps] XWiki Platform 15.10.10 - Remote Code Execution
- [webapps] YesWiki 4.5.1 - Unauthenticated Path Traversal
- [webapps] Apache Tomcat 11.0.3 - Remote Code Execution
- [webapps] Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
- [webapps] WBCE CMS 1.6.3 - Authenticated Remote Code Execution (RCE)
- [webapps] Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary F
- [webapps] Watcharr 1.43.0 - Remote Code Execution (RCE)
- [webapps] Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
- [webapps] DataEase 2.4.0 - Database Configuration Information Exposure
- [webapps] phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
- [webapps] MiniCMS 1.1 - Cross Site Scripting (XSS)
- [webapps] NEWS-BUZZ News Management System 1.0 - SQL Injection
- [webapps] Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
- [webapps] CyberPanel 2.3.6 - Remote Code Execution (RCE)
- [webapps] LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
- [webapps] MagnusSolution magnusbilling 7.3.0 - Command Injection
- [webapps] RosarioSIS 7.6 - SQL Injection
- [webapps] GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
- [webapps] Gnuboard5 5.3.2.8 - SQL Injection
- [webapps] flatCore 1.5 - Cross Site Request Forgery (CSRF)
- [webapps] flatCore 1.5.5 - Arbitrary File Upload
- [webapps] AquilaCMS 1.409.20 - Remote Command Execution (RCE)
- [webapps] Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
- [webapps] Typecho 1.3.0 - Race Condition
- [hardware] Cosy+ firmware 21.2s7 - Command Injection
- [webapps] CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS
- [remote] K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
- [webapps] PandoraFMS 7.0NG.772 - SQL Injection
- [webapps] Centron 19.04 - Remote Code Execution (RCE)
- [webapps] Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
- [webapps] Feng Office 3.11.1.2 - SQL Injection
- [webapps] PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CS
- [webapps] ChurchCRM 5.9.1 - SQL Injection
- [webapps] Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RC
- [webapps] ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
- [webapps] Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
- [webapps] Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
- [webapps] Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
- [webapps] Artica Proxy 4.50 - Remote Code Execution (RCE)
- [local] qBittorrent 5.0.1 - MITM RCE
- [webapps] GeoVision GV-ASManager 6.1.0.0 - Broken Access Control
- [hardware] ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
- [webapps] GeoVision GV-ASManager 6.1.1.0 - CSRF
- [hardware] ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
- [webapps] WebFileSys 2.31.0 - Directory Path Traversal
- [hardware] ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning
- [hardware] Netman 204 - Remote command without authentication
- [hardware] ABB Cylon Aspect 3.08.02 - PHP Session Fixation
- [webapps] CMU CERT/CC VINCE 2.0.6 - Stored XSS
- [hardware] ABB Cylon FLXeon 9.3.4 - Cross-Site Request Forgery
- [hardware] ABB Cylon FLXeon 9.3.4 - Default Credentials
- [hardware] ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
- [webapps] Nagios Log Server 2024R1.3.1 - API Key Exposure
- [webapps] OpenPanel 0.3.4 - OS Command Injection
- [webapps] OpenPanel 0.3.4 - Incorrect Access Control
- [webapps] OpenPanel 0.3.4 - Directory Traversal
- [webapps] Pimcore 11.4.2 - Stored cross site scripting
- [webapps] Pimcore customer-data-framework 4.2.0 - SQL injection
- [webapps] Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
- [hardware] ZTE ZXHN H168N 3.1 - Remote Code Execution (RCE) via authentication bypass
- [remote] GestioIP 3.5.7 - Remote Command Execution (RCE)
- [remote] GestioIP 3.5.7 - Cross-Site Scripting (XSS)
- [remote] GestioIP 3.5.7 - Reflected Cross-Site Scripting (Reflected XSS)
- [remote] GestioIP 3.5.7 - Stored Cross-Site Scripting (Stored XSS)
- [remote] GestioIP 3.5.7 - Cross-Site Request Forgery (CSRF)
- [webapps] SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated)
- [webapps] OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Tra
- [webapps] Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
- [hardware] ABB Cylon Aspect 3.08.02 - Cookie User Password Disclosure
- [webapps] ABB Cylon Aspect 3.08.03 - Hard-coded Secrets
- [webapps] ABB Cylon Aspect 3.08.03 (MapServicesHandler) - Authenticated Reflected XSS
- [hardware] ABB Cylon Aspect 3.07.02 (userManagement.php) - Weak Password Policy
- [hardware] ABB Cylon Aspect 3.08.03 (CookieDB) - SQL Injection
- [hardware] ABB Cylon Aspect 3.08.02 (webServerUpdate.php) - Input Validation Config P
- [hardware] ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) - Denial of Service (DOS)
- [hardware] ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
- [hardware] ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
- [hardware] ABB Cylon Aspect 3.08.02 (licenseUpload.php) - Stored Cross-Site Scripting
- [hardware] ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) - Stored Cross-Site Scr
- [remote] Ivanti Connect Secure 22.7R2.5 - Remote Code Execution (RCE)
- [webapps] IBMi Navigator 7.5 - Server Side Request Forgery (SSRF)
- [webapps] Plane 0.23.1 - Server side request forgery (SSRF)
- [webapps] IBMi Navigator 7.5 - HTTP Security Token Bypass
- [webapps] OpenCMS 17.0 - Stored Cross Site Scripting (XSS)
- [webapps] Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE)
- [webapps] Really Simple Security 9.1.1.1 - Authentication Bypass
- [webapps] Spring Boot common-user-management 0.1 - Remote Code Execution (RCE)
- [remote] Pymatgen 2024.1 - Remote Code Execution (RCE)
- [webapps] FoxCMS 1.2.5 - Remote Code Execution (RCE)
- [webapps] Drupal 11.x-dev - Full Path Disclosure
- [webapps] KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated S
- [webapps] UJCMS 9.6.3 - User Enumeration via IDOR
- [webapps] Inventio Lite 4 - SQL Injection
- [remote] Langflow 1.3.0 - Remote Code Execution (RCE)
- [webapps] Apache Commons Text 1.10.0 - Remote Code Execution
- [webapps] Tatsu 3.3.11 - Unauthenticated RCE
- [webapps] Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation
- [local] AnyDesk 9.0.1 - Unquoted Service Path
- [webapps] compop.ca 3.5.3 - Arbitrary code Execution
- [webapps] Blood Bank & Donor Management System 2.4 - CSRF Improper Input Validation
- [webapps] Usermin 2.100 - Username Enumeration
- [webapps] Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Executio
- [hardware] ABB Cylon Aspect 3.08.02 (ethernetUpdate.php) - Authenticated Path Traver
- [hardware] ABB Cylon Aspect 3.08.02 (deployStart.php) - Unauthenticated Command Execu
- [remote] TP-Link VN020 F3v(T) TT_V6.2.1021 - Denial Of Service (DOS)
- [remote] TP-Link VN020 F3v(T) TT_V6.2.1021 - Buffer Overflow Memory Corruption
- [webapps] WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection
- [webapps] Smart Manager 8.27.0 - Post-Authenticated SQL Injection
- [remote] Dell EMC iDRAC7/iDRAC8 2.52.52.52 - Remote Code Execution (RCE)
- [webapps] KodExplorer 4.52 - Open Redirect
- [local] ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE)
- [webapps] Car Rental Project 1.0 - Remote Code Execution
- [local] Ruckus IoT Controller 1.7.1.0 - Undocumented Backdoor Account
- [webapps] Ethercreative Logs 3.0.3 - Path Traversal
- [webapps] FLIR AX8 1.46.16 - Remote Command Injection
- [remote] Fortinet FortiOS, FortiProxy, and FortiSwitchManager 7.2.0 - Authentication
- [webapps] Garage Management System 1.0 (categoriesName) - Stored XSS
- [remote] WebMethods Integration Server 10.15.0.0000-0092 - Improper Access on Login P
- [webapps] ProConf 6.0 - Insecure Direct Object Reference (IDOR)
- [webapps] phpMyFAQ 3.2.10 - Unintended File Download Triggered by Embedded Frames
- [hardware] ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) - File Write Do
- [hardware] ABB Cylon Aspect 4.00.00 (factorySaved.php) - Unauthenticated XSS
- [hardware] ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution
- [hardware] ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF)
- [webapps] Zabbix 7.0.0 - SQL Injection
- [webapps] NagVis 1.9.33 - Arbitrary File Read
- [webapps] Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
- [remote] Hugging Face Transformers MobileViTV2 4.41.1 - Remote Code Execution (RCE)
- [webapps] phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
- [local] Microsoft Windows 11 - Kernel Privilege Escalation
- [webapps] WordPress Core 6.2 - Directory Traversal
- [remote] Firefox ESR 115.11 - PDF.js Arbitrary JavaScript execution
- [remote] code-projects Online Exam Mastering System 1.0 - Reflected Cross-Site Script
- [remote] WonderCMS 3.4.2 - Remote Code Execution (RCE)
- [local] Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege
- [remote] OpenSSH server (sshd) 9.8p1 - Race Condition
- [local] tar-fs 3.0.0 - Arbitrary File Write/Overwrite
- [local] unzip-stream 0.3.1 - Arbitrary File Write
- [local] Microsoft - NTLM Hash Disclosure Spoofing (library-ms)
- [local] ZTE ZXV10 H201L - RCE via authentication bypass
- [local] Daikin Security Gateway 14 - Remote Password Reset
- [local] Microsoft Windows - XRM-MS File NTLM Information Disclosure Spoofing
- [webapps] ERPNext 14.82.1 - Account Takeover via Cross-Site Request Forgery (CSRF)
- [webapps] Grokability Snipe-IT 8.0.4 - Insecure Direct Object Reference (IDOR)
- [webapps] Casdoor 1.901.0 - Cross-Site Request Forgery (CSRF)
- [remote] Apache ActiveMQ 6.1.6 - Denial of Service (DOS)
- [local] VirtualBox 7.0.16 - Privilege Escalation
- [webapps] SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation
- [webapps] WordPress Depicter Plugin 3.6.1 - SQL Injection
- [local] Microsoft Windows 11 Pro 23H2 - Ancillary Function Driver for WinSock Privile
- [local] TP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer Overflow
- [webapps] WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege E
- [webapps] Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
- [local] RDPGuard 9.9.9 - Privilege Escalation
- [remote] CrushFTP 11.3.1 - Authentication Bypass
- [remote] Invision Community 5.0.6 - Remote Code Execution (RCE)
- [local] Zyxel USG FLEX H series uOS 1.31 - Privilege Escalation
- [remote] Remote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)
- [local] ABB Cylon Aspect Studio 3.08.03 - Binary Planting
- [remote] ABB Cylon Aspect 3.08.03 - Guest2Root Privilege Escalation
- [webapps] Java-springboot-codebase 1.1 - Arbitrary File Read
- [remote] Grandstream GSD3710 1.0.11.13 - Stack Buffer Overflow
- [webapps] WordPress User Registration & Membership Plugin 4.1.2 - Authentication Bypa
- [local] Microsoft Windows Server 2016 - Win32k Elevation of Privilege
- [remote] Windows 2024.15 - Unauthenticated Desktop Screenshot Capture
- [webapps] Campcodes Online Hospital Management System 1.0 - SQL Injection
- [remote] SolarWinds Serv-U 15.4.2 HF1 - Directory Traversal
- [remote] Windows File Explorer Windows 11 (23H2) - NTLM Hash Disclosure
- [remote] Automic Agent 24.3.0 HF4 - Privilege Escalation
- [remote] Fortra GoAnywhere MFT 7.4.1 - Authentication Bypass
- [webapps] WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcin
- [remote] Apache Tomcat 10.1.39 - Denial of Service (DoS)
- [remote] ABB Cylon Aspect 3.08.04 DeploySource - Remote Code Execution (RCE)
- [local] macOS LaunchDaemon iOS 17.2 - Privilege Escalation
- [remote] Microsoft Windows Server 2025 JScript Engine - Remote Code Execution (RCE)
- [webapps] CloudClassroom PHP Project 1.0 - SQL Injection
- [remote] Grandstream GSD3710 1.0.11.13 - Stack Overflow
- [local] TightVNC 2.8.83 - Control Pipe Manipulation
- [remote] ProSSHD 1.2 20090726 - Denial of Service (DoS)
- [local] Microsoft Windows 11 Version 24H2 Cross Device Service - Elevation of Privile
- [webapps] Laravel Pulse 1.3.1 - Arbitrary Code Injection
- [remote] WebDAV Windows 10 - Remote Code Execution (RCE)
- [remote] AirKeyboard iOS App 1.0.5 - Remote Input Injection
- [local] Microsoft Excel Use After Free - Local Code Execution
- [webapps] PHP CGI Module 8.3.4 - Remote Code Execution (RCE)
- [remote] Windows 11 SMB Client - Privilege Escalation & Remote Code Execution (RCE)
- [local] Parrot and DJI variants Drone OSes - Kernel Panic Exploit
- [webapps] Litespeed Cache WordPress Plugin 6.3.0.1 - Privilege Escalation