- [webapps] Litespeed Cache WordPress Plugin 6.3.0.1 - Privilege Escalation
- [webapps] Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
- [remote] PCMan FTP Server 2.0.7 - Buffer Overflow
- [remote] Windows File Explorer Windows 10 Pro x64 - TAR Extraction
- [webapps] Roundcube 1.6.10 - Remote Code Execution (RCE)
- [remote] Freefloat FTP Server 1.0 - Remote Buffer Overflow
- [remote] Ingress-NGINX 4.11.0 - Remote Code Execution (RCE)
- [local] Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)
- [remote] FortiOS SSL-VPN 7.4.4 - Insufficient Session Expiration & Cookie Reuse
- [remote] Microsoft Excel 2024 Use after free - Remote Code Execution (RCE)
- [remote] freeSSHd 1.0.9 - Denial of Service (DoS)
- [webapps] Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
- [remote] OneTrust SDK 6.33.0 - Denial Of Service (DoS)
- [remote] PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
- [webapps] Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE)
- [remote] McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
- [webapps] Sitecore 10.4 - Remote Code Execution (RCE)
- [webapps] Moodle 4.4.0 - Authenticated Remote Code Execution
- [remote] Microsoft SharePoint 2019 - NTLM Authentication
- [remote] gogs 0.13.0 - Remote Code Execution (RCE)
- [remote] Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
- [webapps] Discourse 3.2.x - Anonymous Cache Poisoning
- [webapps] Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeove
- [remote] Microsoft Outlook - Remote Code Execution (RCE)
- [local] Microsoft Defender for Endpoint (MDE) - Elevation of Privilege
- [local] Sudo 1.9.17 Host Option - Elevation of Privilege
- [remote] ScriptCase 9.12.006 (23) - Remote Command Execution (RCE)
- [local] Sudo chroot 1.9.17 - Local Privilege Escalation
- [remote] Microsoft PowerPoint 2019 - Remote Code Execution (RCE)
- [remote] NodeJS 24.x - Path Traversal
- [webapps] WP Publications WordPress Plugin 1.2 - Stored XSS
- [webapps] White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)
- [remote] MikroTik RouterOS 7.19.1 - Reflected XSS
- [webapps] SugarCRM 14.0.0 - SSRF/Code Injection
- [webapps] Langflow 1.2.x - Remote Code Execution (RCE)
- [hardware] TOTOLINK N300RB 8.54 - Command Execution
- [local] Microsoft Graphics Component Windows 11 Pro (Build 26100+) - Local Elevation
- [webapps] PivotX 3.0.0 RC3 - Remote Code Execution (RCE)
- [local] Microsoft Brokering File System Windows 11 Version 22H2 - Elevation of Privil
- [remote] Keras 2.15 - Remote Code Execution (RCE)
- [webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned
- [webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integr
- [webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surnam
- [webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Us
- [webapps] Discourse 3.1.1 - Unauthenticated Chat Message Access
- [remote] Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow
- [webapps] Joomla JS Jobs plugin 1.4.2 - SQL injection
- [remote] Microsoft Edge Windows 10 Version 1511 - Cross Site Scripting (XSS)
- [webapps] Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
- [webapps] Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE
- [webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assi
- [webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transf
- [local] Microsoft Virtual Hard Disk (VHDX) 11 - Remote Code Execution (RCE)
- [webapps] Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation
- [remote] Swagger UI 1.0.3 - Cross-Site Scripting (XSS)
- [webapps] LPAR2RRD 8.04 - Remote Code Execution (RCE)
- [webapps] Copyparty 1.18.6 - Reflected Cross-Site Scripting (XSS)
- [remote] Microsoft Edge (Chromium-based) 135.0.7049.114/.115 - Information Disclosure
- [webapps] Gandia Integra Total 4.4.2236.1 - SQL Injection
- [webapps] Adobe ColdFusion 2023.6 - Remote File Read
- [local] Linux PAM Environment - Variable Injection Local Privilege Escalation
- [webapps] Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)
- [webapps] XWiki 14 - SQL Injection via getdeleteddocuments.vm
- [webapps] Invision Community 4.7.20 - (calendar/view.php) SQL Injection
- [dos] Xlight FTP 1.1 - Denial Of Service (DOS)
- [webapps] JetBrains TeamCity 2023.11.4 - Authentication Bypass
- [webapps] ServiceNow Multiple Versions - Input Validation & Template Injection
- [webapps] Ghost CMS 5.59.1 - Arbitrary File Read
- [webapps] Ghost CMS 5.42.1 - Path Traversal
- [remote] Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
- [webapps] VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
- [remote] Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution
- [remote] Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
- [webapps] Microsoft Edge Renderer Process (Mojo IPC) 134.0.6998.177 - Sandbox Escape
- [webapps] Grav CMS 1.7.48 - Remote Code Execution (RCE)
- [remote] Citrix NetScaler ADC/Gateway 14.1 - Memory Disclosure
- [webapps] atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)
- [local] Microsoft Windows - Storage QoS Filter Driver Checker
- [webapps] projectworlds Online Admission System 1.0 - SQL Injection
- [remote] Cisco ISE 3.0 - Authorization Bypass
- [remote] Cisco ISE 3.0 - Remote Code Execution (RCE)
- [remote] Tenda AC20 16.03.08.12 - Command Injection
- [webapps] Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
- [webapps] Soosyze CMS 2.0 - Brute Force Login
- [remote] Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure
- [remote] PHPMyAdmin 3.0 - Bruteforce Login Bypass
- [webapps] RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
- [webapps] BigAnt Office Messenger 5.6.06 - SQL Injection
- [remote] GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE
- [local] GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
- [webapps] StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
- [remote] Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
- [webapps] Lingdang CRM 8.6.4.7 - SQL Injection
- [webapps] Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
- [remote] windows 10/11 - NTLM Hash Disclosure Spoofing
- [remote] Redis 8.0.2 - RCE
- [webapps] OctoPrint 1.11.2 - File Upload
- [remote] Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE
- [webapps] aiohttp 3.9.1 - directory traversal PoC
- [webapps] FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution
- [local] Docker Desktop 4.44.3 - Unauthenticated API Exposure
- [webapps] Piranha CMS 12.0 - Stored XSS in Text Block
- [webapps] RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS)
- [hardware] D-Link DIR-825 Rev.B 2.10 - Stack Buffer Overflow (DoS)
- [webapps] RPi-Jukebox-RFID 2.8.0 - Remote Command Execution
- [webapps] Siklu EtherHaul Series EH-8010 - Arbitrary File Upload
- [webapps] Siklu EtherHaul Series EH-8010 - Remote Command Execution
- [webapps] WordPress Quiz Maker 6.7.0.56 - SQL Injection
- [webapps] Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via
- [webapps] FreeBSD rtsold 15.x - Remote Code Execution via DNSSL
- [webapps] Summar Employee Portal 3.98.0 - Authenticated SQL Injection
- [webapps] esm-dev 136 - Path Traversal
- [webapps] Pluck 4.7.7-dev2 - PHP Code Execution
- [webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)
- [webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF)
- [webapps] MaNGOSWebV4 4.0.6 - Reflected XSS
- [webapps] Django 5.1.13 - SQL Injection
- [webapps] phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)
- [webapps] MobileDetect 2.8.31 - Cross-Site Scripting (XSS)
- [webapps] phpIPAM 1.4 - SQL-Injection
- [webapps] OpenRepeater 2.1 - OS Command Injection
- [webapps] phpMyAdmin 5.0.0 - SQL Injection
- [webapps] RosarioSIS 6.7.2 - Cross Site Scripting (XSS)
- [webapps] RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)
- [webapps] PluckCMS 4.7.10 - Unrestricted File Upload
- [webapps] openSIS Community Edition 8.0 - SQL Injection
- [webapps] YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
- [webapps] phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
- [webapps] phpIPAM 1.5.1 - SQL Injection
- [webapps] Piwigo 13.6.0 - SQL Injection
- [webapps] phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
- [webapps] phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)
- [webapps] Flowise 3.0.4 - Remote Code Execution (RCE)
- [webapps] Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)
- [remote] Ilevia EVE X1/X5 Server 4.7.18.0.eden - Reverse Rootshell
- [local] Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP - Elevation o
- [remote] ClipBucket 5.5.0 - Arbitrary File Upload
- [remote] ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)
- [webapps] Tourism Management System 2.0 - Arbitrary Shell Upload
- [webapps] Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
- [webapps] dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
- [webapps] ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
- [webapps] XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
- [webapps] Concrete CMS 9.4.3 - Stored XSS
- [webapps] motionEye 0.43.1b4 - RCE
- [remote] Windows 10.0.17763.7009 - spoofing vulnerability
- [local] glibc 2.38 - Buffer Overflow