GeoVision GV-ASManager 6.1.0.0 – Broken Access Control
# Exploit Title: Broken Access Control in GeoVision GV-ASManager
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Broken Access Control in GeoVision GV-ASManager
# Exploit Title: ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
# Exploit Title: GeoVision GV-ASManager 6.1.1.0 - CSRF
# Exploit title: ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
# Exploit Title: Netman 204 - Remote command with out authentication
# Exploit title: ABB Cylon Aspect 3.08.02 PHP Session Fixation Vulnerability
# Exploit Tile: CMU CERT/CC VINCE 2.0.6 - Stored XSS
# Exploit Title: WebFileSys 2.31.0 - Directory Path Traversal in relPath Parameter
# ABB Cylon FLXeon 9.3.4 (wsConnect.js) WebSocket Command Spawning PoC
# Exploit title: ABB Cylon FLXeon 9.3.4 Limited Cross-Site Request Forgery
ABB Cylon FLXeon 9.3.4 Default Credentials
# Exploit Tiltle: ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
# Exploit Title: Nagios Log Server 2024R1.3.1 - API Key Exposure
# Exploit Title: CyberPanel 2.3.6 - Remote Code Execution (RCE)
# Exploit Title: MagnusSolution magnusbilling 7.3.0 - Command Injection
# Exploit Title: Cosy+ firmware 21.2s7 - Command Injection
# Exploit Title: K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
# Exploit Title: Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
# Exploit Title: ManageEngine ADManager Plus Build < 7210 Elevation of
# Exploit Title: Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
# Exploit Title: Information Disclosure in GeoVision GV-ASManager
# Exploit Title: Sony XAV-AX5500 Firmware Update Validation Remote Code Execution
# Exploit Title: InfluxDB OSS Operator Privilege Escalation via BusinessLogic Flaw
# Exploit Title: jQuery Prototype Pollution & XSS Exploit (CVE-2019-11358 & CVE-2020-7656)
# Exploit Title: Jasmin Ransomware - (Authenticated) Arbitrary File Download
# Exploit Title: UNA CMS
# Exploit Title: Nagiosxi authenticated Remote Code Execution
# Exploit Title: WordPress User Registration & Membership Plugin
# Exploit Title: XWiki Platform - Remote Code Execution
# Exploit Title: YesWiki < 4.5.2 - Unauthenticated Path Traversal
# Exploit Title: Apache Tomcat Path Equivalence - Remote Code Execution
# Exploit Title: WBCE CMS
# Exploit Title : Watcharr 1.43.0 - Remote Code Execution (RCE)
# Exploit Title: Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
# Exploit Title: WordPress Plugin Royal Elementor Addons
# Exploit Title: Exclusive Addons for Elementor ≤ 2.6.9 - Authenticated Stored Cross-Site Scripting (XSS)
# Exploit Title: Kubio AI Page Builder
# Exploit Title: Next.js Middleware Bypass Vulnerability (CVE-2025-29927)
# Exploit Title : IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
# Exploit Title: Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
# Exploit Title: Stored XSS Vulnerability in Nagios Log Server (Privilege Escalation to Admin)
# Exploit Title: ollama 0.6.4 - SSRF
# Exploit Title: Vite Arbitrary File Read - CVE-2025-30208
# Exploit Title : ABB Cylon Aspect 3.07.02 - File Disclosure
# Exploit Title: SAPGateBreaker Exploit - CVE-2022-22536 - HTTP Request Smuggling Through SAP's Front Door
# Exploit Title : ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
# Exploit Title: Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
# Exploit Title: Sonatype Nexus Repository 3.53.0-01 - Path Traversal
# Exploit Title: KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
# Exploit Title: Gitea 1.24.0 - HTML Injection