multiple

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers/漏洞数据库

日期 标题 类别 作者
2025-04-05 IBM Security Verify Access 10.0.0 – Open Redirect during OAuth Flow
  • webapps
  • Giulio Garzia
    2025-04-05 Royal Elementor Addons and Templates 1.3.78 – Unauthenticated Arbitrary File Upload
  • webapps
  • 4m3rr0r
    2025-04-05 Exclusive Addons for Elementor 2.6.9 – Stored Cross-Site Scripting (XSS)
  • webapps
  • Al Baradi Joy
    2025-04-05 Kubio AI Page Builder 2.5.1 – Local File Inclusion (LFI)
  • webapps
  • 4m3rr0r
    2025-04-05 Next.js Middleware 15.2.2 – Authorization Bypass
  • webapps
  • kOaDT
    2025-04-04 Angular-Base64-Upload Library 0.1.20 – Remote Code Execution (RCE)
  • remote
  • Ravindu Wickramasinghe
    2025-04-03 ABB Cylon Aspect 3.07.02 – File Disclosure
  • webapps
  • LiquidWorm
    2025-04-03 Nagios Log Server 2024R1.3.1 – Stored XSS
  • webapps
  • Seth Kraft
    2025-04-03 ollama 0.6.4 – Server Side Request Forgery (SSRF)
  • local
  • sud0
    2025-04-03 Vite 6.2.2 – Arbitrary File Read
  • remote
  • 4m3rr0r
    2025-04-02 SAP NetWeaver – 7.53 – HTTP Request Smuggling
  • remote
  • C41Tx90
    2025-04-02 ABB Cylon Aspect 3.08.01 – Remote Code Execution (RCE)
  • webapps
  • LiquidWorm
    2025-03-28 Progress Telerik Report Server 2024 Q1 (10.0.24.305) – Authentication Bypass
  • webapps
  • VeryLazyTech
    2025-03-28 Sonatype Nexus Repository 3.53.0-01 – Path Traversal
  • webapps
  • VeryLazyTech
    2025-03-27 KubeSphere 3.4.0 – Insecure Direct Object Reference (IDOR)
  • webapps
  • Okan Kurtulus
    2025-03-19 Gitea 1.24.0 – HTML Injection
  • webapps
  • Mikail KOCADAĞ
    2024-10-01 reNgine 2.2.0 – Command Injection (Authenticated)
  • webapps
  • Caner Tercan
    2024-08-28 NoteMark < 0.13.0 - Stored XSS
  • webapps
  • Alessio Romano (sfoffo)
    2024-08-28 Gitea 1.22.0 – Stored XSS
  • webapps
  • Catalin Iovita, Alexandru Postolache
    2024-08-23 Calibre-web 0.6.21 – Stored XSS
  • webapps
  • Catalin Iovita, Alexandru Postolache
    2024-08-04 Ivanti vADC 9.9 – Authentication Bypass
  • webapps
  • ohnoisploited
    2024-06-26 SolarWinds Platform 2024.1 SR1 – Race Condition
  • webapps
  • Elhussain Fathy
    2024-06-03 Sitefinity 15.0 – Cross-Site Scripting (XSS)
  • webapps
  • Aldi Saputra Wahyudi
    2024-05-31 changedetection < 0.45.20 - Remote Code Execution (RCE)
  • webapps
  • Zach Crosman (zcrosman)