webapps

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers/漏洞数据库

日期 标题 类别 作者
2025-07-08 Stacks Mobile App Builder 5.2.3 – Authentication Bypass via Account Takeover
  • webapps
  • stealthcopter
    2025-07-02 Moodle 4.4.0 – Authenticated Remote Code Execution
  • webapps
  • Likhith Appalaneni
    2025-06-26 Social Warfare WordPress Plugin 3.5.2 – Remote Code Execution (RCE)
  • webapps
  • Huseyin Mardinli
    2025-06-26 Sitecore 10.4 – Remote Code Execution (RCE)
  • webapps
  • Yesith Alvarez
    2025-06-26 Pterodactyl Panel 1.11.11 – Remote Code Execution (RCE)
  • webapps
  • Zen-kun04
    2025-06-15 Skyvern 0.1.85 – Remote Code Execution (RCE) via SSTI
  • webapps
  • Cristian Branet
    2025-06-15 PHP CGI Module 8.3.4 – Remote Code Execution (RCE)
  • webapps
  • İbrahimsql
    2025-06-15 Litespeed Cache WordPress Plugin 6.3.0.1 – Privilege Escalation
  • webapps
  • Milad karimi
    2025-06-15 Anchor CMS 0.12.7 – Stored Cross Site Scripting (XSS)
  • webapps
  • /bin/neko
    2025-06-13 Roundcube 1.6.10 – Remote Code Execution (RCE)
  • webapps
  • Maksim Rogov
    2025-06-09 Laravel Pulse 1.3.1 – Arbitrary Code Injection
  • webapps
  • Mohammed Idrees Banyamer
    2025-06-05 CloudClassroom PHP Project 1.0 – SQL Injection
  • webapps
  • Sanjay Singh
    2025-05-29 Campcodes Online Hospital Management System 1.0 – SQL Injection
  • webapps
  • Carine Constantino
    2025-05-29 WordPress Digits Plugin 8.4.6.1 – Authentication Bypass via OTP Bruteforcing
  • webapps
  • Saleh Tarawneh
    2025-05-25 Java-springboot-codebase 1.1 – Arbitrary File Read
  • webapps
  • d3sca
    2025-05-25 WordPress User Registration & Membership Plugin 4.1.2 – Authentication Bypass
  • webapps
  • Mohammed Idrees Banyamer
    2025-05-13 Kentico Xperience 13.0.178 – Cross Site Scripting (XSS)
  • webapps
  • Alex Messham
    2025-05-13 WordPress Frontend Login and Registration Blocks Plugin 1.0.7 – Privilege Escalation
  • webapps
  • Md Shoriful Islam
    2025-05-09 SureTriggers OttoKit Plugin 1.0.82 – Privilege Escalation
  • webapps
  • Abdualhadi khalifa
    2025-05-09 WordPress Depicter Plugin 3.6.1 – SQL Injection
  • webapps
  • Andrew Long
    2025-05-06 ERPNext 14.82.1 – Account Takeover via Cross-Site Request Forgery (CSRF)
  • webapps
  • Ahmed Thaiban
    2025-05-06 Grokability Snipe-IT 8.0.4 – Insecure Direct Object Reference (IDOR)
  • webapps
  • Sn1p3r-H4ck3r
    2025-05-06 Casdoor 1.901.0 – Cross-Site Request Forgery (CSRF)
  • webapps
  • Van Lam Nguyen
    2025-04-22 WordPress Core 6.2 – Directory Traversal
  • webapps
  • Milad karimi