Daniel
38 exploits
Active since Aug 2019
YouPHPTube < 7.2 - SQL Injection in AuditTable.php
CVSS 5.3
YouPHPTube < 7.4 - Unauthenticated Arbitrary File Write via checkConfiguration.php
CVSS 9.8
SiYuan < 3.5.4 - Arbitrary File Read via Markdown HTML Rendering
CVSS 7.5
SiYuan < 3.5.4 - Arbitrary File Read via Markdown HTML Rendering
CVSS 7.5
SiYuan < 3.5.4 - Authenticated Path Traversal via Global Copy Files Endpoint
CVSS 6.5
SiYuan < 3.6.5 - Double-Encoded Path Traversal
SiYuan 3.6.1 to 3.6.3 - Bazaar README Stored Cross-Site Scripting
CVSS 5.4
SiYuan <3.6.2 appearance Filepath - Arbitrary File Read
CVSS 7.5
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
CVSS 9.0
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
CVSS 9.8
SiYuan <3.6.1 Desktop Publish Service - Arbitrary File Read
CVSS 9.9
SiYuan <3.6.1 getDynamicIcon - Cross-Site Scripting
CVSS 9.3
SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets
CVSS 6.8
SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
CVSS 7.6
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
CVSS 6.8
SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface
SiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure
IOBit Advanced SystemCare Free <13.5.0.263 - Privilege Escalation
CVSS 7.1
AVideo < 8.9 - Unauthenticated Local File Disclosure via Proxy Streaming
CVSS 7.5
WWBN AVideo < 11.6 - Cross-Site Scripting via yptDevice Parameter
CVSS 6.1
WWBN AVideo < 11.6 - Open Redirect via Login Endpoint
CVSS 6.1
AVideo < 12.4 - Cross-Site Scripting via User Success Parameter
CVSS 6.1
Tumult Hype Animations <1.9.15 - RCE
CVSS 9.9
SiYuan < 3.1.16 - Path Traversal via Template Render Endpoint
CVSS 7.5
SiYuan < 3.1.16 - Unauthenticated Arbitrary File Read via Path Traversal
CVSS 7.5