Daniel
50 exploits
Active since Aug 2019
SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
CVSS 7.6
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
CVSS 6.8
SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface
CVSS 9.0
SiYuan: Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure
CVSS 7.5
IOBit Advanced SystemCare Free <13.5.0.263 - Privilege Escalation
CVSS 7.1
AVideo < 8.9 - Unauthenticated Local File Disclosure via Proxy Streaming
CVSS 7.5
WWBN AVideo < 11.6 - Cross-Site Scripting via yptDevice Parameter
CVSS 6.1
WWBN AVideo < 11.6 - Open Redirect via Login Endpoint
CVSS 6.1
AVideo < 12.4 - Cross-Site Scripting via User Success Parameter
CVSS 6.1
Tumult Hype Animations <1.9.15 - RCE
CVSS 9.9
SiYuan < 3.1.16 - Path Traversal via Template Render Endpoint
CVSS 7.5
SiYuan < 3.1.16 - Unauthenticated Arbitrary File Read via Path Traversal
CVSS 7.5
SiYuan < 3.1.16 - Unauthenticated Arbitrary File Write and Stored Cross-Site Scripting via Asset Upload Endpoint
CVSS 5.4
SiYuan < 3.1.16 - Server-Side Template Injection via Sprig Template Engine
CVSS 9.8
SiYuan Note <3.1.18 - File Deletion
CVSS 9.1
DNN - Info Disclosure
CVSS 4.2
DNN - Info Disclosure
CVSS 4.3
Dnnsoftware Dotnetnuke < 9.13.8 - SSRF
CVSS 6.5
DNN < 9.13.9 Site Export - SuperUser External URL Import
CVSS 3.5
SiYuan < 3.5.4 - Reflected Cross-Site Scripting via Dynamic Icon SVG Content Parameter
CVSS 6.1
SiYuan < 3.5.4 - Authenticated Path Traversal via Global Copy Files Endpoint
CVSS 6.5
SiYuan < 3.5.4 - Stored Cross-Site Scripting via Block Icon Attribute
CVSS 9.6
SiYuan < 3.5.5 - Authenticated Path Traversal and Remote Code Execution via File Copy Endpoint
CVSS 9.1
SiYuan - Stored Cross-Site Scripting in Markdown Rendering Engine
CVSS 4.6
Bosch Video Management System 8.0 - Configuration Client Denial of Service (PoC)