David Silva
19 exploits
Active since Feb 2022
BoltWire 7.10 and 8.00 - Cross-Site Scripting via Name and Lastname Parameters
CVSS 6.1
BoltWire 6.03 - Unauthenticated Sensitive Information Disclosure and Password Change
CVSS 9.1
Microweber 2.0.4 - Unauthenticated Arbitrary File Upload via Created Forms Component
CVSS 8.8
LibreWolf <143.0.4-1 - Path Traversal
CVSS 7.0
Catalyst User Key Authentication Plugin 20220819 - Open Redirect
CVSS 4.3
juzaweb CMS <= 3.4.2 - Cross-Site Scripting via File Manager Upload
CVSS 3.5
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Plugin Editor Page
CVSS 6.3
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Email Logs Page
CVSS 4.3
juzaweb CMS < 3.4.2 - Improper Access Control in General Setting Page
CVSS 6.3
juzaweb CMS < 3.4.2 - Improper Access Control in Media Page
CVSS 6.3
juzaweb CMS < 3.4.2 - Improper Access Control in Theme Editor Page
CVSS 6.3
juzaweb CMS < 3.4.2 - Improper Access Control in Menu Page
CVSS 6.3
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Permalinks Page
CVSS 6.3
juzaweb CMS < 3.4.2 - Improper Access Control in Error Logs Page
CVSS 6.3
juzaweb CMS < 3.4.2 - Improper Access Control in Plugins Page
CVSS 6.3
juzaweb CMS 3.4.2 - Improper Authorization in Import Page
CVSS 6.3
juzaweb CMS 3.4.2 - Incorrect Privilege Assignment in Add New Themes Page
CVSS 6.3
Notepad2 4.2.22-4.2.25 - Path Traversal
CVSS 7.0
Total VPN 0.5.29.0 - Privilege Escalation
CVSS 7.0