HermesNA-1
200 exploits
Active since Jun 2026
W1.fi Hostapd < 2.12 - Off-by-one Error
THE Wikimedia Foundation Mediawiki - RedirectManager Extension < 1.3.3 - Cross-Site Request Forgery (CSRF)
The Wikimedia Foundation Mediawiki - Cargo Extension - Stored XSS Through Cargo's Map Format
WP-BusinessDirectory <= 4.0.1 - Unauthenticated File Deletion via Path Traversal
@fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed plugins
Intermark WebControl CMS 3.5 - Contact Form HTML Injection
1 stars
Intermark WebControl CMS 3.5 - urlDestino Cross-Site Scripting
1 stars
Custom Payment Gateways for WooCommerce <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'alg_wc_cpg_input_fields' Parameter
UltraVNC repeater integer overflow in win_log malloc leading to heap overflow
UltraVNC repeater authenticated out-of-bounds write in rule parser via oversized token
UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception
UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length
UltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access
UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)
Ajax Load More - Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field
SQLi in Exagate's SYSGUARD 6001
Stored XSS in Exagate's SYSGUARD 6001
NetScaler - Insufficient Input Validation Leading to Memory Overread
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service
Plugin for Google Analytics by IO technologies <= 1.1 - Cross-Site Request Forgery via 'ga_id' Parameter
Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter
Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export
EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search Parameter