Nxploited
156 exploits
Active since Nov 2023
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution via sneeit_articles_pagination_callback
CVSS 9.8
garidium g-FFL Checkout <2.1.0 - Unrestricted File Upload
CVSS 10.0
LA-Studio Element Kit - Privilege Escalation
CVSS 9.8
Academy LMS - WordPress LMS Plugin <3.5.0 - Privilege Escalation
CVSS 9.8
RegistrationMagic <6.0.7.1 - Privilege Escalation
CVSS 9.8
Webkul Medical Prescription Attachment Plugin <1.2.3 - RCE
CVSS 10.0
Simple Business Directory Pro - Privilege Escalation
CVSS 9.8
WordPress User Registration & Membership Plugin <=5.1.2 - Privilege Escalation
CVSS 9.8
YayMail WooCommerce Email Customizer <=4.3.2 - Privilege Escalation
CVSS 7.2
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability
CVSS 9.8
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator
CVSS 8.8
quantumcloud Simple Link Directory <14.8.1 - Auth Bypass
CVSS 9.8
User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation
CVSS 8.1
User Profile Builder <3.15.2 - Info Disclosure
CVSS 9.8
Frontend Admin by DynamiApps <3.28.20 - Info Disclosure
CVSS 9.8
Demo Importer Plus <2.0.8 - Privilege Escalation
CVSS 8.8
Pix for WooCommerce <=1.5.0 - Arbitrary File Upload
CVSS 9.8
Contempo Themes Real Estate <3.5.2 - Privilege Escalation
CVSS 7.3
Datalogics Ecommerce Delivery <2.6.60 - Privilege Escalation
CVSS 9.8
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CVSS 9.8
Contempo Themes Real Estate <3.5.2 - Privilege Escalation
CVSS 7.3
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload via slider_future_handle_image_upload
CVSS 9.8
Eventin < 4.0.35 - Unauthenticated Privilege Escalation via SpeakerController Email Update
CVSS 8.8
Imithemes Real Spaces - WordPress Properties Directory Theme <= 3.6 - Privilege Escalation
CVSS 9.8