Nxploited
165 exploits
Active since Nov 2023
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
Contempo Themes Real Estate <3.5.2 - Privilege Escalation
CVSS 7.3
Pix for WooCommerce <=1.5.0 - Arbitrary File Upload
CVSS 9.8
Datalogics Ecommerce Delivery <2.6.60 - Privilege Escalation
CVSS 9.8
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CVSS 9.8
Contempo Themes Real Estate <3.5.2 - Privilege Escalation
CVSS 7.3
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload via slider_future_handle_image_upload
CVSS 9.8
StoreKeeper <14.4.4 - Unrestricted Upload
CVSS 10.0
RestroPress 3.0.0-3.1.9.2 - Unauthenticated Authentication Bypass via REST API
CVSS 9.8
Eventin < 4.0.35 - Unauthenticated Privilege Escalation via SpeakerController Email Update
CVSS 8.8
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload via Webhook REST-API Endpoint
CVSS 9.8
Appy Pie Connect <1.1.2 - Privilege Escalation
CVSS 9.8
AdForest theme <6.0.9 - Auth Bypass
CVSS 9.8
Imithemes Real Spaces - WordPress Properties Directory Theme <= 3.6 - Privilege Escalation
CVSS 9.8
BeyondCart Connector <2.1.0 - Privilege Escalation
CVSS 9.8
Miraculous Core Plugin <2.0.7 - Privilege Escalation
CVSS 9.8
Alone - Charity Multipurpose Non-profit WordPress Theme <7.8.3 - RCE
CVSS 9.8
WPvivid Backup & Migration < 0.9.116 - Authenticated Arbitrary File Upload via wpvivid_upload_import_files
CVSS 7.2
PT Project Notebooks 1.0.0-1.1.3 - Unauthenticated Privilege Escalation via wpnb_pto_new_users_add()
CVSS 9.8
Motors Plugin <= 1.4.64 - Authenticated Arbitrary Plugin Installation
CVSS 8.8
Rometheme RomethemeKit For Elementor <1.5.4 - Code Injection
CVSS 9.9
Celestial Aura < 2.2 - Unrestricted Upload of File with Dangerous Type
CVSS 9.9
SoJ SoundSlides <= 1.2.2 - Authenticated Arbitrary File Upload via soj_soundslides_options_subpanel()
CVSS 8.8
Buddypress Humanity <= 1.2 - Cross-Site Request Forgery
CVSS 9.8
Crowdytheme Arolax < 1.7 - Missing Authorization
CVSS 8.8