SnailSploit
10 exploits
Active since Sep 2025
Chartify - WordPress Chart Plugin <3.5.9 - Auth Bypass
CVSS 5.3
Lemmy's Activitypub-Federation has SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid()
CVSS 6.5
Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
CVSS 4.8
CairoSVG < 2.9.0 - Denial of Service via Recursive <use> Element Amplification
CVSS 7.5
ingress-nginx < 1.13.8, < 1.14.4, < 1.15.0 - Remote Code Execution via Rewrite Target Annotation Injection
CVSS 8.8
Document Library Lite <1.1.6 - Auth Bypass
CVSS 5.3
Friendly Functions for Welcart <= 1.2.5 - Cross-Site Request Forgery via Settings Page
CVSS 4.3
CatFolders - Time-Based SQL Injection
CVSS 6.5
ACF to REST API <3.3.4 - Insecure Direct Object Reference
CVSS 4.3
Omnipress <= 1.6.5 - Authenticated Stored Cross-Site Scripting via SVG File Upload
CVSS 6.4