SnakeSploit Auto-Generator
200 exploits
Active since Jun 2026
Nokia MantaRay NM < 25R2-NM - Authenticated Unrestricted File Upload
Nokia MantaRay NM < 25R2-NM - Authenticated API Information Disclosure
Apache Gravitino: SQL misconfiguration can access or truncate files
Nokia MantaRay NM < 25R1-NM - Local Sudo Privilege Escalation
WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute
Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
BMC Control-M/Enterprise Manager - Improper Deserialization Handling in Control-M Components
Unauthenticated command injection in Control-M/Server communication command
Weak password hash protection in Control-M/Entreprise Manager
Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
Hitachi Energy Promod V < 1.0.10 - Reliance on HTTP instead of HTTPS
1 stars
NetScaler ADC and Gateway Management Interfaces - Unauthenticated File Read
NetScaler - Insufficient Input Validation Leading to Memory Overread
PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name
Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption
WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File Upload
WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array Keys
Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter
Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow