XiaomingX
190 exploits
Active since Oct 2024
macOS Tahoe <26.3 - Info Disclosure
INDEX-EDUCATION PRONOTE <2025.2.8 - Info Disclosure
Red Hat Enterprise Linux 10 - Buffer Overflow
Missing authorization check allows unauthorized modification of other users' comments on a board
Azure MCP Server - Authenticated Server-Side Request Forgery
FreeFloat FTP Server 1.0 - Buffer Overflow
setuptools < 78.1.1 - Path Traversal and Arbitrary File Write via PackageIndex
InvoicePlane < 1.7.1 - Authenticated Stored Cross-Site Scripting via Invoice Number Field
InvoicePlane < 1.7.1 - Authenticated Stored Cross-Site Scripting via Product Unit Name Field
CairoSVG < 2.9.0 - Denial of Service via Recursive <use> Element Amplification
FontForge - Remote Code Execution via SFD File Parsing
InvoicePlane < 1.7.1 - Stored Cross-Site Scripting via Family Name Field
Google Clasp < 3.2.0 - Remote Code Execution via Directory Traversal in Filename
tar < 7.5.11 - Path Traversal via Drive-Relative Symlink Target
Active Directory Domain Services - Privilege Escalation
Worry Proof Backup Plugin <0.2.4 - Path Traversal
CasaMia Theme <=1.1.2 - PHP Local File Inclusion
pac4j-jwt <4.5.9/5.7.9/6.3.3 - Auth Bypass
Budibase < 3.31.4 - Unauthenticated API Access Bypass via Webhook Path Query String
mathurvishal CloudClassroom-PHP-Project - SQL Injection via gnamex Parameter
NetExec < 1.5.1 - Path Traversal and Arbitrary File Write via SMB Share Filename
Koha Staff Interface - SQL Injection
OpenEMR < 8.0.0.1 - Authenticated SQL Injection via AJAX Graphs Library
StudioCMS <0.4.0 - Privilege Escalation
StudioCMS <0.4.0 - Privilege Escalation