XiaomingX
190 exploits
Active since Oct 2024
NextScripts Social Networks Auto-Poster <4.4.6 - XSS
StudioCMS <0.4.0 - Privilege Escalation
liquidjs < 10.25.0 - Path Traversal via Layout, Render, and Include Tags
OpenEMR < 8.0.0.1 - Authenticated SQL Injection via AJAX Graphs Library
ingress-nginx < 1.13.8, < 1.14.4, < 1.15.0 - Remote Code Execution via Rewrite Target Annotation Injection
eml-parser < 2.0.1 - Path Traversal and Arbitrary File Write via Unsanitized Attachment Filename
Microsoft Devices Pricing Program - RCE
nginxui/nginx_ui < 2.3.3 - Unauthenticated Sensitive Data Exposure via Backup Endpoint
Hikvision Wireless AP - Command Injection
Appsmith < 1.96 - Stored Cross-Site Scripting in Table Widget via Invite Users Feature
Koa 3.0.0-3.1.1 and <2.16.14 - Host Header Injection via ctx.hostname
Redis < 6.2.20, 8.2.1-8.2.2 - Authenticated Use-After-Free via Lua Script Garbage Collector Manipulation
WordPress User Registration & Membership Plugin <=5.1.2 - Privilege Escalation
Sliver <= 1.7.3 - Authenticated Denial of Service via Protobuf Unmarshalling
tar < 7.5.10 - Path Traversal via Drive-Relative Hardlink
Chamilo <1.11.34 - Authenticated RCE
Cisco Secure Firewall Management Center 6.4.0.13-6.4.0.18, 7.0.0 - RCE via Java Deserialization
TP-Link Tapo C260 v1, D235 v1, C520WS v2.6 - Path Traversal via URL-Encoded GET Requests
VMware Workstation >=17.0 <25H2u1 - Authenticated Denial of Service via Null Pointer Dereference
MindsDB < 25.9.1.1 - Authenticated Path Traversal and Remote Command Execution via /api/files Upload
Langflow < 1.8.0 - Remote Code Execution via CSV Agent Node
enclave-vm < 2.7.0 - Sandbox Escape via Host Error Prototype Chain Traversal
Cisco Secure Firewall Management Center - Auth Bypass & RCE via Crafted HTTP Requests
Windows OS < 25H2 - Denial of Service via CLFS.sys Driver Inconsistency
FreeScout <=1.8.206 - Authenticated RCE