XiaomingX
190 exploits
Active since Oct 2024
n8n <1.123.17, <2.5.2 - Command Injection
Vendure < 3.5.3 - Timing Attack Enumerating Valid Usernames via NativeAuthenticationStrategy
n8n < 1.123.10 and 2.0.0-2.5.0 - Authenticated OS Command Injection and Arbitrary File Read via Git Node
PolarLearn <0-PRERELEASE-15 - Info Disclosure
CAI Framework <= 0.5.10 - Remote Code Execution via Argument Injection in find_file Tool
llama-stack < 0.4.0rc3 - Sensitive Information Exposure in Initialization Log
OpenClaw <2026.1.29 - Info Disclosure
Group-Office < 6.8.150 - Authenticated Remote Code Execution via tmp_file Parameter
JinJava 2.7.0-2.7.5 and 2.8.0-2.8.2 - Remote Code Execution via ForTag Sandbox Bypass
godot-mcp < 0.1.1 - Remote Code Execution via Project Path Shell Metacharacter Injection
Frigate < 0.16.4 - Remote Command Execution via go2rtc exec Directive
M-Track Duo HD <1.0.0 - Code Injection
calibre < 9.2.0 - Remote Code Execution via Templite Template Injection
NiceGUI < 3.7.0 - Path Traversal via FileUpload.name Property
OpenEMR < 8.0.0 - Authenticated SQL Injection in Prescription Listing
jsPDF < 4.2.0 - Code Injection via addJS Method
taklaxbr/zai_shell < 9.0.3 - Unauthenticated Remote Code Execution via P2P Terminal Sharing
grub-btrfs <2026-01-31 - Command Injection
Tenda G300-F <16.01.14.2 - Command Injection
filebrowser < 2.57.1 - Authenticated Authorization Bypass via Multiple Slash Path Manipulation
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
kanboard < 1.2.50 - Authenticated Remote Code Execution via Plugin Installer Bypass
FUXA 1.2.8-1.2.10 - Unauthenticated Authorization Bypass via Scheduler Modification
SumatraPDF 3.5.0-3.5.2 - Remote Code Execution via Update Mechanism TLS Hostname Verification Bypass
Tandoor Recipes <2.5.1 - Path Traversal