XiaomingX
190 exploits
Active since Oct 2024
Tandoor Recipes < 2.5.1 - Authenticated Blind Server-Side Request Forgery via Cookmate Recipe Import
vaultwarden < 1.35.3 - Incorrect Authorization via Organization Ciphers Endpoint
Microsoft Semantic Kernel <1.39.4 - RCE
manga-image-translator <beta-0.3 - Unauthenticated RCE
10 stars
Hyland OnBase - Unauthenticated RCE
JUNG Smart Visu Server 1.1.1050 - DoS
yt-dlp 2023.06.21-2026.02.21 - Command Injection
Calero VeraSMART <2022 R1 - Remote Code Execution
Advantech WISE-6610 1.2.1 - Command Injection
Richie < 3.3.0 - Observable Timing Discrepancy in HMAC Signature Verification
FormaLMS < 4.1.18 - Unauthenticated User Enumeration via Password Recovery Response Discrepancy
OpenSourcePOS 3.4.1 - Local File Inclusion and Remote Code Execution via Invoice Type Manipulation
LibreNMS < 26.2.0 - SQL Injection via IPv6 Address Search in ajax_table.php
MajorDoMo - Unauthenticated Remote Code Execution via Admin Console Eval
MajorDoMo - Unauthenticated Remote Code Execution via Update URL Poisoning
Werkzeug < 3.1.6 - Denial of Service via Windows Device Name Path Handling
ZoneMinder <=1.36.37, 1.37.61-1.38.0 - SQL Injection
OneUptime <=9.5.13 - Code Injection
Mercator < 2026.02.22 - Authenticated Stored Cross-Site Scripting via Unescaped Blade Directives
rldns 1.3 - Denial of Service via Heap-Based Out-of-Bounds Read
funadmin <7.1.0-rc4 - Deserialization
karnop realtime-collaboration-platform - Origin Validation Error in CORS Configuration
Quiz Maker < 6.7.0.56 - Unauthenticated SQL Injection via Spoofed IP Headers
Google Chrome <143.0.7499.110 - Memory Corruption
WordPress SportsPress <= 2.7.26 - Contributor Local File Inclusion Code Execution