XiaomingX
190 exploits
Active since Oct 2024
Notepad++ < 8.8.9 - Download of Code Without Integrity Check in WinGUp Updater
Camaleon CMS < 2.9.1 - Privilege Escalation via Mass Assignment in UsersController
10 stars
Sudo <1.9.17p1 - Privilege Escalation
Uxper Sala - Startup & SaaS WordPress Theme <=1.1.4 - Privilege Escalation via Account Takeover
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
Pterodactyl Panel < 1.11.11 - Unauthenticated Remote Code Execution via Locale Endpoint
Google Chrome < 137.0.7151.68 - Out-of-bounds Read and Write in V8
1Panel < 2.0.6 - Remote Code Execution via Incomplete Certificate Verification
React Server Components <19.2.0 - RCE
Veeam Backup & Replication 13.0.0.4967-13.0.1.1071 - Authenticated Remote Code Execution via Interval or Order Parameter
vaahcms 2.3.1 - Cross-Site Scripting via UserBase.php storeAvatar() Upload Method
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
FortiSIEM 6.7.0-6.7.10, 7.0.0-7.0.4, 7.1.0-7.1.8, 7.3.0-7.3.4, 7.4.0 - OS Command Injection via TCP Requests
Django 4.2-4.2.25 5.1-5.1.13 5.2a1-5.2.7 - SQL Injection via QuerySet Dictionary Expansion
langgraph-checkpoint-sqlite < 3.0.1 - SQL Injection via Metadata Filter Key Interpolation
Axigen Mail Server <10.5.57 - Privilege Escalation
Gogs < 0.13.3 - Local Code Execution via PutContents API Symbolic Link Handling
Truelysell Core <1.8.7 - Privilege Escalation
Google Chrome < 143.0.7499.192 - Insufficient Policy Enforcement in WebView Tag
User Language Switch <1.6.10 - SSRF
Langflow validate exec_globals - Unauthenticated Root Code Execution
Ivanti Endpoint Manager Mobile (EPMM) unauthenticated RCE
Midi-Synth <1.1.0 - Unauthenticated RCE
Neo4j < 2026.01 - Cross-Site Scripting via Query Log Unicode Character Escaping
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE