anonymous

78 exploits Active since Dec 2000
CVE-2023-22527 NOMISEC CRITICAL WORKING POC
Atlassian Confluence SSTI Injection
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
5 stars
CVSS 9.8
CVE-2023-22527 NOMISEC CRITICAL WORKING POC
Atlassian Confluence SSTI Injection
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
5 stars
CVSS 9.8
CVE-2025-65336 WRITEUP CRITICAL WRITEUP
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 - SQL Injection via show_price_by_pdtId.php pid Parameter
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
CVSS 9.8
CVE-2025-65341 WRITEUP MEDIUM WRITEUP
Ecommerce Fruits Bazar 1.0 - Stored Cross-Site Scripting via Product Edit Form
Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
CVSS 6.1
CVE-2025-65342 WRITEUP MEDIUM WRITEUP
Blood System 1.0 - Stored Cross-Site Scripting via City Field in Donation Form
code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.
CVSS 6.1
CVE-2025-69930 WRITEUP CRITICAL WRITEUP
CodeAstro Membership Management System 1.0 - SQL Injection via print_membership_card.php id Parameter
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
CVSS 9.8
CVE-2025-69931 WRITEUP CRITICAL WRITEUP
CodeAstro Membership Management System 1.0 - SQL Injection via delete_membership.php id Parameter
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
CVSS 9.8
CVE-2025-69933 WRITEUP CRITICAL WRITEUP
CodeAstro Membership Management System 1.0 - Unauthenticated SQL Injection via id Parameter in memberProfile.php
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
CVSS 9.8
CVE-2025-69934 WRITEUP CRITICAL WRITEUP
CodeAstro Membership Management System 1.0 - SQL Injection via delete_members.php id Parameter
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
CVSS 9.8
CVE-2025-69935 WRITEUP CRITICAL WRITEUP
CodeAstro Membership Management System 1.0 - SQL Injection via fromDate Parameter in Report Endpoints
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
CVSS 9.8
CVE-2025-69936 WRITEUP CRITICAL WRITEUP
CodeAstro Membership Management System 1.0 - Unauthenticated SQL Injection via id Parameter in edit_member.php
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CVSS 9.8
CVE-2025-69937 WRITEUP CRITICAL WRITEUP
CodeAstro Membership Management System 1.0 - SQL Injection via edit_type.php id Parameter
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
CVSS 9.8
CVE-2025-69938 WRITEUP CRITICAL WRITEUP
CodeAstro Membership Management System 1.0 - SQL Injection via renew.php membershipType Parameter
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
CVSS 9.8
CVE-2025-69941 WRITEUP CRITICAL WRITEUP
Tailor Management System 1.0 - Unauthenticated SQL Injection via addmeasurement.php id Parameter
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
CVSS 9.8
CVE-2025-69947 WRITEUP CRITICAL WRITEUP
Tailor Management System 1.0 - Unauthenticated SQL Injection via customeredit.php id Parameter
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
CVSS 9.8
CVE-2025-69943 WRITEUP CRITICAL WRITEUP
Hospital Management System 4.0 - SQL Injection via get_doctor.php doctor and specilizationid Parameters
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
CVSS 9.8
CVE-2025-69949 WRITEUP HIGH WRITEUP
Hospital Management System 4.0 - SQL Injection via check_availability.php Email Parameters
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
CVSS 7.3
CVE-2025-65337 WRITEUP MEDIUM WRITEUP
Fantastic Blog CMS 1.0 - Stored Cross-Site Scripting via address Parameter in pageEditMember.php
Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field.
CVSS 6.1
CVE-2025-65340 WRITEUP CRITICAL WRITEUP
Hospital Management System 4.0 - SQL Injection via fromdate Parameter in betweendates-detailsreports.php
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
CVSS 9.8
CVE-2025-67403 WRITEUP CRITICAL WRITEUP
CASAP Automated Enrollment System 1.0 - SQL Injection via update_class.php class_name Parameter
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
CVSS 9.8
CVE-2025-67404 WRITEUP CRITICAL WRITEUP
CASAP Automated Enrollment System 1.0 - SQL Injection via save_stud.php fname, lname, and student_class Parameters
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
CVSS 9.8
CVE-2025-67405 WRITEUP HIGH WRITEUP
CASAP Automated Enrollment System 1.0 - SQL Injection via new_password Parameter in update_password.php
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
CVSS 7.3
CVE-2025-67406 WRITEUP HIGH WRITEUP
Advocate Office Management System 1.0 - Unauthenticated SQL Injection via activate_case.php id Parameter
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate office management system. Unsanitized user input in the specified parameter is interpolated directly into an SQL query, allowing attackers to infer or extract data and, in some cases, execute stacked/time-based payloads. ¶¶ Affected Component & Parameter Affected Endpoint URL: http://localhost/advocate/kortex_lite/control/activate_case.php?id=1 HTTP Method: GET Vulnerable File: activate_case.php Parameter: id Vector Location: GET Injection Techniques (as identified by sqlmap) Type: error-based Title: MySQL >= 5.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXTRACTVALUE) Payload: id=1 AND EXTRACTVALUE(6268,CONCAT(0x5c,0x71766b6a71,(SELECT (ELT(6268=6268,1))),0x716a7a6b71)) Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: id=1 AND (SELECT 4464 FROM (SELECT(SLEEP(5)))aHqo) Proof of Concept (Burp Repeater)
CVSS 7.3
CVE-2025-67407 WRITEUP HIGH WRITEUP
CASAP Automated Enrollment System 1.0 - SQL Injection via update_student.php fname and student_class Parameters
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
CVSS 7.3
CVE-2025-67408 WRITEUP HIGH WRITEUP
CASAP Automated Enrollment System 1.0 - SQL Injection via status Parameter in save_user.php
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
CVSS 7.3