cybersecplayground
26 exploits
Active since Feb 2024
Etoilewebdesign Front End Users < 3.2.32 - Unrestricted File Upload
React Server Components <19.2.0 - RCE
ASP.NET Core - SSRF
Oracle E-Business Suite CVE-2025-61882 RCE
Dlink Dns-320 Firmware - Command Injection
Ivanti Connect Secure - XXE
Zabbix Server - Command Injection
Check Point Quantum Gateway - Information Disclosure
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
Pgadmin 4 < 9.10 - Code Injection
BIG-IP - Command Injection
Fortinet Fortiproxy < 7.4.7 - Missing Authentication
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
SysAid On-Prem <= 23.3.40 - XML External Entity
Vite Development Server - Path Traversal
SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
BIG-IP TMOS Shell - Command Injection
XWiki Platform - SQL Injection
Fortinet Fortimail < 7.0.9 - Out-of-Bounds Write
Themewinter Eventin < 4.0.27 - Incorrect Privilege Assignment
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
NetAlertX <25.6.7 - Auth Bypass
Roundcube Webmail < 1.5.10 - Insecure Deserialization
Fortinet FortiSwitch GUI - RCE
Wazuh server remote code execution caused by an unsafe deserialization vulnerability.