cybersecplayground
26 exploits
Active since Feb 2024
Front End Users <= 3.2.32 - Unauthenticated Arbitrary File Upload via Registration Form
React Server Components <19.2.0 - RCE
ASP.NET Core 2.3.0-2.3.5 - HTTP Request Smuggling via Inconsistent Request Interpretation
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L - OS Command Injection via cgi_user_add name Parameter
Ivanti Connect Secure - XXE
Zabbix 6.0.0-6.0.27 - Time-Based Blind SQL Injection via Audit Log Client IP Field
Check Point Quantum Gateway - Information Disclosure
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
pgAdmin < 9.10 - Remote Code Execution via PLAIN-Format Dump File Restore
F5 BIG-IP 15.1.0-15.1.10.6 - Authenticated OS Command Injection via iControl REST and TMOS Shell Save Command
FortiProxy 7.6.0-7.6.1, FortiSwitchManager 7.2.5, FortiOS 7.4.4-7.4.6, 7.6.0 - Authentication Bypass
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
SysAid On-Prem <= 23.3.40 - XML External Entity
Vite Development Server - Path Traversal
SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
BIG-IP TMOS Shell - Command Injection
XWiki Platform - SQL Injection
Fortinet Fortimail < 7.0.9 - Out-of-Bounds Write
Eventin <= 4.0.26 - Privilege Escalation via Incorrect Privilege Assignment
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
netalertx < 25.6.7 - Authentication Bypass via PHP Loose Comparison
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
FortiSwitch >=6.4.0 <6.4.15 - Unauthenticated Password Change via GUI Request
Wazuh server remote code execution caused by an unsafe deserialization vulnerability.