iSee857
106 exploits
Active since Mar 2024
NovaCHRON Smart Time Plus <8.6 - SQL Injection
Checkout Mestres do WP for WooCommerce <8.7.5 - Privilege Escalation
Kubio AI Page Builder <2.5.1 - Local File Inclusion
FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload
Cisco IOS XE - Unauthenticated Arbitrary File Upload and Remote Code Execution via Hard-coded JWT
Altenergy Power Control Software <20241108 - SQL Injection
NUUO Camera <20250203 - Command Injection
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L - OS Command Injection via nas_sharing.cgi System Parameter
DataEase < 2.10.2 - Use of Hard-coded Credentials for JWT Forgery
DataEase < 2.10.10 - Improper Authentication via JWT Secret Bypass
dedecms 5.71sp1 - URL Redirection via GET Request
Dify 1.6.0 RemoteFileUploadApi - Server-Side Request Forgery
DocsGPT 0.8.1-0.12.0 - Remote Code Execution via /api/remote Endpoint
40 stars
FREEDOM Administration - Default Login
40 stars
Grafana 11.0.0-11.0.5 - Authenticated Command Injection via DuckDB SQL Expressions
Ivanti Endpoint Manager Cloud Services Appliance - Unauthenticated Path Traversal
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
Ivanti Endpoint Manager Mobile <= 12.5.0.0 - Unauthenticated Authentication Bypass via API
Guangzhou Huayi Intelligent Technology Jeewms < 2025-01-01 - SQL Injection via datagridGraph Function
JeecgBoot 3.7.1 - SQL Injection via /onlDragDatasetHead/getTotalData
Jinher OA < 1.2 - SQL Injection via ID Parameter in GetTreeDate.aspx
Landray EIS 2001-2006 - SQL Injection via Message/fi_message_receiver.aspx replyid Parameter
Langflow AI - Unauthenticated Remote Code Execution
Lingdang CRM < 8.6.5.2 - SQL Injection via yunzhijiaApi.php delete_user Function
Oracle Configurator 12.2.3-12.2.14 - Unauthenticated CRLF Injection via Runtime UI