iSee857
106 exploits
Active since Mar 2024
Landray EIS 2001-2006 - SQL Injection via Message/fi_message_receiver.aspx replyid Parameter
Langflow AI - Unauthenticated Remote Code Execution
Lingdang CRM < 8.6.5.2 - SQL Injection via yunzhijiaApi.php delete_user Function
MasterSAM Star Gate 11 - Path Traversal
NAKIVO Backup & Replication < 11.0.0.88174 - Absolute Path Traversal via getImageByPath
Navidrome <=0.54.5 - Authentication Bypass in Subsonic API
nestjs/devtools-integration < 0.2.1 - Remote Code Execution via Unsafe JavaScript Sandbox
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
Palo Alto Networks PAN-OS 10.2 11.0 11.1 11.2 - Unauthenticated Authentication Bypass
Next.js 13.4.0-14.1.1 - Server-Side Request Forgery via Server Actions Redirect
NUUO Camera <20250203 - Command Injection
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
Oracle Configurator 12.2.3-12.2.14 - Unauthenticated CRLF Injection via Runtime UI
ProjectSend < r1720 - Unauthenticated Configuration Modification via options.php
Ricoh and KONICA MINOLTA Web Image Monitor - Reflected Cross-Site Scripting
Scan2Net < 7.40 - Unauthenticated OS Command Injection via msg_events.php data Parameter
SimpleHelp Path Traversal Vulnerability CVE-2024-57727
Spring WebMvc.fn and WebFlux.fn 6.1.0-6.1.13 - Path Traversal via Static Resource Handling
Apache Struts 2.0.0-6.3.9 - Path Traversal and Remote Code Execution via File Upload
SysAid On-Prem <= 23.3.40 - XML External Entity
Traccar <6.8.1-6.0 - Local File Inclusion
40 stars
NPM Vite < 6.2.6 - Information Disclosure
40 stars
WP Query Console <= 1.0 - Remote Code Execution
HUSKY Products Filter Professional for WooCommerce <= 1.3.6.5 - Local File Inclusion via 'template'
PDF Generator Addon - Path Traversal