iSee857
106 exploits
Active since Mar 2024
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
WordPress Crypto <2.15 - Auth Bypass
Fancy Product Designer <6.4.3 - SQL Injection
Tutor LMS < 2.7.6 - Unauthenticated SQL Injection via Rating Filter Parameter
Event Monster < 1.4.3 - Unauthenticated Information Exposure via Visitors List Export
Small Package Quotes - UPS Edition <4.5.16 - SQL Injection
LTL Freight Quotes - TForce Edition <3.6.4 - SQL Injection
LTL Freight Quotes - ABF Freight Edition <3.3.7 - SQL Injection
Yawave < 2.9.1 - Unauthenticated SQL Injection via lbid Parameter
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal via wfu_file_downloader.php
Hunk Companion <= 1.8.4 - Unauthenticated Arbitrary Plugin Installation and Activation via REST API
Wordpress Email Subscribers by Icegram Express - SQL Injection
Madara WordPress <2.2.2 - Local File Inclusion
Web Directory Free <1.7.3 - Code Injection
LTL Freight Quotes - Estes Edition <3.3.7 - SQL Injection
SureTriggers - All-in-One Automation Platform < 1.0.78 - Authentication Bypass
XWiki 1.8-15.10.8 - Unauthenticated Exposure of Private Personal Information via REST API
Palo Alto Networks PAN-OS - Auth Bypass
Apache Tomcat 9.0.0-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - RCE via TOCTOU Race Condition in JSP Compilation
XWiki Platform - Remote Code Execution
Vite server.fs.deny Bypass - Local File Inclusion
Apache Kafka Client - Arbitrary File Read
Cleo Harmony, VLTrader, and LexiCom < 5.8.0.21 - Unrestricted File Upload and Remote Code Execution
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal via wfu_file_downloader.php
Palo Alto Networks PAN-OS 10.2 11.0 11.1 11.2 - Unauthenticated Authentication Bypass