kimstars

3 exploits Active since Oct 2018
CVE-2026-21509 NOMISEC HIGH WORKING POC
Microsoft Office - Info Disclosure
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
8 stars
CVSS 7.8
CVE-2022-28117 NOMISEC MEDIUM WORKING POC
Naviwebs Navigate Cms - SSRF
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.
CVSS 4.9
CVE-2018-17552 NOMISEC CRITICAL WORKING POC
Naviwebs Navigate CMS 2.8 - SQL Injection
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
CVSS 9.8