m10sec
20 exploits
Active since Sep 2014
Backdrop CMS 1.28.0-1.28.4 and 1.29.0-1.29.2 - Stored Cross-Site Scripting via SVG Image Upload
SUSE Linux Enterprise Module for Development Tools - Denial of Service via HTTP/2 Stream Reset
iPadOS < 17.7.6 - Unauthenticated AirPlay Command Execution via Network Access
FortiWeb 7.4.0-7.4.9, 7.6.0-7.6.4, 8.0.0 - Unauthenticated SAML Authentication Bypass via Crafted SAML Response
Fortinet FortiOS/FortiProxy/FortiSwitchManager SAML Signature Verification Bypass
jQuery < 3.0.0 - Cross-Site Scripting via Cross-Domain Ajax Request
Next.js Middleware Bypass
NGINX <1.23.2-1.22.1 - Memory Corruption
NGINX < 1.17.7 - HTTP Request Smuggling via error_page Configuration
SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
CVSS 10.0
Symfony <5.4.46, <6.4.14, <7.1.7 - Auth Bypass
CVSS 7.5
Google Chrome < 108.0.5359.71 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
Symfony 2.0.0-4.4.49 - Session Fixation via HTTP Cache Set-Cookie Header
CVSS 5.9
Log4Shell HTTP Header Injection
CVSS 10.0
nginx 0.6.18-1.20.0 - Denial of Service via DNS Resolver Off-by-one Error
CVSS 7.7
Symfony 3.4.0-3.4.48 - Unauthorized User Enumeration via Switch User Functionality
CVSS 5.3
Symfony 2.7.0-2.7.50, 2.8.0-2.8.49, 3.0.0-3.4.25, 4.0.0-4.1.11, 4.2.0-4.2.6 - XSS in Validation Messages
CVSS 5.4
OpenSSH < 7.7 - User Enumeration via Authentication Request Timing
CVSS 5.3
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVSS 9.8
Next.js Middleware Bypass
CVSS 9.1