sh7err
21 exploits
Active since Nov 2025
Scada-LTS < 2.7.8.1 - Cross-Site Request Forgery
CVSS 4.3
Scada-LTS < 2.7.8.1 - Path Traversal in Project Import via ZIPProjectManager
CVSS 6.3
NutzBoot < 2.6.0-SNAPSHOT - Exposure of Sensitive Information in Ethereum Wallet Handler
CVSS 4.3
NutzBoot < 2.6.0-SNAPSHOT - Remote Code Execution via LiteRpc-Serializer Deserialization
CVSS 3.7
nutzam NutzBoot < 2.6.0 - Improper Authorization in Transaction API
CVSS 7.3
orionsec orion-ops < 2025-08-01 - Incorrect Privilege Assignment in MachineKeyController
CVSS 4.3
orionsec orion-ops - Incorrect Privilege Assignment in User Profile Handler
CVSS 7.3
orionsec orion-ops < 2025-08-01 - Server-Side Request Forgery via SSH Connection Handler
CVSS 6.3
jsnjfz WebStack-Guns 1.0 - Path Traversal in KaptchaController renderPicture Function
CVSS 5.3
jsnjfz WebStack-Guns 1.0 - SQL Injection via Sort Parameter
CVSS 6.3
mogublog < 5.2 - Missing Authorization in Storage Management Endpoint
CVSS 5.6
mogublog < 5.2 - Server-Side Request Forgery via LocalFileServiceImpl.uploadPictureByUrl
CVSS 7.3
mogublog < 5.2 - Unrestricted File Upload via /file/pictures filedatas Parameter
CVSS 6.3
mogublog < 5.2 - Path Traversal via ZIP File Handler
CVSS 6.3
Yohann0617 oci-helper <3.2.4 - Path Traversal
CVSS 6.3
Takes TkFiles <2.0-SNAPSHOT - Path Traversal
CVSS 7.5
Turms Admin API thru v0.10.0-SNAPSHOT - Cross-Site Request Forgery
CVSS 6.1
Turms AI-Serving < 0.10.0-SNAPSHOT - Unrestricted File Upload via OCR Image Upload
CVSS 5.3
Turms AI-Serving module <= 0.10.0-SNAPSHOT - Unauthenticated Denial of Service via Image Decompression Bomb
CVSS 7.5
Turms Server v0.10.0-SNAPSHOT - Info Disclosure
CVSS 6.0
Turms IM Server <= 0.10.0-SNAPSHOT - Authenticated Improper Access Control in User Online Status Query
CVSS 6.5