webraybtl
62 exploits
Active since Mar 2022
Kingsoft WPS Office < 11.2.0.10382 - Remote Code Execution via Registry Modification
Notepad++ < 8.5.6 - Heap-based Buffer Overflow in Utf8_16_Read::convert
Foxit PDF Reader < 12.1.1.15289 and PDF Editor < 10.1.11.37866 - Remote Code Execution via exportXFAData Method
WPS Office < 11.2.0.10258 - Incorrect Default Permissions in Service Directory
modbustools/modbus_slave < 7.4.3 - Stack-based Buffer Overflow in Registration Field
Modbus Tools Modbus Slave <7.5.1 - Buffer Overflow
CVSS 6.3
Modbus Tools Modbus Poll <9.10.0 - Buffer Overflow
CVSS 6.3
DolphinPHP < 1.5.0 - Cross-Site Scripting in User Management Page
CVSS 3.5
htmly 5.3 - Authenticated Stored Cross-Site Scripting in Edit Profile Module
CVSS 3.5
GetSimple CMS - Authenticated Stored Cross-Site Scripting in Content Module via post-content Argument
CVSS 3.5
Bludit 3.13.1 - Authenticated Stored Cross-Site Scripting via New Content Endpoint
CVSS 3.5
Badminton Center Management System - Authenticated Cross-Site Scripting in Userlist Module
CVSS 3.5
SourceCodester Prison Management System 1.0 - SQL Injection via Visit Handler id Parameter
CVSS 4.7
SourceCodester Prison Management System 1.0 - SQL Injection via Inmate Handler id Parameter
CVSS 4.7
SourceCodester Prison Management System 1.0 - Improper Authorization in New User Creation
CVSS 7.3
SourceCodester Prison Management System 1.0 - Cross-Site Scripting in System Name Handler
CVSS 2.4
SourceCodester Bank Management System 1.0 - SQL Injection via login.php Password Parameter
CVSS 6.3
SourceCodester Bank Management System 1.0 - Cross-Site Scripting via mnotice.php id Parameter
CVSS 3.5
eveo urve_web_manager - Unrestricted File Upload via img_upload.php
CVSS 8.0
eveo urve_web_manager - Unrestricted File Upload in upload.php
CVSS 8.0
eveo urve_web_manager - Unrestricted File Upload via _internal/uploader.php
CVSS 8.0
WAVLINK WN535K2 and WN535K3 - OS Command Injection via mesh.cgi Upgrade Key Parameter
CVSS 8.0
WAVLINK WN535K2 and WN535K3 - OS Command Injection via nightled.cgi start_hour Parameter
CVSS 8.0
WAVLINK WN535K2 and WN535K3 - OS Command Injection via touchlist_sync.cgi IP Parameter
CVSS 8.0
SourceCodester Garage Management System 1.0 - SQL Injection
CVSS 6.3