xxconi
23 exploits
Active since Aug 2025
Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
CVSS 7.8
Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
CVSS 9.8
Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
CVSS 9.8
WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability
CVSS 10.0
Gravity Forms < 2.9.23.1 - Remote Code Execution via Chunked Upload
CVSS 6.8
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
CVSS 9.8
Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter
CVSS 6.5
Jetpack CRM <=6.7.0 - PHP Local File Inclusion
CVSS 7.5
Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
CVSS 9.8
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
CVSS 8.1
Service Finder Bookings <6.0 - Privilege Escalation
CVSS 9.8
Drag and Drop File Upload for Contact Form 7 <= 1.1.3 - Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass
CVSS 8.1
W3 Total Cache <=2.9.1 - Privilege Escalation
CVSS 9.0
LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability
CVSS 8.8
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
CVSS 8.1
Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata
CVSS 9.8
Career Section <= 1.7 - Unauthenticated Arbitrary File Upload
CVSS 9.8
ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess
CVSS 9.8
Receive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth Callback
CVSS 9.8
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
Avada (Fusion) Builder <= 3.15.2 - Remote Code Execution via PHP Function Injection
CVSS 9.8
BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field
CVSS 9.8
Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter
CVSS 8.8