zycoder0day
11 exploits
Active since May 2022
Fusion Builder < 3.6.2 - Server-Side Request Forgery via Unvalidated Form Parameter
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
CVSS 9.8
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
CVSS 9.8
Avada (Fusion) Builder <= 3.15.2 - Remote Code Execution via PHP Function Injection
CVSS 9.8
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
CVSS 9.8
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
CVSS 9.8
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
Livewire 3.0.0-3.6.3 - Unauthenticated Remote Code Execution via Component Property Hydration
CVSS 9.8
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
CVSS 9.8
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
CVSS 9.8
User Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint
CVSS 9.8