Exploit Database

150,541 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-8331 WRITEUP MEDIUM
OpenRapid RapidCMS <1.3.1 - SQL Injection
A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been classified as critical. This affects an unknown part of the file /admin/user/user-move-run.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2024-8335 WRITEUP MEDIUM
OpenRapid RapidCMS <1.3.1 - SQL Injection
A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2024-8568 WRITEUP MEDIUM
Mini-Tmall <20240901 - SQL Injection
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 6.3
CVE-2024-8612 WRITEUP LOW
Red Hat Enterprise Linux - Information Disclosure in virtio-scsi, virtio-blk, and virtio-crypto Devices
A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.
CVSS 3.8
CVE-2024-9048 WRITEUP LOW
RuoYi < 4.7.9 - Cross-Site Scripting in Backend User Import via loginName
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java of the component Backend User Import. The manipulation of the argument loginName leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The patch is named 9b68013b2af87b9c809c4637299abd929bc73510. It is recommended to apply a patch to fix this issue.
CVSS 3.1
CVE-2024-9076 WRITEUP MEDIUM
dedecms < 5.7.115 - OS Command Injection via article_string_mix.php
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 4.7
CVE-2024-9293 WRITEUP MEDIUM
skyselang yyladmin < 3.0 - SQL Injection via is_disable Argument
A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2025-0781 WRITEUP HIGH
simgear < 2020.3.19 - Unauthenticated Arbitrary File Write via Nasal Script Sandbox Bypass
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
CVSS 8.6
CVE-2025-0781 WRITEUP HIGH
simgear < 2020.3.19 - Unauthenticated Arbitrary File Write via Nasal Script Sandbox Bypass
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
CVSS 8.6
CVE-2025-13151 WRITEUP HIGH
libtasn1 v4.20.0 - Stack-based Buffer Overflow in asn1_expend_octet_string
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.
CVSS 7.5
CVE-2025-14674 WRITEUP MEDIUM
aizuda snail-job <1.6.0 - Code Injection
A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java. The manipulation results in injection. The attack can be launched remotely. Upgrading to version 1.7.0-beta1 addresses this issue. The patch is identified as 978f316c38b3d68bb74d2489b5e5f721f6675e86. The affected component should be upgraded.
CVSS 6.3
CVE-2025-29647 WRITEUP CRITICAL
SeaCMS v13.3 - SQL Injection in admin_tempvideo.php
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
CVSS 9.8
CVE-2025-32461 WRITEUP CRITICAL
Tiki < 21.12, 22-24.7, 25-27.1, 28-28.2 - Remote Code Execution via wikiplugin_includetpl Eval
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
CVSS 9.9
CVE-2025-5569 WRITEUP MEDIUM
ideacms < 1.7 - SQL Injection via Article/Goods Field Parameter
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getList.html. The manipulation of the argument Field leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.8 is able to address this issue. The patch is named 935aceb4c21338633de6d41e13332f7b9db4fa6a. It is recommended to upgrade the affected component.
CVSS 6.3
CVE-2025-57563 WRITEUP MEDIUM
StarNet Communications Corporation FastX <4.1.51 - Path Traversal
A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files.
CVSS 6.5
CVE-2025-57618 WRITEUP HIGH
FastX3 <= 3.3.67 - Unauthenticated Path Traversal and Remote Code Execution
A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the server. By leveraging this vulnerability, it is possible to access the application's configuration files, which contain the secret key used to sign JSON Web Tokens as well as existing JTIs. With this information, an attacker can forge valid JWTs, impersonate the root user, and achieve remote code execution in privileged context via authenticated endpoints.
CVSS 7.3
CVE-2025-57783 WRITEUP MEDIUM
Hiawatha 11.7 - Unauthenticated Request Smuggling via Improper Header Parsing
Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.
CVSS 5.3
CVE-2025-57784 WRITEUP LOW
Hiawatha 11.7 - Timing Attack via Tomahawk Auth strcmp
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
CVSS 3.3
CVE-2025-57785 WRITEUP MEDIUM
Hiawatha Webserver 11.7 - Unauthenticated Double Free in XSLT show_index
A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.
CVSS 6.5
CVE-2025-61962 WRITEUP MEDIUM
fetchmail 5.9.9-6.5.5 - Denial of Service via Malformed SMTP 334 Status Code
In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.
CVSS 5.9
CVE-2025-62618 WRITEUP HIGH
elog < 3.1.5-20251014 - Authenticated Arbitrary HTML File Upload and Credential Theft
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and replay them or crack the password hash offline. In ELOG 3.1.5-20251014 release, HTML files are rendered as plain text.
CVSS 8.0
CVE-2025-64348 WRITEUP HIGH
elog < 3.1.5-20251014 - Authenticated Configuration File Overwrite and Denial of Service
ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.
CVSS 7.1
CVE-2025-64349 WRITEUP HIGH
elog < 3.1.5-20251014 - Authenticated Account Takeover via Profile Modification
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration.
CVSS 8.8
CVE-2025-65594 WRITEUP HIGH
OpenSIS < 9.2 - Authenticated Incorrect Access Control in Student.php
OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users.
CVSS 8.1
CVE-2025-67897 WRITEUP MEDIUM
Sequoia < 2.1.0 - Denial of Service via AES Key Unwrap Panic
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.
CVSS 5.3