Exploit Database

151,777 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-7926 WRITEUP HIGH
ZZCMS 2023 - Path Traversal via skin Parameter in about_edit.php
A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 7.3
CVE-2024-7927 WRITEUP HIGH
ZZCMS 2023 - Path Traversal via skin[] Parameter in /admin/class.php
A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 7.3
CVE-2024-8294 WRITEUP MEDIUM
FeehiCMS <2.1.1 - Unrestricted Upload
A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The manipulation of the argument FriendlyLink[image] leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 6.3
CVE-2024-8295 WRITEUP MEDIUM
FeehiCMS <2.1.1 - Unrestricted Upload
A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbanner-create. The manipulation of the argument BannerForm[img] leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 6.3
CVE-2024-8296 WRITEUP MEDIUM
FeehiCMS <2.1.1 - Unrestricted Upload
A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation of the argument User[avatar] leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 6.3
CVE-2024-8331 WRITEUP MEDIUM
OpenRapid RapidCMS <1.3.1 - SQL Injection
A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been classified as critical. This affects an unknown part of the file /admin/user/user-move-run.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2024-8335 WRITEUP MEDIUM
OpenRapid RapidCMS <1.3.1 - SQL Injection
A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2024-8568 WRITEUP MEDIUM
Mini-Tmall <20240901 - SQL Injection
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 6.3
CVE-2024-8612 WRITEUP LOW
Red Hat Enterprise Linux - Information Disclosure in virtio-scsi, virtio-blk, and virtio-crypto Devices
A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.
CVSS 3.8
CVE-2024-9048 WRITEUP LOW
RuoYi < 4.7.9 - Cross-Site Scripting in Backend User Import via loginName
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java of the component Backend User Import. The manipulation of the argument loginName leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The patch is named 9b68013b2af87b9c809c4637299abd929bc73510. It is recommended to apply a patch to fix this issue.
CVSS 3.1
CVE-2024-9076 WRITEUP MEDIUM
dedecms < 5.7.115 - OS Command Injection via article_string_mix.php
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 4.7
CVE-2024-9293 WRITEUP MEDIUM
skyselang yyladmin < 3.0 - SQL Injection via is_disable Argument
A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3
CVE-2025-0781 WRITEUP HIGH
simgear < 2020.3.19 - Unauthenticated Arbitrary File Write via Nasal Script Sandbox Bypass
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
CVSS 8.6
CVE-2025-0781 WRITEUP HIGH
simgear < 2020.3.19 - Unauthenticated Arbitrary File Write via Nasal Script Sandbox Bypass
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
CVSS 8.6
CVE-2025-13151 WRITEUP HIGH
libtasn1 v4.20.0 - Stack-based Buffer Overflow in asn1_expend_octet_string
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.
CVSS 7.5
CVE-2025-14674 WRITEUP MEDIUM
aizuda snail-job <1.6.0 - Code Injection
A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java. The manipulation results in injection. The attack can be launched remotely. Upgrading to version 1.7.0-beta1 addresses this issue. The patch is identified as 978f316c38b3d68bb74d2489b5e5f721f6675e86. The affected component should be upgraded.
CVSS 6.3
CVE-2025-29647 WRITEUP CRITICAL
SeaCMS v13.3 - SQL Injection in admin_tempvideo.php
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
CVSS 9.8
CVE-2025-32461 WRITEUP CRITICAL
Tiki < 21.12, 22-24.7, 25-27.1, 28-28.2 - Remote Code Execution via wikiplugin_includetpl Eval
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
CVSS 9.9
CVE-2025-5569 WRITEUP MEDIUM
ideacms < 1.7 - SQL Injection via Article/Goods Field Parameter
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getList.html. The manipulation of the argument Field leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.8 is able to address this issue. The patch is named 935aceb4c21338633de6d41e13332f7b9db4fa6a. It is recommended to upgrade the affected component.
CVSS 6.3
CVE-2025-57563 WRITEUP MEDIUM
StarNet Communications Corporation FastX <4.1.51 - Path Traversal
A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files.
CVSS 6.5
CVE-2025-57618 WRITEUP HIGH
FastX3 <= 3.3.67 - Unauthenticated Path Traversal and Remote Code Execution
A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the server. By leveraging this vulnerability, it is possible to access the application's configuration files, which contain the secret key used to sign JSON Web Tokens as well as existing JTIs. With this information, an attacker can forge valid JWTs, impersonate the root user, and achieve remote code execution in privileged context via authenticated endpoints.
CVSS 7.3
CVE-2025-57783 WRITEUP MEDIUM
Hiawatha 11.7 - Unauthenticated Request Smuggling via Improper Header Parsing
Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.
CVSS 5.3
CVE-2025-57784 WRITEUP LOW
Hiawatha 11.7 - Timing Attack via Tomahawk Auth strcmp
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
CVSS 3.3
CVE-2025-57785 WRITEUP MEDIUM
Hiawatha Webserver 11.7 - Unauthenticated Double Free in XSLT show_index
A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.
CVSS 6.5
CVE-2025-61962 WRITEUP MEDIUM
fetchmail 5.9.9-6.5.5 - Denial of Service via Malformed SMTP 334 Status Code
In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.
CVSS 5.9