Exploit Database
153,618 exploits tracked across all sources.
Kentico Xperience 10.0-10.0.50 - Cross-Site Scripting via Crafted URL
Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a system page.
CVSS 5.4
Kentico Xperience 10.0-10.0.50 - Authenticated SQL Injection
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
CVSS 7.2
SquirrelMail 1.4.22 - Path Traversal
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.
CVSS 8.8
TNLSoftSolutions Sentry Vision 3.x - Unauthenticated Password Disclosure via Client-Side Authentication
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.
CVSS 9.8
Foxconn AP-FC4064-T Firmware - Stored Cross-Site Scripting via User Account Configuration
Cross Site Scripting (XSS) exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via the configuration of a user account. An attacker can execute arbitrary script on an unsuspecting user's browser.
CVSS 5.4
Foxconn AP-FC4064-T Firmware - Use of Hard-coded Credentials and Privilege Escalation via Cookie Manipulation
A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One can gain privileges by modifying cookies.
CVSS 9.8
Twonky Server < 8.5.1 - Cross-Site Scripting via Shared Folders Screen
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
CVSS 6.1
Twonky Server < 8.5.1 - Cross-Site Scripting via Language Parameter
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
CVSS 6.1
FiberHome VDSL2 Modem HG 150-UB Firmware - Authentication Bypass via JavaScript Location Ignore
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
CVSS 9.8
CMS Made Simple 2.2.7 - Path Traversal via Admin Checksum Endpoint
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an admin/checksum.php?__c= request.
CVSS 5.3
Frog CMS 0.9.5 - Cross-Site Scripting via Admin User Add Name or Username Parameter
Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter.
CVSS 4.8
Frog CMS 0.9.5 - Stored Cross-Site Scripting via File Manager Name Field
Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen.
CVSS 4.8
zzcms < 8.3 - SQL Injection
zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.
CVSS 9.8
zzcms < 8.3 - File Deletion to Remote Code Execution via user/licence_save.php
zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.
CVSS 9.8
zzcms < 8.3 - Unauthenticated File Deletion and Remote Code Execution via /user/zssave.php
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php.
CVSS 9.8
zzcms zzmcms < 8.3 - Path Traversal and Arbitrary File Deletion via ppsave.php
zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php.
CVSS 9.8
zzcms < 8.3 - Unauthenticated File Deletion and Remote Code Execution via user/manage.php
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80.
CVSS 9.8
zzcms < 8.3 - SQL Injection via zs/subzs.php
zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.
CVSS 9.8
LineageOS <16.0 - Incorrect Access Control
LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` can also be set in a normal adb shell session. The component is: adb shell (patches to fix this are at https://review.lineageos.org/c/LineageOS/android_system_core/+/234800, https://review.lineageos.org/c/LineageOS/android_device_lineage_sepolicy/+/234799). The attack vector is: When adb is enabled, and an attacker has physical access, `adb shell setprop service.adb.root 1` allows restarting adb as root.
CVSS 6.8
SUNNET WMPro 5.0-5.1 - Unauthenticated OS Command Injection via doajaxfileupload.php
The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
CVSS 9.8
androvideo vd_1_firmware < 230 - Unauthenticated Remote Credential Disclosure via ExportSettings.cgi
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication.
CVSS 9.8
BiYan 1.57-2.8 - Unauthenticated User Information Leak via EMP_NO Parameter
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.
CVSS 9.8
BiYan 1.57-2.8 - Unauthenticated Exposure of Sensitive Information via Login Info Endpoint
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element to the auth/main/asp/check_user_login_info.aspx URI, and then reading the response, as demonstrated by the KW_EMAIL or KW_TEL field.
CVSS 7.5
Hisilicon HI3516 Firmware - Unauthenticated Remote Code Execution via RTSP over HTTP Packet
A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using hisilicon's hardware and software, as demonstrated by TENVIS cameras 1.3.3.3, 1.2.7.2, 1.2.1.4, 7.1.20.1.2, and 13.1.1.1.7.2; FDT FD7902 11.3.14.1.3 and 10.3.14.1.3; FOSCAM cameras 3.2.1.1.1_0815 and 3.2.2.2.1_0815; and Dericam cameras V11.3.8.1.12.
CVSS 9.8
Hanwah Techwin SRN-472s <1.07_190502 - Buffer Overflow
An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.
CVSS 7.5
By Source