Writeup Exploits

62,344 exploits tracked across all sources.

Sort: Activity Stars
CVE-2026-10282 WRITEUP MEDIUM
Bottelet DaybydayCRM <= 2.2.1 - Incorrect Privilege Assignment in DocumentsController
A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manipulation leads to improper authorization. The attack may be launched remotely. It is best practice to apply a patch to resolve this issue.
CVSS 4.3
CVE-2020-35707 WRITEUP MEDIUM
Daybyday 2.1.0 - Stored Cross-Site Scripting via Company Name Parameter
Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
CVSS 5.4
CVE-2020-35706 WRITEUP MEDIUM
Daybyday 2.1.0 - Stored Cross-Site Scripting via New Project Title Parameter
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
CVSS 5.4
CVE-2020-35705 WRITEUP MEDIUM
daybyday 2.1.0 - Stored Cross-Site Scripting via New User Name Parameter
Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.
CVSS 5.4
CVE-2020-35704 WRITEUP MEDIUM
Daybyday 2.1.0 - Stored Cross-Site Scripting via New Lead Title Parameter
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.
CVSS 5.4
CVE-2026-10285 WRITEUP MEDIUM
DevaslanPHP project-management <= 2.0.0-beta1 - Improper Authorization in KanbanScrumHelper Ticket Handler
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 5.4
CVE-2026-10285 WRITEUP MEDIUM
DevaslanPHP project-management <= 2.0.0-beta1 - Improper Authorization in KanbanScrumHelper Ticket Handler
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 5.4
CVE-2026-10284 WRITEUP MEDIUM
DevaslanPHP project-management <= 2.0.0-beta1 - Incorrect Privilege Assignment in Livewire Handler
A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the component Livewire Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 5.4
CVE-2026-10284 WRITEUP MEDIUM
DevaslanPHP project-management <= 2.0.0-beta1 - Incorrect Privilege Assignment in Livewire Handler
A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the component Livewire Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 5.4
CVE-2025-52203 WRITEUP HIGH
DevaslanPHP project-management 1.2.4 - Authenticated Stored Cross-Site Scripting in Ticket Name Field
A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability resides in the Ticket Name field, which fails to properly sanitize user-supplied input. An authenticated attacker can inject malicious JavaScript payloads into this field, which are subsequently stored in the database. When a legitimate user logs in and is redirected to the Dashboard panel "automatically upon authentication the malicious script executes in the user's browser context.
CVSS 7.6
CVE-2026-10288 WRITEUP HIGH
code-projects Hotel and Tourism Reservation System 1.0 - Improper Authentication via Admin Login Password Parameter
A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
CVSS 7.3
CVE-2026-10289 WRITEUP MEDIUM
Hotel and Tourism Reservation System 1.0 - Cross-Site Scripting via Tour.php Name/Email/People/Number Parameters
A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
CVSS 4.3
CVE-2026-10290 WRITEUP HIGH
Hotel and Tourism Reservation System 1.0 - SQL Injection via tour.php GET Parameter
A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
CVSS 7.3
CVE-2026-10291 WRITEUP MEDIUM
Enderfga claw-orchestrator <= 3.7.0 - Inefficient Regular Expression Complexity in Session Grep Endpoint
A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the component Session Grep Endpoint. The manipulation of the argument body.pattern leads to inefficient regular expression complexity. The attack may be initiated remotely. Upgrading to version 3.7.1 is sufficient to resolve this issue. The identifier of the patch is 3f970a974c65a94555c25af9f2796f11315e4584. It is recommended to upgrade the affected component.
CVSS 4.3
CVE-2026-10292 WRITEUP HIGH
UTT HiPER 1200GW up to 2.5.3-170306 - Stack-Based Buffer Overflow in formTaskEdit
A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
CVSS 8.8
CVE-2026-10293 WRITEUP HIGH
UTT HiPER 1200GW up to 2.5.3-170306 - Stack-Based Buffer Overflow via Profile Argument in formFireWall
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formFireWall. This manipulation of the argument Profile causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVSS 8.8
CVE-2026-10294 WRITEUP MEDIUM
PackageKit <= 1.3.5 - Improper Authorization via Frontend-Socket Argument
A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
CVSS 4.3
CVE-2026-10294 WRITEUP MEDIUM
PackageKit <= 1.3.5 - Improper Authorization via Frontend-Socket Argument
A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
CVSS 4.3
CVE-2026-41651 WRITEUP HIGH
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING. 2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags. 3. Late flag read at execution time (lines 2273–2277): The scheduler's idle callback reads cached_transaction_flags at dispatch time, not at authorization time. If flags were overwritten between authorization and execution, the backend sees the attacker's flags.
CVSS 8.8
CVE-2026-10298 WRITEUP LOW
whisper.cpp <= 1.8.2 - Null Pointer Dereference in whisper_model_load
A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2. This vulnerability affects the function whisper_model_load of the file ggml/src/ggml.c. The manipulation results in null pointer dereference. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.3
CVE-2026-10298 WRITEUP LOW
whisper.cpp <= 1.8.2 - Null Pointer Dereference in whisper_model_load
A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2. This vulnerability affects the function whisper_model_load of the file ggml/src/ggml.c. The manipulation results in null pointer dereference. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 3.3
CVE-2025-14569 WRITEUP MEDIUM
ggml-org whisper.cpp <1.8.2 - Use After Free
A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after free. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 5.3
CVE-2026-10299 WRITEUP LOW
Online Hospital Management System 1.0 - IDOR via viewdoctortimings.php delid Parameter
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVSS 3.8
CVE-2026-37226 WRITEUP HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via E42_RIC_SUBSCRIPTION_REQUEST
FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGABRT) and dereferenced in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the iApp process (port 36422) by sending a subscription request with an arbitrary global_e2_node_id.
CVSS 7.5
CVE-2026-37228 WRITEUP HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via SCTP Message Overflow
FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on the sctp_recvmsg() return value. A remote unauthenticated attacker can send a single SCTP message with payload >= 32,768 bytes to crash the near-RT RIC, iApp, E2 Agent, or xApp process via SIGABRT. No valid E2AP PDU is required. All four SCTP endpoint types (ports 36421 and 36422) share this vulnerable code path. In Release builds (NDEBUG), the stripped assertion leads to a signed-to-unsigned integer overflow and potential out-of-bounds read.
CVSS 7.5