Writeup Exploits

64,734 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-44408 WRITEUP HIGH
D-Link DIR-823G v1.0.2B05_20181207 - Unauthenticated Information Disclosure via Configuration File Download
D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.
CVSS 7.5
CVE-2024-44410 WRITEUP CRITICAL
D-Link DI-8300 v16.07.26A1 - OS Command Injection via upgrade_filter_asp Function
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
CVSS 9.8
CVE-2024-44411 WRITEUP CRITICAL
D-Link DI-8300 v16.07.26A1 - OS Command Injection via msp_info_htm Function
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
CVSS 9.8
CVE-2024-44413 WRITEUP HIGH
DI_8200-16.07.26A1 - Command Injection
A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
CVSS 8.8
CVE-2024-44414 WRITEUP HIGH
FBM_292W-21.03.10V - Command Injection
A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_info.htm file. Manipulation of the path parameter can lead to command injection.
CVSS 8.8
CVE-2024-44415 WRITEUP MEDIUM
DI_8200-16.07.26A1 - Buffer Overflow
A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.
CVSS 6.5
CVE-2024-44450 WRITEUP MEDIUM
AIMS eCrew - Authorization Bypass Through User-Controlled Key
Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.
CVSS 5.4
CVE-2024-44541 WRITEUP CRITICAL
evilnapsis Inventio Lite <v4 - SQL Injection
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."
CVSS 9.8
CVE-2024-44541 WRITEUP CRITICAL
evilnapsis Inventio Lite <v4 - SQL Injection
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."
CVSS 9.8
CVE-2024-44542 WRITEUP CRITICAL
todesk 1.1 - SQL Injection via News Parameter
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.
CVSS 9.8
CVE-2024-44546 WRITEUP CRITICAL
Powerjob >= 3.2.0 - SQL Injection via Version Parameter
Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.
CVSS 9.8
CVE-2024-44734 WRITEUP HIGH
Mirotalk <9de226 - Privilege Escalation
Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.
CVSS 7.5
CVE-2024-44731 WRITEUP MEDIUM
Mirotalk - DOM-based Cross-Site Scripting via RTC Message Payload
Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.
CVSS 4.7
CVE-2024-44730 WRITEUP CRITICAL
Mirotalk - Incorrect Access Control in handleDataChannelChat Function
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
CVSS 9.1
CVE-2024-44729 WRITEUP HIGH
Mirotalk <9de226 - Privilege Escalation
Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.
CVSS 7.5
CVE-2023-27054 WRITEUP MEDIUM
MiroTalk P2P < 2023-02-18 - Cross-Site Scripting via Name Parameter in Settings Module
A cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the settings module.
CVSS 6.1
CVE-2023-27054 WRITEUP MEDIUM
MiroTalk P2P < 2023-02-18 - Cross-Site Scripting via Name Parameter in Settings Module
A cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the settings module.
CVSS 6.1
CVE-2024-44756 WRITEUP CRITICAL
NUS-M9 ERP Mgmt SW v3.0.0 - SQL Injection
NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.
CVSS 9.8
CVE-2024-44757 WRITEUP HIGH
NUS-M9 ERP Mgmt <3.0.0 - Info Disclosure
An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.
CVSS 7.5
CVE-2024-44758 WRITEUP CRITICAL
NUS-M9 ERP Management Software <3.0.0 - Code Injection
An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.
CVSS 9.8
CVE-2024-44759 WRITEUP HIGH
NUS-M9 ERP Mgmt <3.0.0 - Info Disclosure
An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.
CVSS 7.5
CVE-2024-44760 WRITEUP HIGH
Shenzhou News Union Enterprise Management System <18.8 - Incorrect Access Control
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.
CVSS 7.5
CVE-2024-44761 WRITEUP CRITICAL
EQ Enterprise Management System <2.0.0 - Path Traversal
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
CVSS 9.8
CVE-2024-44765 WRITEUP MEDIUM
MGT-COMMERCE GmbH CloudPanel <2.4.2 - Auth Bypass
An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality.
CVSS 6.5
CVE-2024-44825 WRITEUP HIGH
InVesalius3 <3.1.99995 - Path Traversal
Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.
CVSS 7.5