Writeup Exploits

64,737 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-4511 WRITEUP MEDIUM
Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4 - Buffe...
A vulnerability classified as critical has been found in Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4. This affects an unknown part of the component Message Handler. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263115. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 6.3
CVE-2024-46073 WRITEUP MEDIUM
IceHRM 32.4.0.OS - Reflected Cross-Site Scripting via Login Page Next Parameter
A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place.
CVSS 6.1
CVE-2022-25015 WRITEUP MEDIUM
icehrm 30.0.0.OS - Stored Cross-Site Scripting via First Name Field
A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field.
CVSS 5.4
CVE-2022-25014 WRITEUP MEDIUM
icehrm 30.0.0.OS - Reflected Cross-Site Scripting via Dashboard m Parameter
Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session credentials via user interaction with a crafted link.
CVSS 6.1
CVE-2022-25013 WRITEUP MEDIUM
icehrm 30.0.0.OS - Reflected Cross-Site Scripting via Key and fm Parameters
Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php.
CVSS 6.1
CVE-2018-12420 WRITEUP HIGH
IceHrm <23.0.1.OS - Info Disclosure
IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
CVSS 7.5
CVE-2024-46076 WRITEUP CRITICAL
RuoYi < 4.7.9 - Code Injection via Code Generation Feature
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.
CVSS 9.8
CVE-2024-46209 WRITEUP MEDIUM
REDAXO CMS 5.17.1 - Stored Cross-Site Scripting via Password Parameter in /media/test.html
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.
CVSS 5.4
CVE-2024-46209 WRITEUP MEDIUM
REDAXO CMS 5.17.1 - Stored Cross-Site Scripting via Password Parameter in /media/test.html
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.
CVSS 5.4
CVE-2024-46210 WRITEUP HIGH
Redaxo CMS 5.17.1 - Arbitrary File Upload and Remote Code Execution via MediaPool Module
An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.
CVSS 7.2
CVE-2024-46215 WRITEUP MEDIUM
KM08-708H-v1.1 - Buffer Overflow in sub_445BDC Function via strcpy
A vulnerability was discovered in KM08-708H-v1.1, There is a buffer overflow in the sub_445BDC() function within the /usr/sbin/goahead program; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.
CVSS 6.5
CVE-2024-46237 WRITEUP MEDIUM
PHPGurukul Hospital Management System 4.0 - Stored Cross-Site Scripting via patname, pataddress, and medhis Parameters
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
CVSS 5.4
CVE-2024-46258 WRITEUP HIGH
cute_png v1.05 - Heap Buffer Overflow in cp_load_png_mem()
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.
CVSS 7.8
CVE-2024-46259 WRITEUP HIGH
cute_png v1.05 - Heap Buffer Overflow in cp_unfilter()
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.
CVSS 7.8
CVE-2024-46261 WRITEUP HIGH
cute_png v1.05 - Heap Buffer Overflow in cp_make32()
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
CVSS 7.8
CVE-2024-46263 WRITEUP HIGH
cute_png v1.05 - Stack Overflow in cp_dynamic()
cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.
CVSS 7.8
CVE-2024-46264 WRITEUP HIGH
cute_png v1.05 - Heap-based Buffer Overflow via cp_find()
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.
CVSS 7.8
CVE-2024-46267 WRITEUP HIGH
cute_png v1.05 - Heap Buffer Overflow in cp_block()
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.
CVSS 7.8
CVE-2024-46274 WRITEUP HIGH
cute_png v1.05 - Heap Buffer Overflow in cp_stored()
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.
CVSS 7.8
CVE-2024-46276 WRITEUP HIGH
cute_png v1.05 - Heap Buffer Overflow in cp_chunk Function
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.
CVSS 7.8
CVE-2024-46278 WRITEUP HIGH
Teedy 1.11 - Cross-Site Scripting via Management Console
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
CVSS 8.4
CVE-2024-46377 WRITEUP CRITICAL
Best House Rental Management System 1.0 - Arbitrary File Upload via save_settings() Function
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.
CVSS 9.8
CVE-2024-46451 WRITEUP CRITICAL
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 - Buffer Overflow in setWiFiAclRules via desc Parameter
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.
CVSS 9.8
CVE-2024-46452 WRITEUP MEDIUM
VigyBag Open Source Online Shop <commit 3f0e21b - SSRF
A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b allows attackers to redirect victim users to a malicious site via a crafted URL.
CVSS 6.1
CVE-2024-46479 WRITEUP CRITICAL
Venki Supravizio BPM <= 18.0.1 - Authenticated Arbitrary File Upload and Remote Code Execution
Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.
CVSS 9.9