Writeup Exploits

64,811 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-25427 WRITEUP MEDIUM
TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 - Stored Cross-Site Scripting via UPnP Port Mapping Description
A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote attackers to inject arbitrary JavaScript code via the port mapping description. This leads to an execution of the JavaScript payload when the upnp page is loaded.
CVSS 5.4
CVE-2025-25453 WRITEUP MEDIUM
Tenda AC10 V4.0si_V16.03.10.20 - Buffer Overflow via AdvSetMacMtuWan serviceName2
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
CVSS 4.6
CVE-2025-25454 WRITEUP HIGH
Tenda AC10 V4.0si_V16.03.10.20 - Stack-based Buffer Overflow via wanSpeed2
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
CVSS 7.5
CVE-2025-25455 WRITEUP HIGH
Tenda AC10 V4.0si_V16.03.10.20 - Stack-based Buffer Overflow via wanMTU2
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
CVSS 7.5
CVE-2025-25456 WRITEUP CRITICAL
Tenda AC10 V4.0si_V16.03.10.20 - Buffer Overflow via AdvSetMacMtuWan mac2 Parameter
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
CVSS 9.8
CVE-2025-25457 WRITEUP HIGH
Tenda AC10 V4.0si_V16.03.10.20 - Stack-based Buffer Overflow via cloneType2
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.
CVSS 7.5
CVE-2025-25458 WRITEUP MEDIUM
Tenda AC10 V4.0si_V16.03.10.20 - Buffer Overflow via AdvSetMacMtuWan serverName2
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
CVSS 4.6
CVE-2025-25579 WRITEUP CRITICAL
TOTOLINK A3002R V4.0.0-B20230531.1404 - OS Command Injection via bandstr Parameter
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
CVSS 9.8
CVE-2025-25612 WRITEUP HIGH
FS Inc S3150-8T2F <S3150-8T2F_2.2.0D_135103 - XSS
FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the "Time Range Name" field, which is improperly sanitized. When this input is saved, it is later executed in the browser of any user accessing the affected page, including administrators, resulting in arbitrary script execution in the user's browser.
CVSS 7.1
CVE-2025-46204 WRITEUP MEDIUM
Unifiedtransform v2.0 - Privilege Escalation
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
CVSS 6.5
CVE-2025-46203 WRITEUP MEDIUM
Unifiedtransform 2.0 - Privilege Escalation via /students/edit/{id} Endpoint
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
CVSS 6.5
CVE-2025-25621 WRITEUP MEDIUM
Unifiedtransform 2.0 - Incorrect Access Control via Teacher Attendance Endpoint
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.
CVSS 4.3
CVE-2025-25620 WRITEUP MEDIUM
Unifiedtransform 2.0 - Cross-Site Scripting in Create Assignment Function
Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.
CVSS 5.4
CVE-2025-25618 WRITEUP LOW
Unifiedtransform 2.0 - Privilege Escalation via Incorrect Access Control
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.
CVSS 3.3
CVE-2025-25617 WRITEUP MEDIUM
Unifiedtransform 2.X - Privilege Escalation
Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.
CVSS 4.3
CVE-2025-25616 WRITEUP MEDIUM
Unifiedtransform 2.0 - Improper Access Control via Exam Rule Edit Endpoint
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.
CVSS 4.3
CVE-2025-25615 WRITEUP LOW
Unifiedtransform 2.0 - Improper Access Control
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.
CVSS 2.7
CVE-2025-25614 WRITEUP HIGH
Unifiedtransform 2.0 - Privilege Escalation via Incorrect Access Control
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.
CVSS 8.8
CVE-2025-25650 WRITEUP CRITICAL
Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 - Info Disclosure
An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.
CVSS 9.1
CVE-2025-25724 WRITEUP MEDIUM
libarchive < 3.7.7 - Denial of Service via Crafted TAR Archive with Verbose Mode
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
CVSS 4.0
CVE-2025-25763 WRITEUP CRITICAL
crmeb CRMEB-KY < 5.4.0 - SQL Injection via getRead() in SystemDatabackupServices.php
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
CVSS 9.8
CVE-2025-25763 WRITEUP CRITICAL
crmeb CRMEB-KY < 5.4.0 - SQL Injection via getRead() in SystemDatabackupServices.php
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
CVSS 9.8
CVE-2025-25953 WRITEUP MEDIUM
Academia Student Information System EagleR 1.0.118 - Authenticated Privilege Escalation via Azure JWT Token Exposure
Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive information.
CVSS 6.5
CVE-2025-25953 WRITEUP MEDIUM
Academia Student Information System EagleR 1.0.118 - Authenticated Privilege Escalation via Azure JWT Token Exposure
Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive information.
CVSS 6.5
CVE-2025-25952 WRITEUP MEDIUM
Academia Student Information System EagleR 1.0.118 - Authorization Bypass via getStudemtAllDetailsById API
An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information via a crafted API request.
CVSS 6.5