Writeup Exploits

64,811 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-25952 WRITEUP MEDIUM
Academia Student Information System EagleR 1.0.118 - Authorization Bypass via getStudemtAllDetailsById API
An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information via a crafted API request.
CVSS 6.5
CVE-2025-25951 WRITEUP HIGH
Academia Student Information System EagleR 1.0.118 - Exposure of Sensitive Information via /rest/cb/executeBasicSearch
An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.
CVSS 7.5
CVE-2025-25951 WRITEUP HIGH
Academia Student Information System EagleR 1.0.118 - Exposure of Sensitive Information via /rest/cb/executeBasicSearch
An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.
CVSS 7.5
CVE-2025-25950 WRITEUP HIGH
Academia Student Information System EagleR 1.0.118 - Improper Access Control in /rest/staffResource/update
Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
CVSS 8.1
CVE-2025-25950 WRITEUP HIGH
Academia Student Information System EagleR 1.0.118 - Improper Access Control in /rest/staffResource/update
Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
CVSS 8.1
CVE-2025-25949 WRITEUP MEDIUM
Academia Student Information System EagleR 1.0.118 - Stored Cross-Site Scripting via User ID Parameter
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.
CVSS 5.4
CVE-2025-25949 WRITEUP MEDIUM
Academia Student Information System EagleR 1.0.118 - Stored Cross-Site Scripting via User ID Parameter
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.
CVSS 5.4
CVE-2025-25948 WRITEUP CRITICAL
Academia Student Information System EagleR 1.0.118 - Improper Access Control in Staff Resource Creation
Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
CVSS 9.1
CVE-2025-25948 WRITEUP CRITICAL
Academia Student Information System EagleR 1.0.118 - Improper Access Control in Staff Resource Creation
Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
CVSS 9.1
CVE-2024-53636 WRITEUP MEDIUM
Serosoft Academia Student Information System EagleR-1.0.118 - Arbitrary File Upload via writefile.php filePath Parameter
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.
CVSS 6.4
CVE-2025-25983 WRITEUP LOW
Macro-video Technologies Co.,Ltd V380 Pro <2.1.64 - Info Disclosure
An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.
CVSS 3.4
CVE-2025-25984 WRITEUP MEDIUM
Macro-video Technologies Co.,Ltd V380E6_C1 - RCE
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.
CVSS 6.8
CVE-2025-25985 WRITEUP LOW
Macro-video Technologies Co.,Ltd V380E6_C1 IP camera - RCE
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini components.
CVSS 2.6
CVE-2025-2539 WRITEUP HIGH
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.
CVSS 7.5
CVE-2025-2512 WRITEUP CRITICAL
File Away < 3.9.9.0.1 - Unauthenticated Arbitrary File Upload via upload() Function
The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the upload() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVSS 9.8
CVE-2025-2582 WRITEUP LOW
SimpleMachines SMF 2.1.4 - Cross-Site Scripting in ManageAttachments.php
A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The manipulation of the argument Notice leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor does not declare this issue a security vulnerability due to authentication requirements before being able to access any feature in the software that allows file modification.
CVSS 3.5
CVE-2025-2583 WRITEUP LOW
SimpleMachines SMF 2.1.4 - Cross-Site Scripting in ManageNews.php
A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php. The manipulation of the argument subject/message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor does not declare this issue a security vulnerability due to authentication requirements before being able to access any feature in the software that allows file modification.
CVSS 3.5
CVE-2025-26001 WRITEUP HIGH
Telesquare TLR-2005KSH 1.1.4 - Information Disclosure via getUserNamePassword Parameter
Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.
CVSS 7.5
CVE-2025-26002 WRITEUP CRITICAL
Telesquare TLR-2005KSH 1.1.4 - Unauthenticated Stack Overflow via admin.cgi setSyncTimeHost Parameter
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.
CVSS 9.8
CVE-2025-26074 WRITEUP CRITICAL
Conductor Core < 3.21.13 - Remote Code Execution via Java Class Access
Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.
CVSS 9.8
CVE-2025-26125 WRITEUP HIGH
IObit Malware Fighter <12.1.0 - Privilege Escalation
An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.
CVSS 7.3
CVE-2025-26153 WRITEUP MEDIUM
Chamilo LMS 1.11.28 - Stored Cross-Site Scripting in Message Compose Feature
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.
CVSS 5.4
CVE-2025-26159 WRITEUP MEDIUM
laravel-starter < 11.11.0 - Stored Cross-Site Scripting in Tags Feature
Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.
CVSS 6.1
CVE-2025-26198 WRITEUP CRITICAL
CloudClassroom-PHP-Project v1.0 - Unauthenticated SQL Injection via Admin Login Username Field
CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and bypass authentication, gaining unauthorized administrative access. The vulnerability is triggered when an attacker supplies specially crafted input in the username field, such as ' OR '1'='1, leading to complete compromise of the login mechanism and potential exposure of sensitive backend data.
CVSS 9.8
CVE-2025-26198 WRITEUP CRITICAL
CloudClassroom-PHP-Project v1.0 - Unauthenticated SQL Injection via Admin Login Username Field
CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and bypass authentication, gaining unauthorized administrative access. The vulnerability is triggered when an attacker supplies specially crafted input in the username field, such as ' OR '1'='1, leading to complete compromise of the login mechanism and potential exposure of sensitive backend data.
CVSS 9.8