Writeup Exploits
64,811 exploits tracked across all sources.
Espressif ESP32 Firmware - Hidden Functionality via Undocumented HCI Commands
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
CVSS 6.8
Digiwin ERP 5.1 - Unrestricted Upload
A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 7.3
Dietiqa 1.0.20 - SQL Injection via Progress Body Weight Endpoint u Parameter
A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.
CVSS 9.8
Edimax BR-6478AC V3 Firmware 1.0.15 - OS Command Injection via formDiskCreateShare foldername Parameter
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.
CVSS 6.5
Edimax BR-6478AC V3 Firmware 1.0.15 - OS Command Injection via Groupname Parameter
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.
CVSS 6.5
Edimax BR-6478AC V3 Firmware 1.0.15 - Stack-based Buffer Overflow via peerPin Parameter
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin parameter in the formWsc function.
CVSS 6.5
Edimax BR-6478AC V3 Firmware 1.0.15 - OS Command Injection via Disk Format Partition Parameter
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.
CVSS 6.5
Edimax BR-6478AC V3 Firmware 1.0.15 - OS Command Injection via fota_url Parameter
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel
CVSS 9.8
Leantime < 3.3.0 - Authenticated Stored Cross-Site Scripting via First Name Field in processMentions()
Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().
CVSS 5.4
Volmarg Personal Management System 1.4.65 - Cross-Site Request Forgery via SameSite Cookie Attribute
Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none
CVSS 4.7
Mydata Ticket Sales Automation < 2025-04-03 - Blind SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection.
This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY).
CVSS 9.8
D-Link DIR-823x Firmware - Remote Code Execution via Function 0x41dda8
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8
CVSS 7.2
D-Link DIR-823x Firmware 240802 - OS Command Injection via target_addr Parameter
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c
CVSS 9.8
D-Link DIR-823x 240802 - OS Command Injection via target_addr Parameter
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c
CVSS 9.8
D-Link DIR-823x Firmware - OS Command Injection via macaddr Parameter
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c
CVSS 9.8
D-Link DIR-823x Firmware - OS Command Injection via Function 0x417234
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234
CVSS 9.8
Netgear R6100 Firmware V1.0.1.28 - Buffer Overflow via QUERY_STRING
Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via the QUERY_STRING key value
CVSS 9.8
ALFA WiFi CampPro Firmware - Buffer Overflow via newap_text_0 Key Value
Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_text_0 key value
CVSS 9.8
ALFA WiFi CampPro Firmware ALFA_CAMPRO-co-2.29 - Buffer Overflow via GAPSMinute3 Key Value
Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the GAPSMinute3 key value
CVSS 9.8
ALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 - Buffer Overflow via StorageEditUser hiddenIndex
Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the hiddenIndex in the function StorageEditUser
CVSS 9.8
SQLite 3.49.0 - Denial of Service via sqlite3_db_config Integer Overflow
In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.
CVSS 5.6
Motivian Content Management System 41.0.0 - Remote Code Execution via Gallery Images Upload
File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component.
CVSS 8.2
Tenda AC8 V16.03.34.06 - Stack-based Buffer Overflow via fromSetRouteStatic Parameter
Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.
CVSS 9.8
Tenda AC7 V15.03.06.44 - Stack-based Buffer Overflow via formWifiBasicSet Security Parameter
A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.
CVSS 9.8
Swagger Petstore 1.0.7 - Remote Code Execution via DELETE Endpoint
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
CVSS 6.5
By Source