Writeup Exploits

64,858 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-9728 WRITEUP MEDIUM
Vvveb 1.0.7.2 - Cross-Site Scripting via Email/Password Argument
A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue.
CVSS 4.3
CVE-2025-9728 WRITEUP MEDIUM
Vvveb 1.0.7.2 - Cross-Site Scripting via Email/Password Argument
A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue.
CVSS 4.3
CVE-2025-9745 WRITEUP MEDIUM
D-Link DI-500WF 14.04.10A1T - Code Injection
A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
CVSS 4.7
CVE-2025-9749 WRITEUP HIGH
Grocery List Management Web App < 2025-08-23 - SQL Injection via ID Parameter in update.php
A vulnerability was identified in HKritesh009 Grocery List Management Web App up to f491b681eb70d465f445c9a721415c965190f83b. This affects an unknown part of the file /src/update.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
CVSS 7.3
CVE-2025-9758 WRITEUP MEDIUM
deepakmisal24 Chemical Inventory Management System < 1.0 - SQL Injection via chem_name Parameter
A vulnerability was identified in deepakmisal24 Chemical Inventory Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory_form.php. Such manipulation of the argument chem_name leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
CVSS 6.3
CVE-2025-9760 WRITEUP MEDIUM
Portabilis i-educar < 2.10.0 - Incorrect Privilege Assignment in Matricula API
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Matricula API. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.
CVSS 6.3
CVE-2025-9769 WRITEUP MEDIUM
D-Link DI-7400G+ 19.12.25A1 - OS Command Injection via mng_platform.asp addr Parameter
A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.
CVSS 4.1
CVE-2025-9778 WRITEUP LOW
Tenda W12 <3.0.0.6 - Hard-Coded Credentials
A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. The manipulation leads to hard-coded credentials. An attack has to be approached locally. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.
CVSS 1.9
CVE-2025-9779 WRITEUP HIGH
TOTOLINK A702R 4.0.0-B20211108.1423 - Buffer Overflow via formFilter ip6addr Argument
A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_4162DC of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.
CVSS 8.8
CVE-2025-9780 WRITEUP HIGH
TOTOLINK A702R 4.0.0-B20211108.1423 - Buffer Overflow via formIpQoS mac Parameter
A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the file /boafrm/formIpQoS. This manipulation of the argument mac causes buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.
CVSS 8.8
CVE-2025-9781 WRITEUP HIGH
TOTOLINK A702R 4.0.0-B20211108.1423 - Buffer Overflow via formFilter ip6addr Argument
A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file /boafrm/formFilter. Such manipulation of the argument ip6addr leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 8.8
CVE-2025-9782 WRITEUP HIGH
TOTOLINK A702R 4.0.0-B20211108.1423 - Buffer Overflow via formOneKeyAccessButton submit-url Argument
A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAccessButton. Performing manipulation of the argument submit-url results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.
CVSS 8.8
CVE-2025-9783 WRITEUP HIGH
TOTOLINK A702R 4.0.0-B20211108.1423 - Buffer Overflow via Parent Control Form Submit-URL
A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentControl. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVSS 8.8
CVE-2025-9791 WRITEUP HIGH
Tenda AC20 16.03.08.05 - Stack-Based Buffer Overflow via wanMTU Parameter
A weakness has been identified in Tenda AC20 16.03.08.05. This vulnerability affects unknown code of the file /goform/fromAdvSetMacMtuWan. This manipulation of the argument wanMTU causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
CVSS 8.8
CVE-2025-9806 WRITEUP LOW
Tenda F1202 <1.2.0.20 - Info Disclosure
A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.
CVSS 1.9
CVE-2025-9810 WRITEUP MEDIUM
linenoise - Time-of-check Time-of-use Race Condition in linenoiseHistorySave
TOCTOU  in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path and subsequent chmod() on the same path.
CVSS 6.8
CVE-2025-9815 WRITEUP HIGH
alaneuler batteryKid < 2.1 - Improper Authentication in NSXPCListener
A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.
CVSS 7.8
CVE-2025-9934 WRITEUP MEDIUM
TOTOLINK X5000R 9.1.0cu.2415_B20250515 - OS Command Injection via pid Parameter
A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
CVSS 6.3
CVE-2026-0571 WRITEUP MEDIUM
yeqifu warehouse < 2025-10-06 - Path Traversal via createResponseEntity
A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function createResponseEntity of the file warehouse\src\main\java\com\yeqifu\sys\common\AppFileUtils.java. The manipulation of the argument path results in path traversal. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
CVSS 4.3
CVE-2026-0574 WRITEUP MEDIUM
yeqifu warehouse <aaf29962ba407d22d991781de28796ee7b4670e4 - Privil...
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java of the component Request Handler. This manipulation causes improper authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.
CVSS 6.3
CVE-2026-0575 WRITEUP HIGH
Online Product Reservation System 1.0 - SQL Injection via Administrator Login Email/Password Parameters
A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unknown function of the file /handgunner-administrator/adminlogin.php of the component Administrator Login. Such manipulation of the argument emailadd/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
CVSS 7.3
CVE-2026-0576 WRITEUP HIGH
Online Product Reservation System 1.0 - SQL Injection via Parameter Handler
A vulnerability was detected in code-projects Online Product Reservation System 1.0. Affected is an unknown function of the file /handgunner-administrator/prod.php of the component Parameter Handler. Performing a manipulation of the argument cat/price/name/model/serial results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
CVSS 7.3
CVE-2026-0577 WRITEUP MEDIUM
Online Product Reservation System 1.0 - Unrestricted File Upload in prod.php
A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /handgunner-administrator/prod.php. Executing a manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used.
CVSS 6.3
CVE-2026-0578 WRITEUP HIGH
Online Product Reservation System 1.0 - SQL Injection via /handgunner-administrator/delete.php ID Parameter
A vulnerability has been found in code-projects Online Product Reservation System 1.0. Affected by this issue is some unknown functionality of the file /handgunner-administrator/delete.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 7.3
CVE-2026-0579 WRITEUP HIGH
Online Product Reservation System 1.0 - SQL Injection via POST Parameter Handler
A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the file /handgunner-administrator/edit.php of the component POST Parameter Handler. The manipulation of the argument prod_id/name/price/model/serial results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
CVSS 7.3