Writeup Exploits

60,504 exploits tracked across all sources.

Sort: Activity Stars
CVE-2026-3977 WRITEUP MEDIUM
projectsend < r1945 - Missing Authorization in AJAX Endpoints
A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation leads to missing authorization. The attack can be initiated remotely. The identifier of the patch is 35dfd6f08f7d517709c77ee73e57367141107e6b. To fix this issue, it is recommended to deploy a patch.
CVSS 6.3
CVE-2025-13232 WRITEUP LOW
ProjectSend < r1720 - Cross-Site Scripting in File Editor/Custom Download Aliases
A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Download Aliases. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version r1945 is recommended to address this issue. Patch name: 334da1ea39cb12f6b6e98dd2f80bb033e0c7b845. It is advisable to upgrade the affected component.
CVSS 3.5
CVE-2026-3978 WRITEUP HIGH
D-Link DIR-513 1.10 - Buffer Overflow
A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formEasySetupWizard3. The manipulation of the argument wan_connected results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.
CVSS 8.8
CVE-2026-1145 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_constructor_ta
A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 53aebe66170d545bb6265906fe4324e4477de8b4. It is suggested to install a patch to address this issue.
CVSS 6.3
CVE-2026-1145 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_constructor_ta
A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 53aebe66170d545bb6265906fe4324e4477de8b4. It is suggested to install a patch to address this issue.
CVSS 6.3
CVE-2026-1145 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_constructor_ta
A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 53aebe66170d545bb6265906fe4324e4477de8b4. It is suggested to install a patch to address this issue.
CVSS 6.3
CVE-2026-1144 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Use-After-Free in Atomics Ops Handler
A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.
CVSS 6.3
CVE-2026-1144 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Use-After-Free in Atomics Ops Handler
A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.
CVSS 6.3
CVE-2026-1144 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Use-After-Free in Atomics Ops Handler
A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.
CVSS 6.3
CVE-2026-0822 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_sort
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 53eefbcd695165a3bd8c584813b472cb4a69fbf5. To fix this issue, it is recommended to deploy a patch.
CVSS 6.3
CVE-2026-0822 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_sort
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 53eefbcd695165a3bd8c584813b472cb4a69fbf5. To fix this issue, it is recommended to deploy a patch.
CVSS 6.3
CVE-2026-0822 WRITEUP MEDIUM
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_sort
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 53eefbcd695165a3bd8c584813b472cb4a69fbf5. To fix this issue, it is recommended to deploy a patch.
CVSS 6.3
CVE-2026-0821 WRITEUP HIGH
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_constructor
A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called c5d80831e51e48a83eab16ea867be87f091783c5. A patch should be applied to remediate this issue.
CVSS 7.3
CVE-2026-0821 WRITEUP HIGH
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_constructor
A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called c5d80831e51e48a83eab16ea867be87f091783c5. A patch should be applied to remediate this issue.
CVSS 7.3
CVE-2026-0821 WRITEUP HIGH
quickjs-ng quickjs < 0.11.0 - Heap-Based Buffer Overflow in js_typed_array_constructor
A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called c5d80831e51e48a83eab16ea867be87f091783c5. A patch should be applied to remediate this issue.
CVSS 7.3
CVE-2025-46688 WRITEUP MEDIUM
QuickJS <2025-04-26 - Buffer Overflow
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
CVSS 5.6
CVE-2025-46688 WRITEUP MEDIUM
QuickJS <2025-04-26 - Buffer Overflow
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
CVSS 5.6
CVE-2025-46687 WRITEUP MEDIUM
QuickJS <2025-04-26 - Buffer Overflow
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
CVSS 5.6
CVE-2025-46687 WRITEUP MEDIUM
QuickJS <2025-04-26 - Buffer Overflow
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
CVSS 5.6
CVE-2024-13903 WRITEUP MEDIUM
quickjs-ng QuickJS < 0.9.0 - Stack-Based Buffer Overflow in JS_GetRuntime
A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c of the component qjs. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. Upgrading to version 0.9.0 is able to address this issue. The patch is named 99c02eb45170775a9a679c32b45dd4000ea67aff. It is recommended to upgrade the affected component.
CVSS 4.3
CVE-2024-13903 WRITEUP MEDIUM
quickjs-ng QuickJS < 0.9.0 - Stack-Based Buffer Overflow in JS_GetRuntime
A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c of the component qjs. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. Upgrading to version 0.9.0 is able to address this issue. The patch is named 99c02eb45170775a9a679c32b45dd4000ea67aff. It is recommended to upgrade the affected component.
CVSS 4.3
CVE-2026-3979 WRITEUP MEDIUM
quickjs-ng quickjs <=0.12.1 - Use After Free
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the recommended action to fix this issue.
CVSS 5.3
CVE-2026-3979 WRITEUP MEDIUM
quickjs-ng quickjs <=0.12.1 - Use After Free
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the recommended action to fix this issue.
CVSS 5.3
CVE-2026-3979 WRITEUP MEDIUM
quickjs-ng quickjs <=0.12.1 - Use After Free
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the recommended action to fix this issue.
CVSS 5.3
CVE-2026-3979 WRITEUP MEDIUM
quickjs-ng quickjs <=0.12.1 - Use After Free
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the recommended action to fix this issue.
CVSS 5.3