Writeup Exploits

65,295 exploits tracked across all sources.

Sort: Activity Stars
CVE-2026-5752 WRITEUP CRITICAL
cohere-terrarium all - Privilege Escalation
Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal.
CVSS 9.3
CVE-2026-5121 WRITEUP HIGH
Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
CVSS 7.5
CVE-2026-4786 WRITEUP HIGH
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVSS 7.1
CVE-2025-63939 WRITEUP CRITICAL
Grocery Store Management System 1.0 - SQL Injection
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.
CVSS 9.8
CVE-2025-65132 WRITEUP MEDIUM
hotel-management-php 1.0 - Cross-Site Scripting via room_id GET Parameter
alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which allows an attacker to inject and execute arbitrary JavaScript via the room_id GET parameter.
CVSS 6.1
CVE-2025-65133 WRITEUP CRITICAL
School Management System 1.0 - SQL Injection
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information.
CVSS 9.8
CVE-2025-65134 WRITEUP MEDIUM
School-management-system 1.0 - Reflected Cross-Site Scripting via Email POST Parameter
In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the email POST parameter.
CVSS 6.1
CVE-2025-65135 WRITEUP CRITICAL
School-management-system 1.0 - SQL Injection
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.
CVSS 9.8
CVE-2025-65136 WRITEUP MEDIUM
School-management-system 1.0 - Reflected Cross-Site Scripting via pagedes POST Parameter
In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter.
CVSS 6.1
CVE-2025-70023 WRITEUP CRITICAL
transloadit uppy v0.25.6 - Type Confusion
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
CVSS 9.8
CVE-2025-70023 WRITEUP CRITICAL
transloadit uppy v0.25.6 - Type Confusion
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
CVSS 9.8
CVE-2026-30480 WRITEUP MEDIUM
LibreNMS 22.11.0-23-gd091788f2 - LFI
A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.
CVSS 6.5
CVE-2026-31049 WRITEUP CRITICAL
Hostbill 2025-11-24/2025-12-01 - Privilege Escalation
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
CVSS 9.8
CVE-2026-37589 WRITEUP LOW
Storage Unit Rental Management System 1.0 - SQL Injection
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.
CVSS 2.7
CVE-2026-37590 WRITEUP LOW
Storage Unit Rental Management System 1.0 - SQL Injection
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.
CVSS 2.7
CVE-2026-37591 WRITEUP LOW
Storage Unit Rental Management System 1.0 - SQL Injection
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php.
CVSS 2.7
CVE-2026-37592 WRITEUP LOW
Storage Unit Rental Management System 1.0 - SQL Injection
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php.
CVSS 2.7
CVE-2026-37593 WRITEUP LOW
Online Employees Work From Home Attendance System 1.0 - SQL Injection
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.
CVSS 2.7
CVE-2026-37594 WRITEUP LOW
Online Employees Work From Home Attendance System 1.0 - SQL Injection
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php.
CVSS 2.7
CVE-2026-37595 WRITEUP LOW
Online Employees Work From Home Attendance System 1.0 - SQL Injection
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.
CVSS 2.7
CVE-2026-37596 WRITEUP LOW
Online Employees Work From Home Attendance System 1.0 - SQL Injection
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php.
CVSS 2.7
CVE-2026-37597 WRITEUP LOW
Online Employees Work From Home Attendance System 1.0 - SQL Injection
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php.
CVSS 2.7
CVE-2026-37598 WRITEUP LOW
Patient Appointment Scheduler System 1.0 - RCE
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings.
CVSS 2.7
CVE-2026-37600 WRITEUP LOW
Patient Appointment Scheduler System 1.0 - SQL Injection
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.
CVSS 2.7
CVE-2026-37601 WRITEUP LOW
Patient Appointment Scheduler System 1.0 - SQL Injection
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php.
CVSS 2.7