OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 2 March 2026 at 22:11 Topic: OpenClaw tools.exec.safeBins
Google Chrome < 145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free The Exploit Database - CXSecurity.com By: nu11secur1ty 23 February 2026 at 23:18 Topic: Google Chrome
Siklu EtherHaul Series EH-8010 Remote Command Execution The Exploit Database - CXSecurity.com By: semaja2 14 February 2026 at 21:31 Topic: Siklu EtherHaul Series EH-8010 Remote Command Execution Risk: High Text:# Exploit Title:Siklu EtherHaul Series EH-8010 - Remote Command Execution # Shodan Dork: "EH-8010" or "EH-1200" # Date: 2025-...
aiohttp 3.9.1 Directory Traversal The Exploit Database - CXSecurity.com By: Beatriz Fresno Naumova 5 February 2026 at 22:43 Topic: aiohttp 3.9.1 Directory Traversal Risk: Medium Text:# Exploit Title: Python aiohttp directory traversal PoC (CVE-2024-23334) # Google Dork: N/A # Date: 2025-10-06 # Exploit Aut...
deephas < = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 2 February 2026 at 22:14 Topic: deephas
LangChain Core - Serialization Injection to Jinja2 SSTI/RCE The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 26 January 2026 at 20:48 Topic: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE Risk: High Text:# Exploit Title: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE # Date: 2025-12-29 # Exploit Author: Mohammed I...
AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution The Exploit Database - CXSecurity.com By: Valentin 18 January 2026 at 22:49 Topic: AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution Risk: High Text:## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-...
Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure The Exploit Database - CXSecurity.com By: Byte Reaper 28 December 2025 at 11:40 Topic: Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure Risk: Low Text:/* * Exploit Title : Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure * Author : Byte Reaper *...
dotCMS 25.07.02-1 Authenticated Blind SQL Injection The Exploit Database - CXSecurity.com By: Matan Sandori 18 December 2025 at 00:01 Topic: dotCMS 25.07.02-1 Authenticated Blind SQL Injection Risk: Medium Text:#!/usr/bin/env python3 # Exploit Title: dotCMS 25.07.02-1 - Authenticated Blind SQL Injection # Google Dork: N/A # Date: 2...
Mbed TLS 3.6.4 Use-After-Free The Exploit Database - CXSecurity.com By: Byte Reaper 9 December 2025 at 22:45 Topic: Mbed TLS 3.6.4 Use-After-Free Risk: High Text:/* * Exploit Title: Mbed TLS 3.6.4 - Use-After-Free * Google Dork: N/A * Date: 2025-08-29 * Exploit Author: Byte Reaper...
MonstaFTP Unauthenticated File Upload The Exploit Database - CXSecurity.com By: ibrahimsql 1 December 2025 at 17:53 Topic: MonstaFTP Unauthenticated File Upload Risk: Medium Text:# Titles: MonstaFTP Unauthenticated File Upload CVE-2025-34299 # Author: ibrahimsql # Date: 11/21/2025 # Vendor: https://www...
Flowise 3.0.4 Remote Code Execution The Exploit Database - CXSecurity.com By: nltt0 1 November 2025 at 20:53 Topic: Flowise 3.0.4 Remote Code Execution Risk: High Text:# Exploit Title: Flowise 3.0.4 - Remote Code Execution (RCE) # Date: 10/11/2025 # Exploit Author: [nltt0] (https://github.com...
Swagger UI 1.0.3 Cross-Site Scripting (XSS) The Exploit Database - CXSecurity.com By: ByteReaper0 29 October 2025 at 21:23 Topic: Swagger UI 1.0.3 Cross-Site Scripting (XSS) Risk: Low Text:/* * Author : Byte Reaper * Telegram : @ByteReaper0 * CVE : CVE-2025-8191 * Title : Swagger UI 1.0.3...
Vvveb CMS 1.0.5 Remote Code Execution The Exploit Database - CXSecurity.com By: Maksim 24 October 2025 at 09:39 Topic: Vvveb CMS 1.0.5 Remote Code Execution Risk: High Text:## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-...
SugarCRM unauthenticated Remote Code Execution (RCE) The Exploit Database - CXSecurity.com By: DANG 7 October 2025 at 23:08 Topic: SugarCRM unauthenticated Remote Code Execution (RCE) Risk: High Text:# Exploit Title: SugarCRM unauthenticated Remote Code Execution (RCE) # Exploit Author: DANG # Vendor Homepage: https://www.s...
Belkin F9K1009 F9K1010 2.00.04/2.00.09 Hard Coded Credentials The Exploit Database - CXSecurity.com By: Byte 30 September 2025 at 22:51 Topic: Belkin F9K1009 F9K1010 2.00.04/2.00.09 Hard Coded Credentials Risk: High Text:/* * Title : Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials * Author : Byte Reaper * CVE...
Commvault CLI Argument Injection / Traversal / Remote Code Execution The Exploit Database - CXSecurity.com By: Piotr Bazydlo 21 September 2025 at 19:30 Topic: Commvault CLI Argument Injection / Traversal / Remote Code Execution Risk: High Text:## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-...
Sitecore XP Post-Authentication File Upload The Exploit Database - CXSecurity.com By: Piotr Bazydlo 14 September 2025 at 18:43 Topic: Sitecore XP Post-Authentication File Upload Risk: High Text:## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-...
Ultimate Member WordPress Plugin 2.6.6 Privilege Escalation The Exploit Database - CXSecurity.com By: Gurjot Singh 28 August 2025 at 13:18 Topic: Ultimate Member WordPress Plugin 2.6.6 Privilege Escalation Risk: Medium Text:#!/usr/bin/env python3 # Exploit Title: Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation # Exploit Author: Gur...
Ghost CMS 5.59.1 Arbitrary File Read The Exploit Database - CXSecurity.com By: ibrahimsql 28 August 2025 at 13:18 Topic: Ghost CMS 5.59.1 Arbitrary File Read Risk: Medium Text:#!/usr/bin/env python3 # -*- coding: utf-8 -*- """ # Exploit Title: Ghost CMS 5.59.1 - Arbitrary File Read # Date: 2023-09-...