ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 2 August 2026 at 17:16 Topic: ArcadeDB
Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE) The Exploit Database - CXSecurity.com By: M@rAz Ali Β· Peyman Siyahi Β· MR.PERSIA 19 July 2026 at 11:36 Topic: Joomla Page Builder CK
Microsoft Edge < = 150.0.4078.48 (Chromium-based) Type Confusion RCE The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 19 July 2026 at 11:35 Topic: Microsoft Edge
PraisonAI CodeAgent < = 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 19 July 2026 at 11:34 Topic: PraisonAI CodeAgent
XenForo XSS CVE Scanner β Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 The Exploit Database - CXSecurity.com By: Xasthur 3 July 2026 at 17:40 Topic: XenForo XSS CVE Scanner β Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 Risk: Low Text:#!/usr/bin/env python3 """ XenForo XSS CVE Scanner Author: Xasthur Passive detection for CVE-2026-35055, CVE-2026-35054, ...
ePati Antikor NGFW 2.0.1301 Authentication Bypass The Exploit Database - CXSecurity.com By: SADIK ERTΓRK 27 May 2026 at 20:42 Topic: ePati Antikor NGFW 2.0.1301 Authentication Bypass Risk: Medium Text:# Exploit Title: ePati Antikor NGFW 2.0.1301 - Authentication Bypass # Date: 2026-04-13 # Exploit Author: [SADIK ERTΓRK] ...
Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service The Exploit Database - CXSecurity.com By: xeloxa 27 May 2026 at 20:41 Topic: Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Risk: Medium Text:# Exploit Title: Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service # Google Dork: intext:"Apache/2.4.66" "...
NiceGUI 3.6.1 Path Traversal The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 19 May 2026 at 23:16 Topic: NiceGUI 3.6.1 Path Traversal Risk: Medium Text:# Exploit Title: NiceGUI 3.6.1 - Path Traversal # Author: Mohammed Idrees Banyamer # Instagram: @banyamer_security # GitHub...
Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Vulnerability - Realistic Full Chain Attack on F-16 Avionics (Ground The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 4 May 2026 at 22:19 Topic: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Vulnerability - Realistic Full Chain Attack on F-16 Avionics (Ground Risk: Low Text:#!/usr/bin/env python3 # Exploit Title: Green Hills INTEGRITY RTOS IPCOMShell TELNET Format String Full Chain - Realistic F-16...
OpenClaw < 2026.3.28 Discord Text Approval Authorization Bypass The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 22 April 2026 at 23:53 Topic: OpenClaw
Kanboard < = 1.2.50 Authenticated SQL Injection The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 18 March 2026 at 22:17 Topic: Kanboard
OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 2 March 2026 at 22:11 Topic: OpenClaw tools.exec.safeBins
Google Chrome < 145.0.7632.75 - CSSFontFeatureValuesMap Use-After-Free The Exploit Database - CXSecurity.com By: nu11secur1ty 23 February 2026 at 23:18 Topic: Google Chrome
Siklu EtherHaul Series EH-8010 Remote Command Execution The Exploit Database - CXSecurity.com By: semaja2 14 February 2026 at 21:31 Topic: Siklu EtherHaul Series EH-8010 Remote Command Execution Risk: High Text:# Exploit Title:Siklu EtherHaul Series EH-8010 - Remote Command Execution # Shodan Dork: "EH-8010" or "EH-1200" # Date: 2025-...
aiohttp 3.9.1 Directory Traversal The Exploit Database - CXSecurity.com By: Beatriz Fresno Naumova 5 February 2026 at 22:43 Topic: aiohttp 3.9.1 Directory Traversal Risk: Medium Text:# Exploit Title: Python aiohttp directory traversal PoC (CVE-2024-23334) # Google Dork: N/A # Date: 2025-10-06 # Exploit Aut...
deephas < = 1.0.7 - Prototype Pollution leading to Arbitrary Code Execution / DoS The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 2 February 2026 at 22:14 Topic: deephas
LangChain Core - Serialization Injection to Jinja2 SSTI/RCE The Exploit Database - CXSecurity.com By: Mohammed Idrees Banyamer 26 January 2026 at 20:48 Topic: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE Risk: High Text:# Exploit Title: LangChain Core - Serialization Injection to Jinja2 SSTI/RCE # Date: 2025-12-29 # Exploit Author: Mohammed I...
AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution The Exploit Database - CXSecurity.com By: Valentin 18 January 2026 at 22:49 Topic: AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution Risk: High Text:## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-...
Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure The Exploit Database - CXSecurity.com By: Byte Reaper 28 December 2025 at 11:40 Topic: Birth Chart Compatibility WordPress Plugin 2.0 Full Path Disclosure Risk: Low Text:/* * Exploit Title : Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure * Author : Byte Reaper *...
dotCMS 25.07.02-1 Authenticated Blind SQL Injection The Exploit Database - CXSecurity.com By: Matan Sandori 18 December 2025 at 00:01 Topic: dotCMS 25.07.02-1 Authenticated Blind SQL Injection Risk: Medium Text:#!/usr/bin/env python3 # Exploit Title: dotCMS 25.07.02-1 - Authenticated Blind SQL Injection # Google Dork: N/A # Date: 2...