header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

phpIPAM 1.6 – Reflected Cross Site Scripting (XSS)

phpIPAM version 1.6 is vulnerable to reflected cross-site scripting (XSS) due to improper sanitization of user-supplied data in the 'closeClass' parameter of the 'popup.php' script. An attacker can exploit this by injecting malicious scripts into the parameter, leading to script execution in the context of the victim's browser.

Intelight X-1L Traffic controller Maxtime 1.9.6 – Remote Code Execution (RCE)

The Intelight X-1L Traffic controller Maxtime 1.9.6 allows remote attackers to bypass authentication to gain full control of traffic controllers, modify traffic light sequences, trigger denial of service, and cause traffic congestion. This vulnerability exists in the web-based UI of Traffic Controllers running version 1.9.x firmware due to lack of authentication before allowing access to critical functionality.

OpenPanel 0.3.4 – Directory Traversal

The OpenPanel version 0.3.4 is vulnerable to directory traversal. By exploiting this vulnerability, an attacker can traverse the directories outside the intended location and gain unauthorized access to sensitive files. This vulnerability has been assigned CVE-2024-53537.

WordPress Backup and Staging Plugin Arbitrary File Upload to Remote Code Execution

The WordPress plugin 'Backup and Staging by WP Time Capsule' up to version 1.21.16 allows unauthenticated attackers to upload arbitrary files via the upload.php endpoint, potentially leading to remote code execution by uploading and executing a PHP file directly from a specific directory.

Ivanti Connect Secure 22.7R2.5 – Remote Code Execution (RCE)

The Ivanti Connect Secure version 22.7R2.5 is vulnerable to remote code execution. By crafting a specific payload, an attacker can exploit this vulnerability to execute arbitrary commands on the target system. This vulnerability has been assigned the CVE-2025-0282.

Recent Exploits: