header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Cacti 1.2.24 – Authenticated command injection when using SNMP options

In Cacti 1.2.24, under certain conditions, an authenticated privileged user can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server.

OpenPLC WebServer 3 – Denial of Service

This exploit allows an attacker to remotely execute code on the OpenPLC_v3 WebServer. The vulnerability occurs when the web server fails to properly handle user authentication, allowing an attacker to bypass authentication and gain unauthorized access to the server. By exploiting this vulnerability, an attacker can perform various malicious activities, including uploading and executing arbitrary code on the target system.

WordPress Sonaar Music Plugin 4.7 – Stored XSS

This exploit allows an attacker to execute arbitrary JavaScript code in the context of a user's browser by injecting a malicious payload into the comment section of a published page in the Wordpress Sonaar Music Plugin 4.7. The payload used in this example is <script>alert("XSS")</script>.

Media Library Assistant WordPress Plugin – RCE and LFI

Media Library Assistant Wordpress Plugin in version < 3.10 is affected by an unauthenticated remote reference to Imagick() conversion which allows attacker to perform LFI and RCE depending on the Imagick configuration on the remote server. The affected page is: wp-content/plugins/media-library-assistant/includes/mla-stream-image.php

Recent Exploits: