Atomicorp WAF Research Notes

Research Update - 2026-05-29

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2009-0545ZeroShell <= 1.0beta11 Remote Code Execution312657 , 340007 , 340029 , 344360 , 344370 , 347009 , 390709
CVE-2010-5286Joomla! Component Jstore - 'Controller' Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2019-11510Pulse Connect Secure SSL VPN Arbitrary File Read347009
CVE-2021-44228Apache Log4j2 Remote Code Injection345115 , 345117 , 345118 , 393655
CVE-2022-22536SAP Memory Pipes (MPI) Desynchronization392301
CVE-2024-10081CodeChecker <= 6.24.1 - Authentication Bypass392301
CVE-2024-30498CRM Perks Forms <= 1.1.4 - SQL Injection380122
CVE-2025-20281Cisco ISE - Remote Code Execution392301
CVE-2025-34030sar2html <=3.2.2 Plot Parameter - Remote Code Execution340014 , 340193 , 344364 , 344366
CVE-2025-34035EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 Root Remote Code Execution341245
CVE-2025-34040Zhiyuan OA - arbitrary file upload leading330791 , 340007 , 340152
CVE-2025-34073Maltrail <=0.54 Username Parameter - Remote Command Execution340014 , 344363 , 344370
CVE-2025-47812Wing FTP Server <= 7.4.3 - Remote Code Execution344362 , 344363 , 380026 , 390614
CVE-2025-49132Pterodactyl Panel - Remote Code Execution340007
CVE-2025-53833LaRecipe < 2.8.1 Remote Code Execution via SSTI340087
CVE-2025-55169WeGIA - Directory Traversal340007 , 344360
CVE-2025-55182React Server Components - Remote Code Execution331702 , 344370 , 345240 , 380026 , 393655
CVE-2025-57819FreePBX - Remote Code Execution340157 , 341245 , 344365 , 344370 , 360147 , 360148
CVE-2019-10758mongo-express Remote Code Execution345240 , 360151 , 380026
CVE-2021-21881Lantronix PremierWave 2050 8.9.0.0R4 - Remote Command Injection340014 , 344363 , 344370
CVE-2021-33690SAP NetWeaver Development Infrastructure - Server Side Request Forgery340162 , 340163
CVE-2009-1151PhpMyAdmin Scripts - Remote Code Execution340029 , 344360
CVE-2010-2861Adobe ColdFusion - Directory Traversal340007 , 344360 , 347009 , 390613 , 390614 , 390704 , 390709
CVE-2010-4239Tiki Wiki CMS Groupware 5.2 - Local File Inclusion340007 , 390109
CVE-2012-1823PHP CGI v5.3.12/5.4.2 Remote Code Execution340165 , 378491
CVE-2013-2251Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution337209 , 337211 , 344361 , 393655
CVE-2014-1203Eyou E-Mail <3.6 - Remote Code Execution340023 , 341245 , 344360 , 344361 , 344363 , 344370
CVE-2014-3206Seagate BlackArmor NAS - Command Injection311235 , 340014 , 340193 , 344364 , 344366
CVE-2014-6271ShellShock - Remote Code Execution330701 , 344360 , 390719 , 393134
CVE-2014-6287HTTP File Server <2.3c - Remote Command Execution390613 , 390614
CVE-2014-9614Netsweeper 4.0.5 - Default Weak Account392301
CVE-2015-1427ElasticSearch - Remote Code Execution344360 , 380026 , 390724
CVE-2015-4455WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload340007 , 391742 , 391743
CVE-2016-10134Zabbix - SQL Injection340157 , 340159 , 341245 , 360147 , 360148
CVE-2016-15042WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Upload382238
CVE-2016-15043WP Mobile Detector <= 3.5 - Unrestricted File Upload340162 , 340163 , 391740
CVE-2016-1555NETGEAR WNAP320 Access Point Firmware - Remote Command Injection340014 , 344364 , 344366
CVE-2016-3088Apache ActiveMQ Fileserver - Arbitrary File Write392301
CVE-2017-11444Subrion CMS <4.1.5.10 - SQL Injection341245
CVE-2017-12611Apache Struts2 S2-053 - Remote Code Execution337207 , 337209 , 337211 , 337218 , 340014 , 340029 , 340193 , 344360 , 344362 , 344363 , 344370 , 347009
CVE-2017-12635Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation392301
CVE-2017-5638Apache Struts 2 - Remote Command Execution332791 , 334168 , 390719
CVE-2017-8917Joomla! <3.7.1 - SQL Injection340157 , 340159 , 341245 , 360147 , 360148
CVE-2017-9791Apache Struts2 S2-053 - Remote Code Execution337207
CVE-2017-9841PHPUnit - Remote Code Execution392648 , 393782
CVE-2018-0127Cisco RV132W/RV134W Router - Information Disclosure312863 , 390716
CVE-2018-10562Dasan GPON Devices - Remote Code Execution392301
CVE-2018-11511ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection341245 , 380026 , 380122
CVE-2018-11686FlexPaper/FlowPaper 2.3.6 - Remote Code Execution340029 , 344361 , 344364
CVE-2018-12031Eaton Intelligent Power Manager 1.6 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2018-1273Spring Data Commons - Remote Code Execution344360 , 344370
CVE-2018-13379Fortinet FortiOS - Credentials Disclosure340007
CVE-2018-14064VelotiSmart Wifi - Directory Traversal347009
CVE-2018-14728Responsive filemanager 9.13.1 Server-Side Request Forgery392301
CVE-2018-16159WordPress Gift Voucher <4.1.8 - Blind SQL Injection380122
CVE-2018-16167LogonTracer <=1.2.0 - Remote Command Injection340014 , 344364 , 344366
CVE-2018-16283WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2018-16763FUEL CMS 1.4.1 - Remote Code Execution340023 , 344360 , 344370 , 347009 , 380026
CVE-2018-16836Rubedo CMS <=3.4.0 - Directory Traversal347009
CVE-2018-17173LG Supersign EZ CMS - Remote Code Execution340014 , 340029 , 344361 , 344363 , 344370
CVE-2018-17246Kibana - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2018-17254Joomla! JCK Editor SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2018-18925Gogs (Go Git Service) 0.11.66 - Remote Code Execution344360
CVE-2018-20985WordPress Payeezy Pay <=2.97 - Local File Inclusion392301
CVE-2018-3810Oturia WordPress Smart Google Code Inserter <3.5 - Authentication Bypass380026
CVE-2018-6605Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection340016 , 340017 , 340144 , 340157 , 360147 , 360148
CVE-2018-7314Joomla! Component PrayerCenter 3.0.2 - SQL Injection340157 , 341245 , 360147 , 360148
CVE-2019-10068Kentico CMS Insecure Deserialization Remote Code Execution341256
CVE-2019-10232Teclib GLPI <= 9.3.3 - Unauthenticated SQL Injection340016 , 340017 , 340144 , 340155 , 340157 , 341155 , 341245 , 360147 , 360148
CVE-2019-10647ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)340162 , 340163
CVE-2019-11581Atlassian Jira Server-Side Template Injection311299
CVE-2019-12314Deltek Maconomy 2.2.5 - Local File Inclusion347009
CVE-2019-12725Zeroshell 3.9.0 - Remote Command Execution340023 , 340029 , 344360 , 344361 , 344363 , 344370 , 347009 , 390722
CVE-2019-12985Citrix SD-WAN Center - Remote Command Injection340014 , 340029 , 344364 , 344366 , 344370
CVE-2019-12986Citrix SD-WAN Center - Remote Command Injection340014 , 340029 , 344364 , 344366 , 344370
CVE-2019-12987Citrix SD-WAN Center - Remote Command Injection340014
CVE-2019-12988Citrix SD-WAN Center - Remote Command Injection393655
CVE-2019-15107Webmin <= 1.920 - Unauthenticated Remote Command Execution340023 , 344360 , 344361 , 344363
CVE-2019-16278nostromo 1.9.6 - Remote Code Execution390714 , 392301
CVE-2019-16662rConfig 3.9.2 - Remote Code Execution340029 , 344360 , 344361 , 344363 , 347009
CVE-2019-16759vBulletin 5.0.0-5.5.4 - Remote Command Execution341245
CVE-2019-16920D-Link Routers - Remote Code Execution340023 , 344360 , 344361 , 344363 , 344365 , 344366
CVE-2019-17270Yachtcontrol Webapplication 1.0 - Remote Command Injection344360 , 347009 , 390904
CVE-2019-17564Apache Dubbo 2.5.x-2.7.4 - Insecure Deserialization344370 , 344380 , 390614 , 390626 , 390724
CVE-2019-3396Atlassian Confluence Server - Path Traversal392301
CVE-2019-7256eMerge E3 1.00-06 - Remote Code Execution340029 , 344360 , 344361 , 344363 , 344370 , 347009
CVE-2019-9194elFinder <= 2.1.47 - Command Injection390700 , 393781
CVE-2019-9618WordPress GraceMedia Media Player 1.0 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2019-9762PHPSHE 1.7 - SQL Injection340016 , 340017 , 340145 , 340156 , 340157 , 340159 , 360147 , 360148
CVE-2020-10148SolarWinds Orion API - Auth Bypass390709
CVE-2020-10189ManageEngine Desktop Central Java Deserialization340007 , 344365 , 344380 , 347019
CVE-2020-10220rConfig 3.9 - SQL Injection340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2020-10546rConfig 3.9.4 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380123
CVE-2020-10547rConfig 3.9.4 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380123
CVE-2020-10548rConfig 3.9.4 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380123
CVE-2020-10549rConfig <=3.9.4 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380123
CVE-2020-11455LimeSurvey 4.1.11 - Local File Inclusion344360 , 347009
CVE-2020-11530WordPress Chop Slider 3 - Blind SQL Injection340016 , 380026 , 380122
CVE-2020-11546SuperWebmailer 7.21.0.01526 - Remote Code Execution340095 , 393655
CVE-2020-11984Apache HTTP Server - Remote Code Execution344363 , 390614 , 390626 , 390724
CVE-2020-12641Roundcube Webmail - Command Injection340014
CVE-2020-12720vBulletin SQL Injection340016 , 340017 , 340155 , 340157 , 340159 , 341155 , 341245 , 360147 , 360148
CVE-2020-13117Wavlink Multiple AP - Remote Command Injection340014 , 344364 , 344366 , 344370
CVE-2020-13167Netsweeper <=6.4.3 - Python Code Injection340087 , 340095 , 390810
CVE-2020-13640wpDiscuz <= 5.3.5 - SQL Injection331028 , 340016 , 340155 , 341155 , 360147 , 360148 , 380026
CVE-2020-14750Oracle WebLogic Server - Remote Command Execution337209 , 337210 , 337211 , 340014 , 340029 , 340095 , 344361 , 344362 , 344370 , 380026
CVE-2020-15415DrayTek Vigor - Command Injection390700
CVE-2020-15568TerraMaster TOS <.1.29 - Remote Code Execution340023 , 344360 , 347009
CVE-2020-15920Mida eFramework <=2.9.0 - Remote Command Execution340023 , 344360 , 344361 , 344363 , 347009
CVE-2020-17456SEOWON INTECH SLC-130 & SLR-120S - Unauthenticated Remote Code Execution340014 , 344363 , 344370
CVE-2020-17463Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)340016 , 341245 , 380026 , 380122 , 390727 , 392301 , 392648
CVE-2020-17496vBulletin 5.5.4 - 5.6.2- Remote Command Execution340007 , 344360 , 344370 , 390709
CVE-2020-17506Artica Web Proxy 4.30 - Authentication Bypass/SQL Injection340017 , 340157 , 341245 , 360147 , 360148
CVE-2020-17530Apache Struts 2.0.0-2.5.25 - Remote Code Execution344360 , 347009
CVE-2020-19625Gridx 1.3 - Remote Code Execution341250
CVE-2020-20300WeiPHP 5.0 - SQL Injection340157 , 340159 , 360147 , 360148
CVE-2020-21224Inspur ClusterEngine 4.0 - Remote Code Execution340023 , 344360 , 344361 , 344363 , 344370
CVE-2020-2220874cms - ajax_street.php 'x' SQL Injection340016 , 340017 , 340144 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2020-2220974cms - ajax_common.php SQL Injection341250 , 390703
CVE-2020-2221074cms - ajax_officebuilding.php SQL Injection340145
CVE-2020-2221174cms - ajax_street.php 'key' SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2020-24391Mongo-Express - Remote Code Execution345240 , 380026
CVE-2020-25213WordPress File Manager Plugin - Remote Code Execution393781
CVE-2020-25506D-Link DNS-320 - Unauthenticated Remote Code Execution344363 , 392301
CVE-2020-26919NETGEAR ProSAFE Plus - Unauthenticated Remote Code Execution392301
CVE-2020-27481Good Layers LMS Plugin <= 2.1.4 - SQL Injection322102 , 340016 , 380122
CVE-2020-28188TerraMaster TOS - Unauthenticated Remote Command Execution340014 , 340193 , 344363 , 344370
CVE-2020-29214Alumni Management System 1.0 - SQL Injection340156
CVE-2020-29227Car Rental Management System 1.0 - Local File Inclusion340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2020-2927974CMS - Remote File Inclusion340128 , 344363 , 380018
CVE-2020-29390Zeroshell 3.9.3 - Command Injection340023 , 341245 , 344360 , 344361 , 344363 , 344370 , 347009
CVE-2020-35476OpenTSDB <=2.4.0 - Remote Code Execution340014 , 340087 , 340095 , 340193 , 344370
CVE-2020-35713Belkin Linksys RE6500 <1.0.012.001 - Remote Command Execution392301
CVE-2020-35729Klog Server <=2.41 - Unauthenticated Command Injection392301
CVE-2020-5307PHPGurukul Dairy Farm Shop Management System 1.0 - SQL Injection340145 , 340156 , 341145
CVE-2020-5722Grandstream UCM6200 - SQL Injection340145 , 340156 , 341145 , 341245 , 344364 , 344366 , 390572 , 393655
CVE-2020-5902F5 BIG-IP TMUI - Remote Code Execution344360 , 347009 , 390709 , 390714 , 392301
CVE-2020-7209LinuxKI Toolset <= 6.01 - Remote Command Execution340029 , 344360 , 344361 , 344363 , 347009
CVE-2020-8515Multiple DrayTek Products - Pre-authentication Remote Root Code Execution392301
CVE-2020-8656EyesOfNetwork - Hardcoded API Key & SQL Injection340016 , 340017 , 340157 , 340159 , 360147 , 360148 , 380026 , 380122
CVE-2020-8771WordPress Time Capsule < 1.21.16 - Authentication Bypass392301
CVE-2020-9054Zyxel NAS Firmware 5.21- Remote Code Execution312659 , 340023 , 344360 , 344361 , 344363 , 344370 , 347009
CVE-2021-1472Cisco Small Business RV Series - OS Command Injection340014 , 340149 , 344364 , 344366 , 344370 , 350147
CVE-2021-1498Cisco HyperFlex HX Data Platform - Remote Command Execution340014 , 344364 , 344366 , 344370
CVE-2021-20038SonicWall SMA100 Stack - Buffer Overflow/Remote Code Execution340193
CVE-2021-20158Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change392301
CVE-2021-20617Acmailer - Improper Access Control to OS Command Injection340014 , 344363
CVE-2021-21307Lucee Admin - Remote Code Execution340149 , 342259 , 344364 , 344366 , 350147
CVE-2021-23394elFinder < 2.1.58 - Remote Code Execution393781
CVE-2021-24212WooCommerce Help Scout - Arbitrary File Upload330791 , 340152 , 382238
CVE-2021-24284WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File Upload382238
CVE-2021-24285WordPress Car Seller - Auto Classifieds Script - SQL Injection340016 , 340017 , 340144 , 360147 , 360148
CVE-2021-24442Wordpress Polls Widget < 1.5.3 - SQL Injection380122
CVE-2021-24472Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery340162 , 340163
CVE-2021-24499WordPress Workreap - Remote Code Execution330791 , 340152 , 382238
CVE-2021-24527Profile Builder < 3.4.9 - Improper Authentication340130
CVE-2021-24666WordPress Podlove Podcast Publisher <3.5.6 - SQL Injection340016 , 340017 , 340144 , 340157 , 360147 , 360148
CVE-2021-24731Pie Register < 3.7.1.6 - SQL Injection340016 , 340156 , 341245 , 380026 , 380122
CVE-2021-24762WordPress Perfect Survey <1.5.2 - SQL Injection340016 , 380122
CVE-2021-24827WordPress Asgaros Forum <1.15.13 - SQL Injection340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2021-24915Contest Gallery < 13.1.0.6 - SQL injection340017 , 340144 , 340157 , 344361
CVE-2021-24931WordPress Secure Copy Content Protection and Content Locking <2.8.2 - SQL Injection340016 , 380122
CVE-2021-24943Registrations for the Events Calendar < 2.7.6 - SQL Injection340016 , 380122
CVE-2021-24946WordPress Modern Events Calendar <6.1.5 - Blind SQL Injection340016 , 340017 , 360147 , 360148 , 380122
CVE-2021-25114WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2021-27132Sercomm VD625 Smart Modems - CRLF Injection330708 , 390714
CVE-2021-27314Doctor Appointment System 1.0 - SQL Injection340016 , 340156 , 380026 , 380122
CVE-2021-30118Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Execution344365 , 392301
CVE-2021-3110PrestaShop 1.7.7.0 - SQL Injection340016 , 341245 , 380026 , 380122
CVE-2021-31755Tenda Router AC11 - Remote Command Injection340014
CVE-2021-31805Apache Struts2 S2-062 - Remote Code Execution330791 , 340152
CVE-2021-31856Layer5 Meshery 0.5.2 - SQL Injection341245 , 344366
CVE-2021-32305Websvn <2.6.1 - Remote Code Execution340014 , 340193 , 344364 , 344366 , 344370
CVE-2021-34187Chamilo model.ajax.php - SQL Injection340016 , 340017 , 340144 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2021-34624WordPress ProfilePress 3.0-3.1.3 - Arbitrary File Upload382238
CVE-2021-35395RealTek Jungle SDK - Arbitrary Command Injection340014 , 340029 , 344361 , 344363
CVE-2021-36260Hikvision IP camera/NVR - Remote Command Execution393655
CVE-2021-36380Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection392301
CVE-2021-37291KevinLAB BEMS 1.0 - SQL Injection340156 , 341245
CVE-2021-37538PrestaShop SmartBlog <4.0.6 - SQL Injection340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2021-40870Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Execution340007
CVE-2021-40960Galera WebTemplate 1.0 Directory Traversal347009 , 390709
CVE-2021-41649PuneethReddyHC Online Shopping System homeaction.php SQL Injection392301
CVE-2021-41691openSIS Student Information System 8.0 SQL Injection340157 , 340159 , 341245 , 360147 , 360148
CVE-2021-41749CraftCMS SEOmatic - Server-Side Template Injection390719
CVE-2021-41773Apache 2.4.49 - Path Traversal and Remote Code Execution347009
CVE-2021-42013Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution347009
CVE-2021-43421Studio-42 elFinder <2.1.60 - Arbitrary File Upload393781
CVE-2021-43510Sourcecodester Simple Client Management System 1.0 - SQL Injection340145 , 340156 , 341145
CVE-2021-45382D-Link - Remote Command Execution392301
CVE-2021-45428Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Upload392301
CVE-2022-0169Photo Gallery by 10Web < 1.6.0 - SQL Injection340016 , 340017 , 360147 , 360148
CVE-2022-0349WordPress NotificationX <2.3.9 - SQL Injection341245 , 380026 , 380122
CVE-2022-0412WordPress TI WooCommerce Wishlist <1.40.1 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2022-0434WordPress Page Views Count <2.4.15 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-0592MapSVG < 6.2.20 - Unauthenticated SQLi340016 , 380026 , 380122
CVE-2022-0658CommonsBooking < 2.6.8 - SQL Injection340016 , 380122
CVE-2022-0679WordPress Narnoo Distributor <=2.5.1 - Local File Inclusion344360 , 390709
CVE-2022-0693WordPress Master Elements <=8.0 - SQL Injection340016 , 380122
CVE-2022-0747Infographic Maker iList < 4.3.8 - SQL Injection340016 , 380122
CVE-2022-0760WordPress Simple Link Directory <7.7.2 - SQL injection340016 , 380122
CVE-2022-0769Users Ultra <= 3.1.0 - SQL Injection340016 , 380122
CVE-2022-0773Documentor <= 1.5.3 - Unauthenticated SQL Injection340016 , 380122
CVE-2022-0781WordPress Nirweb Support <2.8.2 - SQL Injection340016 , 340017 , 340144 , 360147 , 360148
CVE-2022-0783Multiple Shipping Address Woocommerce < 2.0 - SQL Injection340016 , 380122
CVE-2022-0784WordPress Title Experiments Free <9.0.1 - SQL Injection340016 , 380122
CVE-2022-0785WordPress Daily Prayer Time <2022.03.01 - SQL Injection340016 , 380122
CVE-2022-0786WordPress KiviCare <2.3.9 - SQL Injection340016 , 380122
CVE-2022-0787Limit Login Attempts (Spam Protection) < 5.1 - SQL Injection340016 , 380122
CVE-2022-0814Ubigeo de Peru < 3.6.4 - SQL Injection340016 , 340017 , 340144 , 360147 , 360148
CVE-2022-0817WordPress BadgeOS <=3.7.0 - SQL Injection340016 , 340017 , 340144 , 360147 , 360148
CVE-2022-0826WordPress WP Video Gallery <=1.7.1 - SQL Injection340016 , 380122
CVE-2022-0827WordPress Best Books <=2.6.3 - SQL Injection340156 , 380122
CVE-2022-0846SpeakOut Email Petitions < 2.14.15.1 - SQL Injection340016 , 380122
CVE-2022-0867WordPress ARPrice <3.6.1 - SQL Injection340016 , 380122
CVE-2022-0949WordPress Stop Bad Bots <6.930 - SQL Injection380122
CVE-2022-1013WordPress Personal Dictionary <1.3.4 - Blind SQL Injection340016 , 380122
CVE-2022-1057WordPress Pricing Deals for WooCommerce <=2.0.2.02 - SQL Injection340016 , 340017 , 360147 , 360148 , 380122
CVE-2022-1388F5 BIG-IP iControl - REST Auth Bypass RCE344361 , 392767
CVE-2022-1390WordPress Admin Word Count Column 2.2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2022-1391WordPress Cab fare calculator < 1.0.4 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2022-1574WordPress HTML2WP <=1.0.0 - Arbitrary File Upload382238
CVE-2022-1609The School Management < 9.9.7 - Remote Code Execution340095 , 344361
CVE-2022-1950Youzify < 1.2.0 - Unauthenticated SQLi340016 , 380122
CVE-2022-22897PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injection340156 , 341145 , 341245 , 380026 , 380122
CVE-2022-22954VMware Workspace ONE Access - Server-Side Template Injection344360 , 344361 , 344363 , 344370 , 393655
CVE-2022-23898MCMS 5.2.5 - SQL Injection340156 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-24223Atom CMS v2.0 - SQL Injection340016 , 340156 , 380122
CVE-2022-24260VoipMonitor - Pre-Auth SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-2467Garage Management System 1.0 - SQL Injection340016 , 340156 , 380026 , 380122
CVE-2022-2486Wavlink WN535K2/WN535K3 - OS Command Injection340014 , 340193 , 344364 , 344366 , 344370
CVE-2022-2488Wavlink WN535K2/WN535K3 - OS Command Injection340014 , 340193 , 344364 , 344366
CVE-2022-25125MCMS 5.2.4 - SQL Injection340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-25488Atom CMS v2.0 - SQL Injection340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-26134Confluence - Remote Code Execution337209 , 337211 , 340087
CVE-2022-26585Mingsoft MCMS v5.2.7 - SQL Injection340156 , 340157 , 360147 , 360148
CVE-2022-27927Microfinance Management System 1.0 - 'customer_number' SQLi331028 , 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 390572 , 393655
CVE-2022-28032Atom CMS v2.0 - SQL Injection380026 , 380122
CVE-2022-29006Directory Management System 1.0 - SQL Injection340145 , 340156
CVE-2022-29007Dairy Farm Shop Management System 1.0 - SQL Injection340145 , 340156 , 341145
CVE-2022-29078Node.js Embedded JavaScript 3.1.6 - Template Injection340014 , 340193 , 344370 , 345240 , 380026
CVE-2022-29303SolarView Compact 6.0 - OS Command Injection340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 393655
CVE-2022-29316Complete Online Job Search System 1.0 - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2022-29383NETGEAR ProSafe SSL VPN firmware - SQL Injection340156 , 341145 , 341245
CVE-2022-31137Roxy-WI < 6.1.1.0 - Remote Code Execution340023 , 340029 , 344360 , 344361 , 344363
CVE-2022-31976Online Fire Reporting System v1.0 - SQL injection340016 , 340156 , 380026 , 380122
CVE-2022-31977Online Fire Reporting System v1.0 - SQL injection340016 , 340156 , 380026 , 380122
CVE-2022-31978Online Fire Reporting System v1.0 - SQL injection340016 , 340156 , 380026 , 380122
CVE-2022-32094Hospital Management System 1.0 - SQL Injection340145 , 340156 , 341145
CVE-2022-32409Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2022-3254AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection340016 , 340017 , 360147 , 360148
CVE-2022-33965WordPress Visitor Statistics <=5.7 - SQL Injection341245 , 380026 , 380122
CVE-2022-35405Zoho ManageEngine - Remote Code Execution392301
CVE-2022-35914GLPI <=10.0.2 - Remote Command Execution340023 , 344360
CVE-2022-36553Hytec Inter HWL-2511-SS - Remote Command Execution344360 , 347009 , 390904
CVE-2022-36642Omnia MPX 1.5.0+r1 - Local File Inclusion340007 , 344360 , 347009
CVE-2022-37042Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution340007 , 390614 , 390626
CVE-2022-38627Nortek Linear eMerge E3-Series - SQL Injection334073 , 340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2022-38637Hospital Management System 1.0 - SQL Injection340145 , 340156 , 341145
CVE-2022-40032Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)331028 , 340016 , 340145 , 340156 , 340157 , 341145 , 341245 , 345493 , 360147 , 360148 , 380026 , 380122 , 390572 , 393655
CVE-2022-4050WordPress JoomSport <5.2.8 - SQL Injection380122
CVE-2022-4059Cryptocurrency Widgets Pack < 2.0 - SQL Injection340016 , 380122
CVE-2022-4060WordPress User Post Gallery <=2.19 - Remote Code Execution340087 , 344360 , 347009
CVE-2022-40881SolarView 6.00 - Remote Command Execution340029 , 344360 , 344370 , 393655
CVE-2022-4117WordPress IWS Geo Form Fields <=1.0 - SQL Injection340016 , 380122
CVE-2022-41840Welcart eCommerce <=2.7.7 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2022-4328WooCommerce Checkout Field Manager < 18.0 - Arbitrary File Upload382238
CVE-2022-4447WordPress Fontsy <=1.8.6 - SQL Injection340016 , 340017 , 340144 , 360147 , 360148
CVE-2022-44588Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injection380122
CVE-2022-44877Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)344364 , 344366 , 393655
CVE-2022-45808LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLi340016 , 341245 , 380026 , 380122
CVE-2022-46071Helmet Store Showroom v1.0 - SQL Injection340145 , 340156 , 341145 , 390572
CVE-2022-47615LearnPress Plugin < 4.2.0 - Local File Inclusion344360 , 347009 , 390709
CVE-2022-47945Thinkphp Lang - Local File Inclusion340007
CVE-2022-48323Sunflower Simple and Personal 1.0.1.43315 - Remote Code Execution392301
CVE-2023-0037WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injection340016 , 341245 , 380026 , 380122
CVE-2023-0297PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)340095
CVE-2023-0562Bank Locker Management System v1.0 - SQL Injection340156 , 341145
CVE-2023-1020Steveas WP Live Chat Shoutbox <= 1.4.2 - SQL Injection340016 , 340017 , 340144 , 360147 , 360148
CVE-2023-1719Bitrix Component - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198
CVE-2023-1730SupportCandy < 3.1.5 - Unauthenticated SQL Injection340016 , 341245 , 380026 , 380122
CVE-2023-2130Purchase Order Management v1.0 - SQL Injection340016 , 340156 , 380026 , 380122
CVE-2023-22463KubePi JwtSigKey - Admin Authentication Bypass392301
CVE-2023-22527Atlassian Confluence - Remote Code Execution340095 , 344364 , 344366
CVE-2023-23333SolarView Compact 6.00 - OS Command Injection344361 , 344363 , 390613 , 390614
CVE-2023-23488WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection380122
CVE-2023-23489WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injection340016 , 380122
CVE-2023-24000WordPress GamiPress <= 2.5.7 - SQL Injection340016 , 340156 , 380026 , 380122
CVE-2023-2479Appium Desktop Server - Remote Code Execution342259
CVE-2023-25135vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution344365 , 390614
CVE-2023-25717Ruckus Wireless Admin - Remote Code Execution344363 , 393655
CVE-2023-27637PrestaShop tshirtecommerce Module - SQL Injection341245 , 344366 , 380026 , 380122
CVE-2023-29300Adobe ColdFusion - Pre-Auth Remote Code Execution344370 , 344380 , 350147
CVE-2023-29827Embedded JavaScript(EJS) 3.1.6 - Template Injection340014 , 340193 , 344370 , 345240 , 380026
CVE-2023-30013TOTOLink - Unauthenticated Command Injection392301
CVE-2023-31465TimeKeeper by FSMLabs - Remote Code Execution344361 , 344364 , 393655
CVE-2023-32563Ivanti Avalanche - Remote Code Execution340007
CVE-2023-33338Old Age Home Management System v1.0 - SQL Injection340145 , 340156 , 390572
CVE-2023-34048VMware vCenter Server - Out-of-Bounds Write392301
CVE-2023-34124SonicWall GMS and Analytics Web Services - Shell Injection340017 , 360148 , 380123
CVE-2023-34362MOVEit Transfer - Remote Code Execution340016 , 390716
CVE-2023-3643CAREL Boss Mini <= 1.4.0 - Local File Inclusion344360 , 390709
CVE-2023-36845Juniper J-Web - Remote Code Execution344360 , 390709
CVE-2023-3722Avaya Aura Device Services - OS Command Injection392301
CVE-2023-37629Online Piggery Management System v1.0 - Unauthenticated File Upload330791
CVE-2023-38203Adobe ColdFusion - Deserialization of Untrusted Data344370 , 344380 , 350147
CVE-2023-39143PaperCut < 22.1.3 - Path Traversal344365 , 347019
CVE-2023-39361Cacti 1.2.24 - SQL Injection344366 , 380026 , 380122
CVE-2023-39796WBCE 1.6.0 - Unauthenticated SQL injection340016 , 340145 , 340156 , 380026 , 380122
CVE-2023-40748PHPJabbers Food Delivery Script - SQL Injection340156 , 341145 , 341245
CVE-2023-40749PHPJabbers Food Delivery Script v3.0 - SQL Injection340017 , 340156 , 340157 , 341245 , 360147 , 360148
CVE-2023-41109SmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway - Command Injection392301
CVE-2023-44353Adobe ColdFusion WDDX Deserialization Gadgets344365 , 344370 , 350147
CVE-2023-4490WordPress Job Portal < 2.0.6 - SQL Injection341245 , 380026 , 380122
CVE-2023-46347PrestaShop Step by Step products Pack - SQL Injection340016 , 340017 , 340144 , 340157 , 341245 , 344366 , 360147 , 360148
CVE-2023-46359cPH2 Charging Station v1.87.0 - OS Command Injection340014 , 340193 , 344363 , 344364 , 344370 , 393655
CVE-2023-46574TOTOLINK A3700R - Command Injection392301 , 392648
CVE-2023-46747F5 BIG-IP - Unauthenticated RCE via AJP Smuggling390626 , 392767
CVE-2023-47246SysAid Server - Remote Code Execution340007 , 390614 , 390626 , 390724
CVE-2023-48022Anyscale Ray - Remote Code Execution392301 , 392648
CVE-2023-48084Nagios XI < 5.11.3 - SQL Injection340130 , 340145 , 340156 , 380026 , 380122
CVE-2023-4974Academy LMS 6.2 - SQL Injection341245 , 380026 , 380122
CVE-2023-50839JS Help Desk <= 2.8.1 - SQL Injection380122
CVE-2023-5652WP Hotel Booking <= 2.0.7 - SQL Injection340156 , 380122
CVE-2023-5815News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion340748 , 347006
CVE-2023-5991Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion344360 , 347009 , 390709
CVE-2023-6623Essential Blocks < 4.4.3 - Local File Inclusion344360 , 347009
CVE-2023-6989Shield Security WP Plugin <= 18.5.9 - Local File Inclusion340748
CVE-2024-10571Chartify – WordPress Chart Plugin < 2.9.6 - Local File Inclusion340748 , 347006
CVE-2024-1061WordPress HTML5 Video Player - SQL Injection340016 , 380026 , 380122
CVE-2024-10763WordPress Campress Theme <= 1.35 - Unauthenticated Local File Inclusion340077
CVE-2024-1512MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection340016 , 340156 , 341245 , 380026 , 380122
CVE-2024-21650XWiki < 4.10.20 - Remote code execution340130
CVE-2024-2330NS-ASG Application Security Gateway 6.3 - Sql Injection340157 , 360147
CVE-2024-24112Exrick XMall - SQL Injection340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2024-24328TotoLink Router setMacFilterRules - Command Injection392301
CVE-2024-24329TotoLink Router setPortForwardRules - Command Injection392301
CVE-2024-2621Fujian Kelixin Communication - Command Injection340016 , 340156 , 341245 , 380026 , 380122
CVE-2024-2667InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload340162 , 340163
CVE-2024-27956WordPress Automatic Plugin <= 3.92.0 - SQL Injection340156 , 341245 , 380026 , 380122 , 390614
CVE-2024-2876Wordpress Email Subscribers by Icegram Express - SQL Injection340016 , 380026 , 380122
CVE-2024-30163IPS Community Suite - Unauthenticated SQL Injection380026
CVE-2024-30490ProfileGrid <= 5.7.8 - SQL Injection340016 , 380122
CVE-2024-31750F-logic DataCube3 - SQL Injection340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2024-34257TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection392301
CVE-2024-36412SuiteCRM - SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2024-38289TurboMeeting - Boolean-based SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 390572
CVE-2024-43360ZoneMinder - SQL Injection341245 , 380026 , 380122
CVE-2024-45507Apache OFBiz - Remote Code Execution340162 , 340163 , 344370
CVE-2024-4577PHP CGI - Argument Injection340165 , 392301
CVE-2024-50603Aviatrix Controller - Remote Code Execution340029 , 344360 , 344363 , 344370 , 393655
CVE-2024-51211openSIS Classic v9.1 - SQL Injection341245 , 380122
CVE-2024-51978Brother Printers – Authentication Bypass via Default Admin Password390709
CVE-2024-6205PayPlus Payment Gateway < 6.6.9 - SQL Injection341245 , 380026 , 380122
CVE-2024-6265UsersWP <= 1.2.10 - Unauthenticated SQL Injection341245 , 380026 , 380122
CVE-2024-7593Ivanti vTM - Authentication Bypass392301
CVE-2024-7954SPIP Porte Plume Plugin - Remote Code Execution340023 , 340128 , 344370 , 380018 , 390801
CVE-2024-9047WordPress File Upload <= 4.24.11 - Arbitrary File Read344360
CVE-2024-9193WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update340087 , 340748 , 344370 , 347006 , 390720
CVE-2025-1661HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion340748
CVE-2025-2294Kubio AI Page Builder <= 2.5.1 - Local File Inclusion344360 , 347009 , 390709
CVE-2025-24813Apache Tomcat Path Equivalence - Remote Code Execution392301
CVE-2025-24893XWiki Platform - Remote Code Execution340023 , 347009
CVE-2025-25257Fortinet FortiWeb - SQL Injection340156
CVE-2025-29085Vipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey Component340157 , 340159 , 341245 , 360147 , 360148
CVE-2025-29306FoxCMS v.1.2.5 - Remote Code Execution344360 , 344370 , 347009 , 393655
CVE-2025-31324SAP NetWeaver Visual Composer Metadata Uploader - Deserialization330791 , 340152
CVE-2025-32814NetMRI Unauthenticated SQL Injection via skipjackUsername340016 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026
CVE-2025-34085WordPress Simple File List <=4.2.2 - Remote Code Execution382238
CVE-2025-44136MapTiler Tileserver-php v2.0 - Unauthenticated XSS341256 , 342259 , 346755 , 350148
CVE-2025-4524WordPress Madara - Local File Inclusion340748 , 344360 , 390709
CVE-2025-47445WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download344360 , 347009 , 390709
CVE-2025-53770Microsoft SharePoint Server - Remote Code Execution (ToolShell)330906 , 350147
CVE-2026-35616FortiClient EMS - Authentication Bypass392301
CVE-2019-8982Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request Forgery344360 , 347009
CVE-2020-20982shadoweb wdja v1.5.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-32853Erxes <0.23.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-45136XWiki < 14.10.14 - Cross-Site Scripting341266
CVE-2025-34152Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via time Parameter344364 , 393655
CVE-2013-1965Apache Struts2 S2-012 RCE337207 , 337209 , 337211 , 344360
CVE-2018-25114osCommerce 2.3.4.1 - Remote Code Execution340023 , 340095 , 344360 , 344370
CVE-2023-28787Quiz and Survey Master <= 8.1.4 - SQL Injection341245 , 380026 , 380122
CVE-2024-27954WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF340165 , 344360 , 347009
CVE-2024-32709WP-Recall <= 16.26.5 - SQL Injection340016 , 340017 , 340144 , 340157 , 340159 , 341245 , 360147 , 360148 , 390703
CVE-2024-4879ServiceNow UI Macros - Template Injection342259 , 344370
CVE-2024-8752WebIQ 2.15.9 - Directory Traversal344365 , 347019 , 390716
CVE-2024-9166TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution340014 , 340193 , 390904
CVE-2025-22785Course Booking System <= 6.0.6 - SQL Injection340016 , 380122
CVE-2025-32969XWiki REST API Query - SQL Injection340016 , 340017 , 340157 , 340159 , 360147 , 360148 , 380026 , 380122
CVE-2025-48281MyStyle Custom Product Designer <= 3.21.1 - SQL Injection340016 , 341245 , 380026 , 380122
CVE-2025-52472XWiki - HQL Injection340087 , 340095 , 340156 , 340157 , 340159 , 360147 , 360148
CVE-2025-54726WordPress JS Archive List <= 6.1.5 - SQL Injection341245 , 380026 , 380122
CVE-2025-55748XWiki Platform - Path Traversal340007
CVE-2024-5217ServiceNow - Incomplete Input Validation340157 , 340159 , 342259 , 344370 , 360147 , 360148 , 380026
CVE-2018-14916Loytec LGATE-902 <6.4.2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2018-16716NCBI ToolBox - Directory Traversal344360 , 347009 , 390709
CVE-2018-19365Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2019-13462Lansweeper Unauthenticated SQL Injection331028 , 340016 , 340155 , 340157 , 341155 , 341245 , 344361 , 360147 , 360148
CVE-2020-24589WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection341256 , 344370 , 344372 , 380018
CVE-2020-36333ThemeGrill Demo Importer < 1.6.2 - Database Reset375357
CVE-2021-21479SCIMono <0.0.19 - Remote Code Execution337209 , 337211 , 340087 , 346755
CVE-2021-27931LumisXP <10.0.0 - Blind XML External Entity Attack344372 , 392301
CVE-2021-28918Netmask NPM Package - Server-Side Request Forgery340162 , 344360 , 347009 , 398003
CVE-2021-46419Telesquare TLR-2855KS6 - Arbitrary File Deletion392301 , 393134
CVE-2022-26960elFinder <=2.1.60 - Local File Inclusion340007 , 344360 , 347009 , 390709 , 393781
CVE-2022-27593QNAP QTS Photo Station External Reference - Local File Inclusion340007
CVE-2023-36934MOVEit Transfer - SQL Injection340016 , 344362
CVE-2024-5276Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection341245
CVE-2024-53900Mongoose < 8.8.3 - Remote Code Execution340087 , 340095 , 345240
CVE-2008-4668Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2021-45046Apache Log4j2 - Remote Code Injection345115 , 345117 , 345118 , 393655
CVE-2016-10960WordPress wSecure Lite < 2.4 - Remote Code Execution392301
CVE-2016-4977Spring Security OAuth2 Remote Command Execution393655
CVE-2016-6277NETGEAR Routers - Remote Code Execution347009
CVE-2017-14535Trixbox - 2.8.0.4 OS Command Injection340023 , 344360 , 344361 , 344363 , 347009
CVE-2017-6090PhpColl 2.5.1 Arbitrary File Upload391746
CVE-2018-10093AudioCodes 420HD - Remote Code Execution344360 , 347009
CVE-2018-10823D-Link Routers - Remote Command Injection347009
CVE-2018-12613PhpMyAdmin <4.8.2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2018-7765Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection341245 , 344364 , 344366
CVE-2019-19824TOTOLINK Realtek SD Routers - Remote Command Injection340014
CVE-2019-9082ThinkPHP < 3.2.4 - Remote Code Execution344361 , 393753
CVE-2020-13851Artica Pandora FMS 7.44 - Remote Code Execution344360 , 347009
CVE-2020-17505Artica Web Proxy 4.30 - OS Command Injection340017 , 340157 , 341245 , 344364 , 344366 , 360147 , 360148
CVE-2020-24579D-Link DSL 2888a - Authentication Bypass/Remote Command Execution344360 , 347009 , 390904 , 392301
CVE-2020-24949PHP-Fusion 9.03.50 - Remote Code Execution393655
CVE-2020-8163Ruby on Rails <5.0.1 - Remote Code Execution340023 , 344360 , 344370 , 347009 , 390724
CVE-2020-8641Lotus Core CMS 1.0.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2020-8813Cacti v1.2.8 - Remote Code Execution340014
CVE-2021-20086Odoo Apps - Cross-Site Scripting via Prototype Pollution333141 , 340099 , 340147 , 341099 , 341256 , 346755 , 347198
CVE-2021-22053Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Execution337209 , 337211 , 340087 , 340193
CVE-2021-28151Hongdian H8922 3.0.5 - Remote Command Injection330925 , 392301
CVE-2021-32819Nodejs Squirrelly - Remote Code Execution340014 , 340087 , 340095 , 340193 , 344370 , 345240 , 380026
CVE-2021-3577Motorola Baby Monitors - Remote Command Execution340014 , 340193 , 344364 , 344370 , 393655
CVE-2022-1883Terraboard <2.2.0 - SQL Injection341245
CVE-2022-28079College Management System 1.0 - 'course_code' SQL Injection (Authenticated)340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 345493 , 360147 , 360148 , 390572
CVE-2023-1389TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection393655
CVE-2023-23492Login with Phone Number - Cross-Site Scripting346755 , 347198
CVE-2023-30625Rudder Server < 1.3.0-rc.1 - SQL Injection392301
CVE-2023-37462XWiki Platform - Remote Code Execution340130
CVE-2023-4169Ruijie RG-EW1200G Router - Password Reset392301
CVE-2023-4415Ruijie RG-EW1200G Router Background - Login Bypass392301
CVE-2023-52163Digiever DS-2105 Pro - Command Injection390709
CVE-2024-7340W&B Weave Server - Remote Arbitrary File Leak347009
CVE-2021-4463Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download344360 , 347009 , 390709
CVE-2024-11303Korenix JetPort 5601v3 - Path Traversal347009
CVE-2024-26291Avid NEXIS Agent - Arbitrary File Read344360 , 344365 , 347009 , 390709
CVE-2025-34031Moodle Jmol Filter 6.1 - Local File Inclusion340165 , 344360 , 347009
CVE-2025-34045WeiPHP 5.0 - Path Traversal340007 , 344360
CVE-2025-4008MeteoBridge <= 6.1 - Remote Code Execution393655
CVE-2025-61666Traccar(Windows) 6.1- 6.8.1 - Local File Inclusion344365 , 347019
CVE-2015-4694WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrieval340007 , 344360 , 347009 , 390709
CVE-2018-16288LG SuperSign EZ CMS 2.5 - Local File Inclusion347009
CVE-2021-32820Express-handlebars - Local File Inclusion344360 , 347009 , 390709
CVE-2022-24900Piano LED Visualizer 1.3 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2022-41412perfSONAR 4.x <= 4.4.4 - Server-Side Request Forgery340007
CVE-2023-26360Adobe ColdFusion - Local File Read340007 , 344360 , 390709
CVE-2023-47105Chaosblade < 1.7.4 - Remote Code Execution393655
CVE-2024-21136Oracle Retail Xstore Suite - Pre-authenticated Path Traversal340007 , 344365 , 347019
CVE-2024-23167GestSup - Cross-Site Scripting333141
CVE-2024-24919Check Point Quantum Gateway - Information Disclosure392301
CVE-2024-48766NetAlert X - Arbitary File Read340007 , 340029 , 344360
CVE-2025-10897WooCommerce Designer Pro <= 1.9.28 - Arbitrary File Read344360
CVE-2025-27222TRUfusion Enterprise <= 7.10.4.0 - Path Traversal340007 , 344360
CVE-2015-2996SysAid Help Desk <15.2 - Local File Inclusion344360 , 347009 , 390709
CVE-2025-34023Karel IP Phone IP1211 Web Management Panel - Local File Inclusion330925 , 340007 , 344360 , 347009 , 390709
CVE-2023-47218QNAP QTS and QuTS Hero - OS Command Injection330791 , 340152
CVE-2024-22024Ivanti Connect Secure - XXE380019
CVE-2024-5420SEH utnserver Pro/ProMAX/INU-100 20.1.22 - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2017-10075Oracle Content Server - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198
CVE-2020-13379Grafana 3.0.1-7.0.1 - Server-Side Request Forgery340165
CVE-2020-26248PrestaShop Product Comments <4.2.0 - SQL Injection341245 , 380026 , 380122
CVE-2022-2633All-In-One Video Gallery <=2.6.0 - Server-Side Request Forgery340163
CVE-2024-21893Ivanti SAML - Server Side Request Forgery (SSRF)392301
CVE-2025-44137MapTiler Tileserver-php v2.0 - Unauthenticated File Read340007 , 344360 , 347009 , 390709
CVE-2025-44177White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)347009 , 390727 , 392648
CVE-2026-39364Vite Dev Server - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2014-3120ElasticSearch v1.1.1/1.2 RCE344360 , 344370 , 380026 , 390724
CVE-2016-3081Apache S2-032 Struts - Remote Code Execution337209 , 337211 , 344360 , 347009 , 390904
CVE-2017-12615Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)337209 , 337210 , 337211 , 340095 , 340128 , 344360 , 345493 , 347009 , 380018 , 380026 , 390904 , 392301
CVE-2017-12617Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)345493 , 392301
CVE-2018-11231Opencart Divido - Sql Injection392301
CVE-2018-11776Apache Struts2 S2-057 - Remote Code Execution337209 , 337211 , 340193 , 347009
CVE-2018-6961VMware NSX SD-WAN Edge - Command Injection344363 , 393655
CVE-2019-6340Drupal - Remote Code Execution392301
CVE-2023-26067Lexmark Printers - Command Injection392301
CVE-2023-6831mlflow - Path Traversal390709
CVE-2024-38473Apache HTTP Server - ACL Bypass390709
CVE-2025-2636InstaWP Connect < 0.1.0.86 - Local PHP File Inclusion340007
CVE-2021-20167Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun392301
CVE-2009-1558Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion344360 , 347009 , 390709
CVE-2010-4231Camtron CMNC-200 IP Camera - Directory Traversal347009
CVE-2011-3315Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2014-2962Belkin N150 Router 1.00.08/1.00.09 - Path Traversal344360 , 347009 , 390709
CVE-2021-21315Node.JS System Information Library <5.3.1 - Remote Command Injection340029 , 344360 , 344364 , 344370 , 347009 , 393655
CVE-2022-25485Cuppa CMS v1.0 - Local File Inclusion340007 , 344360 , 390709
CVE-2022-25486Cuppa CMS v1.0 - Local File Inclusion340007 , 344360 , 390709
CVE-2021-21234Spring Boot Actuator Logview Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2021-43831Gradio < 2.5.0 - Arbitrary File Read347009
CVE-2002-1131SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2006-2842Squirrelmail <=1.4.6 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2008-1059WordPress Sniplets 1.1.2 - Local File Inclusion336461 , 340007 , 344360 , 381206
CVE-2009-2015Joomla! MooFAQ 1.0 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2009-3318Joomla! Roland Breedveld Album 1.14 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2009-4202Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2009-4223KR-Web <=1.1b2 - Remote File Inclusion340162 , 340163
CVE-2009-4679Joomla! Portfolio Nexus - Remote File Inclusion340007 , 344360 , 347009 , 390709
CVE-2010-0157Joomla! Component com_biblestudy - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2010-0759Joomla! Plugin Core Design Scriptegrator - Local File Inclusion344360 , 347009 , 390709
CVE-2010-0972Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0985Joomla! Component com_abbrev - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1306Joomla! Component Picasa 2.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1470Joomla! Component Web TV 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1471Joomla! Component Address Book 1.5.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1472Joomla! Component Horoscope 1.5.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1495Joomla! Component Matamko 1.01 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1531Joomla! Component redSHOP 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1533Joomla! Component TweetLA 1.0.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1535Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1602Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1603Joomla! Component ZiMBCore 0.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1653Joomla! Component Graphics 1.0.6 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1717Joomla! Component iF surfALERT 1.2 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1875Joomla! Component Property - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1878Joomla! Component OrgChart 1.0.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1952Joomla! Component BeeHeard 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1953Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1954Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1955Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1956Joomla! Component Gadget Factory 1.0.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1957Joomla! Component Love Factory 1.3.4 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1977Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1980Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1983Joomla! Component redTWITTER 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2033Joomla! Percha Categories Tree 0.6 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2034Joomla! Component Percha Image Attach 1.1 - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2035Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2036Joomla! Component Percha Fields Attach 1.0 - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2037Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2045Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2050Joomla! Component MS Comment 0.8.0b - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2128Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2259Joomla! Component com_bfsurvey - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2682Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2918Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion340007 , 344360 , 347009 , 390709
CVE-2010-3426Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-4282Pandora Fms < 3.1.1 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2010-4719Joomla! Component JRadio - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-4769Joomla! Component Jimtawl 1.0.2 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-4977Joomla! Component Canteen 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-5028Joomla! Component JE Job 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-1226Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities340007 , 344360 , 347009 , 390709
CVE-2014-10037DomPHP 0.83 - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2014-3704Drupal SQL Injection392301
CVE-2014-3744Node.js st module Directory Traversal347009
CVE-2014-8682Gogs (Go Git Service) - SQL Injection340016 , 340017 , 340157 , 360147 , 360148 , 380026
CVE-2014-9735WordPress RevSlider - Remote Code Execution via File Upload337469
CVE-2015-1000005WordPress Candidate Application Form <= 1.3 - Local File Inclusion337473 , 344360 , 347009 , 390709
CVE-2015-1000010WordPress Simple Image Manipulator < 1.0 - Local File Inclusion337473 , 344360 , 347009 , 390709
CVE-2015-1000012WordPress MyPixs <=0.3 - Local File Inclusion344360 , 347009 , 390709
CVE-2015-1503IceWarp Mail Server < 11.1.1 - Directory Traversal340007 , 344360 , 347009 , 390709 , 390726 , 390727 , 392301 , 392647 , 392648
CVE-2015-2196WordPress Spider Calendar <=1.4.9 - SQL Injection340016 , 340156 , 380122
CVE-2015-3035TP-LINK - Local File Inclusion347009
CVE-2015-3648ResourceSpace - Local File inclusion340007 , 344360 , 347009 , 390709
CVE-2015-4074Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusion344360 , 347009 , 390709
CVE-2015-4632Koha 3.20.1 - Directory Traversal344360 , 347009 , 390709
CVE-2015-5469WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion344360 , 347009 , 390709
CVE-2015-7245D-Link DVG-N5402SP - Local File Inclusion392301
CVE-2015-7297Joomla! Core SQL Injection340157 , 340159 , 341245 , 360147 , 360148
CVE-2015-9406mTheme Unus < 2.3 - Directory Traversal336461 , 340007 , 344360 , 381206
CVE-2016-10367Opsview Monitor Pro - Local File Inclusion390709
CVE-2016-10924Wordpress Zedna eBook download <1.2 - Local File Inclusion336461 , 340007 , 344360 , 381206
CVE-2016-10956WordPress Mail Masta 1.0 - Local File Inclusion344360 , 347009 , 390709
CVE-2016-2389SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2016-6601WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities344360 , 347009 , 390709 , 390727 , 392301 , 392648
CVE-2017-1000028Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusion347009 , 390716
CVE-2017-1000029Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusion347009
CVE-2017-1000170WordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File Inclusion392301
CVE-2017-10974Yaws 1.91 - Local File Inclusion350591
CVE-2017-11512ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval340007 , 344365 , 347019
CVE-2017-14849Node.js <8.6.0 - Directory Traversal347009
CVE-2017-15363Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 - Local File Inclusion340007
CVE-2017-15647FiberHome Routers - Local File Inclusion344360 , 347009 , 390709
CVE-2017-16806Ulterius Server < 1.9.5.0 - Directory Traversal347009 , 390709 , 390716
CVE-2017-16877Nextjs <2.4.1 - Local File Inclusion347009
CVE-2017-16894Laravel <5.5.21 - Information Disclosure390709
CVE-2017-9833BOA Web Server 0.94.14 - Arbitrary File Access340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2018-10822D-Link Routers - Local File Inclusion347009
CVE-2018-10956IPConfigure Orchid Core VMS 2.0.5 - Local File Inclusion347009
CVE-2018-12054Schools Alert Management Script - Arbitrary File Read344360
CVE-2018-12909Webgrind <= 1.5 - Local File Inclusion344360 , 347009 , 390709
CVE-2018-14912cgit < 1.2.1 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2018-14918LOYTEC LGATE-902 6.3.2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2018-15138LG-Ericsson iPECS NMS 30M - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2018-15535Responsive FileManager < 9.13.4 - Directory Traversal340007 , 344360 , 344370 , 345493 , 347009 , 390709 , 390720 , 390727 , 392301 , 392648
CVE-2018-15745Argus Surveillance DVR 4.0.0.0 - Local File Inclusion340007
CVE-2018-16299WordPress Localize My Post 1.0 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2018-18323Centos Web Panel 0.9.8.480 - Local File Inclusion344360 , 347009
CVE-2018-19326Zyxel VMG1312-B10D 5.13AAXA.8 - Local File Inclusion347009
CVE-2018-19458PHP Proxy 3.0.3 - Local File Inclusion340162 , 340165 , 344360 , 347009
CVE-2018-19753Tarantella Enterprise <3.11 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2018-20463WordPress JSmol2WP <=1.07 - Local File Inclusion340007 , 340077 , 340165 , 344360 , 381206
CVE-2018-20470Tyto Sahi pro 7.x/8.x - Local File Inclusion340007
CVE-2018-3760Ruby On Rails - Local File Inclusion347009
CVE-2018-6008Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2018-6184Zeit Next.js < 4.2.3 - Local File Inclusion347009
CVE-2018-7422WordPress Site Editor <=1.1.1 - Local File Inclusion336461 , 344360 , 347009 , 381206 , 390709 , 393771
CVE-2018-7490uWSGI PHP Plugin Local File Inclusion347009
CVE-2018-7719Acrolinx Server <5.2.5 - Local File Inclusion347019
CVE-2018-8033Apache OFBiz - XML External Entity Injection341256 , 344370 , 344372
CVE-2018-9118WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion336461 , 344360 , 381206
CVE-2018-9205Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2019-12276GrandNode 4.40 - Local File Inclusion344360 , 347009 , 390709
CVE-2019-12593IceWarp Mail Server <=10.4.4 - Local File Inclusion340007 , 344360 , 344365 , 347019
CVE-2019-14205WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion336461 , 340007 , 344360 , 381206
CVE-2019-14251T24 Web Server - Local File Inclusion344360 , 347009 , 390709
CVE-2019-16123PilusCart <=1.4.1 - Local File Inclusion344360 , 347009 , 390709
CVE-2019-16469Adobe Experience Manager - Expression Language Injection393655
CVE-2019-17538Jiangnan Online Judge 0.8.0 - Local File Inclusion340007 , 344360 , 347009
CVE-2019-18371Xiaomi Mi WiFi R3G Routers - Local file Inclusion347009 , 390709
CVE-2019-18665DOMOS 5.5 - Local File Inclusion344360 , 347009 , 390709
CVE-2019-18922Allied Telesis AT-GS950/8 - Local File Inclusion347009
CVE-2019-25213WordPress Advanced Access Manager - Path Traversal336461 , 344360 , 381206
CVE-2019-5418Rails File Content Disclosure390719
CVE-2019-7254eMerge E3 1.00-06 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2019-7315Genie Access WIP3BVAF IP Camera - Local File Inclusion347009
CVE-2019-7481SonicWall SRA 4600 VPN - SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2019-9922Joomla! Harmis Messenger 1.2.2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2020-11738WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion323769 , 336461 , 340748 , 344360 , 347006 , 347009 , 381206 , 390709
CVE-2020-12447Onkyo TX-NR585 Web Interface - Directory Traversal347009
CVE-2020-13158Artica Proxy Community Edition <4.30.000000 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2020-14864Oracle Fusion - Directory Traversal/Local File Inclusion344360 , 347009 , 390709 , 390716
CVE-2020-17519Apache Flink - Local File Inclusion390709
CVE-2020-19360FHEM 6.0 - Local File Inclusion344360 , 347009 , 390709
CVE-2020-23575Kyocera Printer d-COPIA253MF - Directory Traversal347009
CVE-2020-24285INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion344360 , 347009 , 390709
CVE-2020-26073Cisco SD-WAN vManage Software - Local File Inclusion347009
CVE-2020-27191LionWiki <3.2.12 - Local File Inclusion344360 , 347009
CVE-2020-27467Processwire CMS <2.7.1 - Local File Inclusion344360 , 347009 , 390709
CVE-2020-35580SearchBlox <9.2.2 - Local File Inclusion344360 , 347009 , 390709
CVE-2020-35598Advanced Comment System 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2020-35736GateOne 1.1 - Local File Inclusion347009
CVE-2020-5410Spring Cloud Config Server - Local File Inclusion390709
CVE-2020-8209Citrix XenMobile Server - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2020-8982Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Read340007
CVE-2021-20123Draytek VigorConnect 1.6.0-B - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2021-20124Draytek VigorConnect 6.0-B3 - Local File Inclusion344360 , 347009 , 390709
CVE-2021-24227Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2021-24340WordPress Statistics <13.0.8 - Blind SQL Injection380122
CVE-2021-25864Hue Magic 3.0.0 - Local File Inclusion347009
CVE-2021-25899Void Aural Rec Monitor 9.0.0.1 - SQL Injection341245 , 380026 , 380122
CVE-2021-27316Doctor Appointment System 1.0 - SQL Injection340016 , 340156 , 341245 , 380026 , 380122
CVE-2021-27319Doctor Appointment System 1.0 - SQL Injection340016 , 340156 , 380122
CVE-2021-27320Doctor Appointment System 1.0 - SQL Injection340016 , 340156 , 341245 , 380026 , 380122
CVE-2021-3223Node RED Dashboard <2.26.2 - Local File Inclusion347009
CVE-2021-32789WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection360150
CVE-2021-33807Cartadis Gespage 8.2.1 - Directory Traversal340007 , 344360
CVE-2021-34805FAUST iServer 9.0.018.018.4 - Local File Inclusion344365 , 347019 , 390716
CVE-2021-35250SolarWinds Serv-U 15.3 - Directory Traversal340007
CVE-2021-35380TermTalk Server 3.24.0.2 - Local File Inclusion340007
CVE-2021-36748PrestaHome Blog for PrestaShop <1.7.8 - SQL Injection341245
CVE-2021-39312WordPress True Ranker <2.2.4 - Local File Inclusion336461 , 344360 , 381206
CVE-2021-39316WordPress DZS Zoomsounds <=6.50 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2021-39433BIQS IT Biqs-drive v1.83 Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2021-40661IND780 - Local File Inclusion340007 , 390716
CVE-2021-40978MKdocs 1.2.2 - Directory Traversal347009
CVE-2021-41277Metabase - Local File Inclusion340165 , 344360 , 347009
CVE-2021-41291ECOA Building Automation System - Directory Traversal Content Disclosure340007 , 344360 , 347009 , 390709
CVE-2021-41293ECOA Building Automation System - Arbitrary File Retrieval392301
CVE-2021-41460ECShop 4.1.0 - SQL Injection340157 , 340159 , 360147 , 360148
CVE-2021-41569SAS/Internet 9.4 1520 - Local File Inclusion344360 , 347009
CVE-2021-41648PuneethReddyHC action.php SQL Injection392301
CVE-2021-43287Pre-Auth Takeover of Build Pipelines in GoCD340007 , 344360 , 347009 , 390709
CVE-2021-43495AlquistManager Local File Inclusion347009
CVE-2021-43496Clustering Local File Inclusion347009
CVE-2021-43734kkFileview v4.0.0 - Local File Inclusion340165 , 344360 , 347009
CVE-2021-43778GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.340007 , 344360 , 347009 , 390709
CVE-2021-43798Grafana v8.x - Arbitrary File Read347009
CVE-2021-45043HD-Network Realtime Monitoring System 2.0 - Local File Inclusion344360
CVE-2021-46104webp_server_go 0.4.0 - Path Traversal390709
CVE-2021-46107Ligeo Archives Ligeo Basics - Server Side Request Forgery340162 , 340165 , 344360 , 347009
CVE-2021-46381DLINK DAP-1620 A1 v1.01 - Directory Traversal344360 , 390709 , 390726 , 392301 , 392647
CVE-2021-46417Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI)340007 , 344360 , 347009
CVE-2021-46418Telesquare TLR-2855KS6 - Arbitrary File Creation392301
CVE-2022-0656uDraw <3.3.3 - Local File Inclusion344360 , 390709
CVE-2022-0666Microweber < 1.2.11 - CRLF Injection330708 , 390722
CVE-2022-1119WordPress Simple File List <3.2.8 - Local File Inclusion336461 , 340007 , 344360 , 381206
CVE-2022-1453RSVPMaker <= 9.2.5 - SQL Injection340016 , 341245 , 380026 , 380122
CVE-2022-1768WordPress RSVPMaker <=9.3.2 - SQL Injection341245 , 380026 , 380122
CVE-2022-23347BigAnt Server v5.6.06 - Local File Inclusion340007
CVE-2022-24124Casdoor 1.13.0 - Unauthenticated SQL Injection341245
CVE-2022-24716Icinga Web 2 - Arbitrary File Disclosure347009
CVE-2022-26233Barco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusion347019
CVE-2022-2627174cmsSE v3.4.1 - Arbitrary File Read340007
CVE-2022-27043Yearning - Directory Traversal347009 , 347019 , 390709 , 390716
CVE-2022-29014Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusion344360
CVE-2022-29298SolarView Compact 6.00 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2022-31474BackupBuddy - Local File Inclusion344360 , 347009 , 390709
CVE-2022-33901WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read340748 , 344360 , 347006 , 347009 , 390709
CVE-2022-34121CuppaCMS v1.0 - Local File Inclusion340007 , 344360 , 390709
CVE-2022-37122Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversal340007 , 344360 , 347009 , 390709
CVE-2022-38794Zaver - Local File Inclusion347009
CVE-2022-38840Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE)344360 , 344370 , 344372 , 380018
CVE-2022-4140WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access344360 , 347009 , 390709
CVE-2022-47501Apache OFBiz < 18.12.07 - Local File Inclusion340165 , 344360 , 347009
CVE-2023-0126SonicWall SMA1000 LFI347009
CVE-2023-0159Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE340077 , 344360 , 381206
CVE-2023-22047Oracle Peoplesoft - Unauthenticated File Read340165 , 344360 , 344365 , 347009
CVE-2023-23063Cellinx NVT Web Server - Local File Disclosure344360 , 347009 , 390709
CVE-2023-26256STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion344360 , 347009 , 390709
CVE-2023-27639PrestaShop TshirteCommerce - Directory Traversal340007
CVE-2023-27640PrestaShop tshirtecommerce - Directory Traversal340007
CVE-2023-29887Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2023-31059Repetier Server - Directory Traversal344365 , 347019
CVE-2023-33510Jeecg P3 Biz Chat - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2023-34092Vite Dev Server - Information Exposure390709
CVE-2023-34133SonicWall GMS and Analytics - SQL Injection340017 , 360148 , 380123
CVE-2023-34843Traggo Server - Local File Inclusion344365 , 347019
CVE-2023-35843NocoDB version <= 0.106.1 - Arbitrary File Read347009
CVE-2023-35844Lightdash version <= 0.510.3 Arbitrary File Read347009
CVE-2023-37474Copyparty <= 1.8.2 - Directory Traversal347009
CVE-2023-38879openSIS v9.0 - Path Traversal344360 , 347009 , 390709
CVE-2023-38950ZKTeco BioTime v8.5.5 - Path Traversal340007
CVE-2023-39026FileMage Gateway - Directory Traversal344365 , 347019 , 390716
CVE-2023-39141Aria2 WebUI - Path traversal347009
CVE-2023-40924SolarView Compact < 6.00 - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2023-5203WP Sessions Time Monitoring Full Automatic <= 1.0.8 - SQL Injection340016 , 380026 , 380122
CVE-2023-5204WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injection340016 , 380122
CVE-2023-6020Ray Static File - Local File Inclusion347009
CVE-2023-6023VertaAI ModelDB - Path Traversal340007 , 344360 , 347009 , 390709
CVE-2023-6038H2O ImportFiles - Local File Inclusion344360 , 347009 , 390709
CVE-2023-6567LearnPress <= 4.2.5.7 - SQL Injection340016 , 341245 , 380026 , 380122
CVE-2023-6750WordPress WP Clone <= 2.4.2 - Database Backup Exposure350590 , 390716
CVE-2023-6909Mlflow <2.9.2 - Path Traversal392301
CVE-2023-6977Mlflow <2.8.0 - Local File Inclusion344360
CVE-2024-12025WordPress Collapsing Categories <= 3.0.8 - SQL Injection340016 , 341245 , 380026 , 380122
CVE-2024-13322Ads Pro Plugin <= 4.88 - Unauthenticated SQL Injection380122
CVE-2024-23334aiohttp - Directory Traversal347009
CVE-2024-27292Docassemble - Local File Inclusion344360 , 347009 , 390709
CVE-2024-28995SolarWinds Serv-U - Directory Traversal340007 , 344365 , 347019
CVE-2024-32736CyberPower < v2.8.3 - SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2024-32737CyberPower - SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2024-32738CyberPower - SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2024-32739CyberPower < v2.8.3 - SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2024-36837CRMEB v.5.2.2 - SQL Injection340156 , 340157 , 360147 , 360148
CVE-2024-37393SecurEnvoy Two Factor Authentication - LDAP Injection392301
CVE-2024-38816WebMvc.fn/WebFlux.fn - Path Traversal347009
CVE-2024-38819Spring Framework Path Traversal in Functional Web Frameworks347009 , 390709
CVE-2024-4443Business Directory Plugin <= 6.4.2 - SQL Injection340156 , 380026
CVE-2024-45241CentralSquare CryWolf - Path Traversal340007
CVE-2024-45388Hoverfly < 1.10.3 - Arbitrary File Read344360 , 390709
CVE-2024-4956Sonatype Nexus Repository Manager 3 - Local File Inclusion347009
CVE-2024-5334Devika - Local File Inclusion344360 , 347009 , 390709
CVE-2024-6250LOLLMS WebUI - Absolute Path Traversal392301
CVE-2024-6893Journyx - XML External Entities Injection (XXE)344360 , 344370 , 344372
CVE-2024-8522LearnPress < 4.2.7.1 - SQL Injection341245 , 380026 , 380122
CVE-2024-9362Polyaxon - Unauthenticated Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2025-10162WordPress OrderConvo < 14 - Path Traversal336461 , 344360
CVE-2025-11371Gladinet CentreStack & TrioFox - Local File Inclusion340007 , 344360 , 344365 , 347019
CVE-2025-13138WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection340016 , 380122
CVE-2025-2011Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection340016 , 340017 , 360147 , 360148
CVE-2025-24963Vitest Browser Mode - Local File Read344360 , 347009 , 390709
CVE-2025-25231Omnissa Workspace ONE UEM - Path Traversal340007
CVE-2025-30567WordPress WP01 - Path Traversal390709
CVE-2025-31125Vite Development Server - Path Traversal347009 , 390709 , 390716
CVE-2025-31131Yeswiki < 4.5.2 - Unauthenticated Path Traversal340007 , 344360 , 347009 , 390709
CVE-2025-4396Relevanssi <= 4.24.4 (Free) - Unauthenticated SQL Injection341245 , 380026 , 380122
CVE-2025-4427Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code Execution337210 , 340087 , 340095 , 380026 , 393655
CVE-2025-5287Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection380122
CVE-2025-59049Mockoon < 9.2.0 - Path Traversal347009
CVE-2025-61884Oracle E-Business Suite - Server-Side Request Forgery337109 , 337110 , 340162 , 340163 , 340165 , 341256 , 342259 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2025-66744Yonyou YonBIP - Path Traversal340007
CVE-2025-6970WordPress Events Manager <= 7.0.3 - SQL Injection380122
CVE-2026-1557WP Responsive Images <= 1.0 - Arbitrary File Read336461 , 344360 , 381206
CVE-2026-1581wpForo Forum <= 2.4.14 - SQL Injection341245 , 380122
CVE-2026-2413Ally – Web Accessibility & Usability <= 4.0.3 - SQL Injection380026 , 380122
CVE-2024-33288Prison Management System - SQL Injection Authentication Bypass341245
CVE-2024-48259Cloudlog - SQL Injection331028 , 340016 , 340157 , 341245 , 360147 , 360148 , 380026
CVE-2026-6433FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code Execution340016 , 340017 , 360147 , 360148
CVE-2018-10735NagiosXI <= 5.4.12 commandline.php SQL injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2018-10736NagiosXI <= 5.4.12 - SQL injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2018-10737NagiosXI <= 5.4.12 logbook.php SQL injection331028 , 340155 , 341155 , 341245
CVE-2018-10738NagiosXI <= 5.4.12 menuaccess.php - SQL injection331028 , 340016 , 340155 , 340157 , 340159 , 341155 , 341245 , 360147 , 360148 , 380026
CVE-2019-16996Metinfo 7.0.0 beta - SQL Injection340016 , 340017 , 340157 , 360147 , 360148
CVE-2019-16997Metinfo 7.0.0 beta - SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2019-17418MetInfo 7.0.0 beta - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2019-2767Oracle Business Intelligence Publisher - XML External Entity Injection344370 , 380018
CVE-2019-9041ZZZCMS 1.6.1 - Remote Code Execution360153 , 380026
CVE-2020-14883Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution380026
CVE-2021-33544Geutebruck - Remote Command Injection340014 , 340193 , 344364 , 344370 , 393655
CVE-2022-31974Online Fire Reporting System v1.0 - SQL injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-31975Online Fire Reporting System v1.0 - SQL injection340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-31984Online Fire Reporting System v1.0 - SQL injection340016 , 340017 , 340144 , 340157 , 360147 , 360148
CVE-2022-32015Complete Online Job Search System 1.0 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-32018Complete Online Job Search System 1.0 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-32022Car Rental Management System 1.0 - SQL Injection340156
CVE-2022-32024Car Rental Management System 1.0 - SQL Injection340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-32025Car Rental Management System 1.0 - SQL Injection340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-32026Car Rental Management System 1.0 - SQL Injection340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-32028Car Rental Management System 1.0 - SQL Injection340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-34590Hospital Management System 1.0 - SQL Injection340145 , 340156
CVE-2023-33629H3C Magic R300-2100M - Remote Code Execution392301
CVE-2025-32813Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request393655
CVE-2019-10717BlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversal340007
CVE-2019-25246BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure330925 , 344360 , 347009 , 390709
CVE-2024-14015Studiocart <= 2.9.0 - Cross-Site Scripting341266
CVE-2019-6793GitLab Enterprise Edition - Server-Side Request Forgery390616
CVE-2018-3238Oracle Fusion Middleware WebCenter Sites 11.1.1.8.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-12987DrayTek Vigor - Command Injection347009 , 393655
CVE-2024-51483Changedetection.io <= 0.47.4 - Path Traversal340130
CVE-2024-7188Bylancer Quicklancer 2.4 G - SQL Injection340016 , 340156 , 341245 , 380026 , 380122
CVE-2024-7339TVT DVR Sensitive Device - Information Disclosure392301
CVE-2024-8877Riello Netman 204 - SQL Injection340156 , 341245
CVE-2025-1743Pichome 2.1.0 - Arbitrary File Read340162 , 340165 , 344360 , 347009
CVE-2025-2473Company Visitor Management System 1.0 - SQL Injection340145 , 340156 , 341145
CVE-2025-4388Liferay Portal - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-4576Liferay Portal & DXP - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-23483Blinko <= 1.8.3 - Path Traversal via /plugins347009
CVE-2004-0519SquirrelMail 1.4.x - Folder Name Cross-Site Scripting341266 , 346755
CVE-2007-0885Jira Rainbow.Zen - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2007-4556OpenSymphony XWork/Apache Struts2 - Remote Code Execution337207 , 337209 , 337211 , 344360
CVE-2008-2650CMSimple 3.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2008-6172Joomla! Component RWCards 3.0.11 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2009-3053Joomla! Agora 3.0.0b - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2010-1056Joomla! Component com_rokdownloads - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1219Joomla! Component com_janews - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1469Joomla! Component JProject Manager 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1473Joomla! Component Advertising 0.25 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1474Joomla! Component Sweetykeeper 1.5 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1475Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1476Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1478Joomla! Component Jfeedback 1.2 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1607Joomla! Component WMI 1.5.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1715Joomla! Component Online Exam 1.5.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1718Joomla! Component Archery Scores 1.0.6 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1719Joomla! Component MT Fire Eagle 1.2 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1722Joomla! Component Online Market 2.x - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1723Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1979Joomla! Component Affiliate Datafeeds 880 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1981Joomla! Component Fabrik 2.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2122Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrieval340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2507Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2680Joomla! Component jesectionfinder - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2010-2857Joomla! Component Music Manager - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2920Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-4617Joomla! Component JotLoader 2.2.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2011-2744Chyrp 2.x - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-0392Apache Struts2 S2-008 RCE337207 , 337209 , 337210 , 337211 , 344360 , 344370 , 347009
CVE-2014-2383Dompdf < v0.6.0 - Local File Inclusion340077 , 340165 , 344360 , 347009
CVE-2017-14537Trixbox 2.8.0 - Path Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2017-9416Odoo 8.0/9.0/10.0 - Local File Inclusion347009 , 390716
CVE-2018-18809TIBCO JasperReports Library - Directory Traversal340007
CVE-2018-3714node-srv - Local File Inclusion347009
CVE-2019-11013Nimble Streamer <=3.5.4-9 - Local File Inclusion347009
CVE-2019-14312Aptana Jaxer 1.0.3.4547 - Local File inclusion344360 , 347009 , 390709
CVE-2019-3799Spring Cloud Config Server - Local File Inclusion347009 , 390709
CVE-2020-5405Spring Cloud Config - Local File Inclusion390709
CVE-2020-6950Eclipse Mojarra - Local File Read340007
CVE-2021-21402Jellyfin <10.7.0 - Local File Inclusion344365 , 347019
CVE-2021-27124Doctor Appointment System 1.0 - SQL Injection340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2021-28149Hongdian H8922 3.0.5 Devices - Local File Inclusion330925 , 340007 , 344360 , 347009 , 390709
CVE-2021-31195Microsoft Exchange Server - Cross-Site Scripting346755 , 350148
CVE-2021-31249CHIYU TCP/IP Converter - Carriage Return Line Feed Injection340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 , 390722
CVE-2021-39165Cachet <=2.3.18 - SQL Injection340145 , 340156 , 341145 , 380026 , 380122
CVE-2021-41349Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting340147 , 340148 , 342259 , 346755 , 350148
CVE-2022-37299Shirne CMS 1.2.0 - Local File Inclusion340077 , 340162 , 340165 , 344360 , 347009
CVE-2022-38812AeroCMS 0.1.1 - SQL Injection340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2022-40734Laravel Filemanager v2.5.1 - Local File Inclusion340007
CVE-2023-3188Owncast - Server Side Request Forgery392301
CVE-2024-27564ChatGPT个人专用版 - Server Side Request Forgery340165 , 344360 , 347009
CVE-2024-36527Puppeteer Renderer - Directory Traversal340165 , 344360 , 347009
CVE-2024-5522WordPress HTML5 Video Player < 2.5.27 - SQL Injection340016 , 340017 , 340144 , 340157 , 340159 , 360147 , 360148
CVE-2024-55457MasterSAM Star Gate v11 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2025-28367mojoPortal <=2.9.0.1 - Directory Traversal340007 , 344360 , 390709
CVE-2025-32430XWiki Platform - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2025-32815NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentials344360 , 390709 , 390722
CVE-2025-53771Microsoft SharePoint Server - Authentication Bypass (ToolShell)330906 , 350147
CVE-2026-24128XWiki Platform Distribution Flavor Main - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2026-40105XWiki - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2000-0760Jakarta Tomcat 3.1 and 3.0 - Information Disclosure310094
CVE-2009-0932Horde/Horde Groupware - Local File Inclusion340007 , 340029 , 344360 , 390613 , 390614 , 390709
CVE-2012-3153Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153)340165
CVE-2012-4940Axigen Mail Server Filename Directory Traversal344365 , 347019
CVE-2011-4336Tiki Wiki CMS Groupware 7.0 Cross-Site Scripting340147 , 341266 , 342259
CVE-2014-4544Podcast Channels < 0.28 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-4592WP Planet <= 0.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2014-9606Netsweeper 4.0.8 - Cross-Site Scripting341266 , 346755
CVE-2014-9607Netsweeper 4.0.4 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-9608Netsweeper 4.0.3 - Cross-Site Scripting341266
CVE-2014-9615Netsweeper 4.0.4 - Cross-Site Scripting341266 , 346755
CVE-2015-6477Nordex NC2 - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2015-6544Combodo iTop <2.2.0-2459 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 390703
CVE-2015-8349SourceBans <2.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-4975Apache mod_userdir CRLF injection330708 , 390714
CVE-2016-7981SPIP <3.1.2 - Cross-Site Scripting341256 , 341266 , 346755
CVE-2016-8527Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 350147 , 350148
CVE-2017-11629FineCMS <=5.0.10 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2017-12583DokuWiki - Cross-Site Scripting333141 , 346755 , 347198
CVE-2017-12794Django Debug Page - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2017-15287Dreambox WebControl 2.0.0 - Cross-Site Scripting341266 , 346755
CVE-2017-18024AvantFAX 3.3.3 - Cross-Site Scripting340147 , 340148 , 342259 , 346755 , 350148
CVE-2017-18536WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2017-3132Fortinet FortiOS < 5.6.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148 , 390727 , 392301 , 392648
CVE-2017-5631KMCIS CaseAware - Cross-Site Scripting340147 , 341266 , 342259 , 346755 , 350147 , 350148 , 360030
CVE-2017-5868OpenVPN Access Server 2.1.4 - CRLF Injection330708 , 390714
CVE-2017-6478MaNGOSWebV4 < 4.0.8 - Cross-Site Scripting341266 , 346755
CVE-2017-7391Magmi 0.7.22 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2017-7855IceWarp WebMail 11.3.1.5 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2017-9140Reflected XSS - Telerik Reporting Module333141 , 341256 , 342259 , 346755
CVE-2017-9506Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery382291
CVE-2018-1000129Jolokia 1.3.7 - Cross-Site Scripting346755 , 347198
CVE-2018-10095Dolibarr <7.0.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2018-10230Zend Server <9.13 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-11227Monstra CMS <=3.0.4 - Cross-Site Scripting333141 , 340248 , 342259 , 346755
CVE-2018-11709WordPress wpForo Forum <= 1.4.11 - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-12300Seagate NAS OS 4.3.15.1 - Open Redirect340163
CVE-2018-12998Zoho manageengine - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-13380Fortinet FortiOS - Cross-Site Scripting333141 , 340147 , 341266 , 342259 , 347198
CVE-2018-14013Synacor Zimbra Collaboration Suite Collaboration <8.8.11 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-16139BIBLIOsoft BIBLIOpac 2008 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147
CVE-2018-16979Monstra CMS 3.0.4 - HTTP Header Injection330708 , 390722
CVE-2018-17082Apache2 - Transfer-Encoding Chunked XSS392301
CVE-2018-18069WordPress sitepress-multilingual-cms 3.6.3 - Cross-Site Scripting392301
CVE-2018-18570Planon <Live Build 41 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2018-18608DedeCMS 5.7 SP2 - Cross-Site Scripting340147 , 341266 , 346755
CVE-2018-18775Microstrategy Web 7 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2018-19439Oracle Secure Global Desktop Administration Console 4.4 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 390585
CVE-2018-19877Adiscon LogAnalyzer <4.1.7 - Cross-Site Scripting340147 , 341266 , 342259 , 360030
CVE-2018-20824Atlassian Jira WallboardServlet <7.13.1 - Cross-Site Scripting346755 , 347198
CVE-2018-5230Atlassian Jira Confluence - Cross-Site Scripting340112 , 340147 , 346755
CVE-2018-5233Grav CMS <1.3.0 - Cross-Site Scripting341266
CVE-2018-5316WordPress SagePay Server Gateway for WooCommerce <1.0.9 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2018-5715SugarCRM 3.5.1 - Cross-Site Scripting340147 , 340148 , 341245 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-7653YzmCMS v3.6 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2018-8006Apache ActiveMQ <=5.15.5 - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-0221Apache Tomcat - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350148
CVE-2019-1010287Timesheet Next Gen <=1.5.3 - Cross-Site Scripting340147 , 342259 , 346755 , 350147 , 350148
CVE-2019-10475Jenkins build-metrics 1.3 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2019-12461WebPort 1.19.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-12581Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting340147 , 341266 , 342259
CVE-2019-13392MindPalette NateMail 3.0.15 - Cross-Site Scripting342259 , 350147 , 350148
CVE-2019-14950WP Live Chat Support <= 8.0.27 — Stored Cross-Site Scripting344370 , 346755 , 380026
CVE-2019-14974SugarCRM Enterprise 9.0.0 - Cross-Site Scripting340112 , 346755 , 350148
CVE-2019-15501L-Soft LISTSERV <16.5-2018a - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-18957MicroStrategy Library <11.1.3 - Cross-Site Scripting346755 , 347198
CVE-2019-19134WordPress Hero Maps Premium <=2.2.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2019-19368Rumpus FTP Web File Manager 8.2.9.1 - Cross-Site Scripting342259 , 350147
CVE-2019-19908phpMyChat-Plus 1.98 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-20141WordPress Laborator Neon Theme 2.0 - Cross-Site Scripting333141 , 340099 , 340147 , 341099 , 342259 , 347198 , 350147 , 350148
CVE-2019-20210WordPress CTHthemes - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-3402Jira < 8.1.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 , 390585
CVE-2019-3911LabKey Server Community Edition <18.3.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-6112WordPress Sell Media 2.4.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2019-6802Pypiserver <1.2.5 - Carriage Return Line Feed Injection330708 , 390714
CVE-2019-7219Zarafa WebApp <=2.0.1.47791 - Cross-Site Scripting342259 , 346755 , 347198 , 350147 , 350148
CVE-2019-7255Linear eMerge E3 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2019-8937HotelDruid 2.3.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-11930WordPress GTranslate <2.8.52 - Cross-Site Scripting340147 , 341266 , 346755
CVE-2020-12054WordPress Catch Breadcrumb <1.5.4 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2020-13258Contentful <=2020-05-21 - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-13820Extreme Management Center 8.4.1.24 - Cross-Site Scripting333141 , 340149 , 342259 , 346755
CVE-2020-14413NeDi 1.9C - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2020-15500TileServer GL <=3.0.0 - Cross-Site Scripting333141 , 341245 , 341256 , 342259 , 346755 , 350147
CVE-2020-15718RosarioSIS 6.7.2 - Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2020-17362Nova Lite < 1.3.9 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-19282Jeesns 1.4.2 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2020-19283Jeesns 1.4.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-19295Jeesns 1.4.2 - Cross-Site Scripting341266
CVE-2020-1943Apache OFBiz <=16.11.07 - Cross-Site Scripting347198
CVE-2020-19515qdPM 9.1 - Cross-site Scripting340099 , 341099 , 346755 , 347198
CVE-2020-2096Jenkins Gitlab Hook <=1.4.2 - Cross-Site Scripting341266
CVE-2020-23517Aryanic HighMail (High CMS) - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-24223Mara CMS 7.5 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2020-24701OX Appsuite - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2020-24902Quixplorer <=2.4.1 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2020-24903Cute Editor for ASP.NET 6.4 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2020-25495SCO Openserver 5.0.7 - 'section' Reflected XSS340147 , 341266 , 342259 , 390585
CVE-2020-25864HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site Scripting392301
CVE-2020-27735Wing FTP 6.4.4 - Cross-Site Scripting346755 , 350148
CVE-2020-27982IceWarp WebMail 11.4.5.0 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2020-29164PacsOne Server <7.1.1 - Cross-Site Scripting333141 , 340099 , 340147 , 341099 , 346755 , 360030
CVE-2020-3580Cisco ASA/FTD Software - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2020-6171CLink Office 2.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-8115Revive Adserver <=5.0.3 - Cross-Site Scripting346755 , 350148
CVE-2020-8191Citrix ADC/Gateway - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2020-8512IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198
CVE-2020-9344Jira Subversion ALM for Enterprise <8.8.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-20137Gryphon Tower - Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-21799Advantech R-SeeNet 2.4.12 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-21800Advantech R-SeeNet 2.4.12 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-21801Advantech R-SeeNet - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-21802Advantech R-SeeNet - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-21803Advantech R-SeeNet - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-24210WordPress PhastPress <1.111 - Open Redirect340162 , 340163
CVE-2021-24235WordPress Goto Tour & Travel Theme <2.0 - Cross-Site Scripting333141 , 340099 , 340149 , 341099 , 341256 , 342259 , 344370 , 346755 , 347198 , 350148 , 390722
CVE-2021-24237WordPress Realteo <=1.2.3 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-24275Popup by Supsystic <1.10.5 - Cross-Site scripting341266 , 346755
CVE-2021-24276WordPress Supsystic Contact Form <1.7.15 - Cross-Site Scripting341266 , 346755
CVE-2021-24291WordPress Photo Gallery by 10Web <1.5.69 - Cross-Site Scripting347198
CVE-2021-24316WordPress Mediumish Theme <=1.0.47 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24387WordPress Pro Real Estate 7 Theme <3.1.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2021-24389WordPress FoodBakery <2.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24435WordPress Titan Framework plugin <= 1.12.1 - Cross-Site Scripting333141 , 340149 , 341245 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-24495Wordpress Marmoset Viewer <1.9.3 - Cross-Site Scripting333141 , 340147 , 340148 , 340162 , 340163 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148
CVE-2021-24498WordPress Calendar Event Multi View <1.4.01 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2021-24838WordPress AnyComment <0.3.5 - Open Redirect390145
CVE-2021-24910WordPress Transposh Translation <1.0.8 - Cross-Site Scripting340099 , 341099 , 347198
CVE-2021-24987WordPress Super Socializer <7.13.30 - Cross-Site Scripting340099 , 341099 , 346755 , 347198
CVE-2021-25016Chaty < 2.8.2 - Cross-Site Scripting341266 , 346755 , 347198
CVE-2021-25074WordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open Redirect340162 , 340163
CVE-2021-25085WOOF WordPress plugin - Cross-Site Scripting340099 , 341099 , 347198
CVE-2021-26247Cacti - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-26475EPrints 3.4.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-26702EPrints 3.4.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-26710Redwood Report2Web 4.3.4.5 & 4.5.3 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-26723Jenzabar 9.2x-9.2.2 - Cross-Site Scripting340147 , 341266 , 342259 , 350147 , 350148
CVE-2021-26947Odoo <= 15.0 - Cross-Site Scripting333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198
CVE-2021-27309Clansphere CMS 2011.4 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-27310Clansphere CMS 2011.4 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-27330Triconsole Datepicker Calendar <3.77 - Cross-Site Scripting340147 , 341266 , 346755
CVE-2021-27519FUDForum 3.1.0 - Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-27520FUDForum 3.1.0 - Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-29625Adminer <=4.8.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-3002Seo Panel 4.8.0 - Cross-Site Scripting333141 , 340147 , 346755
CVE-2021-30049SysAid Technologies 20.3.64 b14 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-30134Php-mod/curl Library <2.3.2 - Cross-Site Scripting333141 , 342259 , 346755 , 347198 , 350148
CVE-2021-30203Dzzoffice 2.02.1 - Cross-Site Scripting333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2021-30213Knowage Suite 7.3 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-31537SIS Informatik REWE GO SP17 <7.7 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-31589BeyondTrust Secure Remote Access Base <=6.0.1 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198
CVE-2021-31682WebCTRL OEM <= 6.5 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-31862SysAid 20.4.74 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2021-32478Moodle 3.8-3.10.3 - Reflected XSS & Open Redirect346755 , 350148
CVE-2021-34630GTranslate < 2.8.65 - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-35265MaxSite CMS > V106 - Cross-Site Scripting346755 , 347198
CVE-2021-35488Thruk 2.40-2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-36450Verint Workforce Optimization 15.2.8.10048 - Cross-Site Scripting350147
CVE-2021-37416Zoho ManageEngine ADSelfService Plus <=6103 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 390585
CVE-2021-37573Tiny Java Web Server - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2021-37833Hotel Druid 3.0.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-3831Gnuboard 5 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2021-38702Cyberoam NetGenie Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-38704ClinicCases 7.3.3 Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-40272IRTS OP5 Monitor - Cross-Site Scripting346755 , 347198
CVE-2021-40542Opensis-Classic 8.0 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2021-40868Cloudron 6.2 Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-41878i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)340099 , 340147 , 341099 , 346755 , 347198
CVE-2021-41951Resourcespace - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 , 390585
CVE-2021-42551NetBiblio WebOPAC - Cross-Site Scripting341245 , 344370 , 346755
CVE-2021-42565myfactory FMS - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-42567Apereo CAS Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 350148
CVE-2021-43062Fortinet FortiMail 7.0.1 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-43574Atmail 6.5.0 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2021-43725Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-43810Admidio - Cross-Site Scripting340112 , 350148 , 390722
CVE-2021-45380AppCMS - Cross-Site Scripting340147 , 341266 , 342259 , 350147 , 350148
CVE-2021-45422Reprise License Manager 14.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-46387Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147
CVE-2022-0087Keystone 6 Login Page - Open Redirect and Cross-Site Scripting333140 , 346755 , 350148
CVE-2022-0201WordPress Permalink Manager <2.2.15 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198
CVE-2022-0208WordPress Plugin MapPress <2.73.4 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-0212WordPress Spider Calendar <=1.5.65 - Cross-Site Scripting341266 , 346755 , 347198
CVE-2022-0234WordPress WOOCS < 1.3.7.5 - Cross-Site Scripting346755 , 347198
CVE-2022-0250Redirection for Contact Form 7 < 2.5.0 - Cross-Site Scripting341266 , 346755
CVE-2022-0271LearnPress <4.1.6 - Cross-Site Scripting340099 , 341099 , 346755 , 347198
CVE-2022-0346WordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code Execution333141 , 340165 , 341256 , 342259 , 344370 , 346755 , 347198 , 350148
CVE-2022-0429WP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Cross-Site Scripting347198
CVE-2022-0437karma-runner DOM-based Cross-Site Scripting340112 , 346755 , 350148
CVE-2022-0653Wordpress Profile Builder Plugin Cross-Site Scripting340112
CVE-2022-0678Microweber <1.2.11 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-0879Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 344361 , 344364 , 346755 , 347198 , 350148
CVE-2022-1168WordPress WP JobSearch <1.5.1 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198
CVE-2022-1170JobMonster < 4.5.2.9 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-1221WordPress Gwyn's Imagemap Selector <=0.3.3 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-1439Microweber <1.2.15 - Cross-Site Scripting346755 , 347198 , 350148
CVE-2022-1904WordPress Easy Pricing Tables <3.2.1 - Cross-Site Scripting341266 , 346755
CVE-2022-1906WordPress Copyright Proof <=4.16 - Cross-Site-Scripting341266 , 346755
CVE-2022-1910WordPress Shortcodes and Extra Features for Phlox <2.9.8 - Cross-Site Scripting341266 , 346755
CVE-2022-1933WordPress CDI <5.1.9 - Cross Site Scripting341266 , 346755
CVE-2022-1946WordPress Gallery <2.0.0 - Cross-Site Scripting341266 , 346755
CVE-2022-2130Microweber < 1.2.17 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-2174microweber 1.2.18 - Cross-site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-2187WordPress Contact Form 7 Captcha <0.1.2 - Cross-Site Scripting341266 , 346755
CVE-2022-22242Juniper Web Device Manager - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-2290Trilium <0.52.4 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2022-23397Cedar Gate EZ-NET <= 6.8.0 - Cross-Site Scripting333141 , 340099 , 340147 , 341099 , 341256 , 346755 , 347198
CVE-2022-23808phpMyAdmin < 5.1.2 - Cross-Site Scripting341266 , 346755
CVE-2022-24384SmarterTools SmarterTrack - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147
CVE-2022-24899Contao <4.13.3 - Cross-Site Scripting341266
CVE-2022-25323ZEROF Web Server 2.0 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2022-26564HotelDruid Hotel Management Software 3.0.3 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-27926Zimbra Collaboration (ZCS) - Cross Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-28290WordPress Country Selector <1.6.6 - Cross-Site Scripting340130 , 346755
CVE-2022-28363Reprise License Manager 14.2 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-28508MantisBT < 2.25.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-30489Wavlink WN-535G3 - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2022-30776Atmail 6.5.0 - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755
CVE-2022-30777Parallels H-Sphere 3.6.1713 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-31299Haraj 3.7 - Cross-Site Scripting340147 , 341266
CVE-2022-31373SolarView Compact 6.00 - Cross-Site Scripting341266
CVE-2022-31798Nortek Linear eMerge E3-Series - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198
CVE-2022-32195Open edX <2022-06-06 - Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755
CVE-2022-3242Microweber <1.3.2 - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-32770WWBN AVideo 11.6 - Cross-Site Scripting333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-32771WWBN AVideo 11.6 - Cross-Site Scripting333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-32772WWBN AVideo 11.6 - Cross-Site Scripting333140 , 340147 , 341266 , 342259
CVE-2022-33119NUUO NVRsolo Video Recorder 03.06.02 - Cross-Site Scripting340003 , 340158 , 342259
CVE-2022-34048Wavlink WN-533A8 - Cross-Site Scripting392301
CVE-2022-34093Software Publico Brasileiro i3geo v7.0.5 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-34094Software Publico Brasileiro i3geo v7.0.5 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-34328PMB 7.3.10 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-3484WordPress WPB Show Core - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2022-35416H3C SSL VPN <=2022-07-10 - Cross-Site Scripting342259 , 346755
CVE-2022-35493eShop 3.0.4 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-35653Moodle LTI module Reflected - Cross-Site Scripting333141 , 342259 , 346755 , 350147 , 350148
CVE-2022-37153Artica Proxy 4.30.000000 - Cross-Site Scripting340147 , 340148 , 342259 , 346755
CVE-2022-3766phpMyFAQ < 3.1.8 - Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755 , 350148
CVE-2022-38463ServiceNow - Cross-Site Scripting346755 , 350148
CVE-2022-38467CRM Perks Forms < 1.1.1 - Cross Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350148 , 390720
CVE-2022-38553Academy Learning Management System <5.9.1 - Cross-Site Scripting340147 , 341266 , 342259 , 350147 , 350148
CVE-2022-39195LISTSERV 17 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-40359Kae's File Manager <=1.4.7 - Cross-Site Scripting340147 , 341266 , 346755
CVE-2022-41441ReQlogic v11.3 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-41473RPCMS 3.0.2 - Cross-Site Scripting340147 , 341266 , 342259 , 350148
CVE-2022-42118Liferay Portal - Cross-site Scripting340147 , 341266 , 342259 , 350148
CVE-2022-42746CandidATS 3.0.0 - Cross-Site Scripting.341266 , 346755
CVE-2022-42747CandidATS 3.0.0 - Cross-Site Scripting.341266 , 346755
CVE-2022-42748CandidATS 3.0.0 - Cross-Site Scripting.341266 , 346755
CVE-2022-42749CandidATS 3.0.0 - Cross-Site Scripting341266 , 346755
CVE-2022-4295Show all comments < 7.0.1 - Cross-Site Scripting341266
CVE-2022-4301WordPress Sunshine Photo Cart <2.9.15 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-4320WordPress Events Calendar <1.4.5 - Cross-Site Scripting340748 , 341266 , 346755 , 347006
CVE-2022-4321PDF Generator for WordPress < 1.1.2 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-45836WordPress Download Manager <= 3.2.59 - Reflected XSS333141 , 340149 , 341256 , 342259 , 346755
CVE-2022-46073Helmet Store Showroom - Cross Site Scripting340147 , 341266 , 342259 , 350147 , 350148
CVE-2022-46381Linear eMerge E3-Series - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2022-46888NexusPHP <1.7.33 - Cross-Site Scripting340147 , 341266 , 342259 , 346755 , 350147 , 350148 , 360030
CVE-2022-48197Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-0334ShortPixel Adaptive Images < 3.6.3 - Cross Site Scripting340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-0448WP Helper Lite < 4.3 - Cross-Site Scripting346755 , 347198
CVE-2023-0527Online Security Guards Hiring System - Cross-Site Scripting333141 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2023-1119WP-Optimize WordPress plugin < 3.2.13 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-1880Phpmyfaq v3.1.11 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-2309wpForo Forum <= 2.1.8 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2023-23161Art Gallery Management System Project v1.0 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2023-23491Quick Event Manager < 9.7.5 - Cross-Site Scripting341266 , 346755
CVE-2023-24278Squidex <7.4.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2023-24322mojoPortal 2.7.0.0 - Cross-Site Scripting346755 , 350148
CVE-2023-24367Temenos T24 R20 - Cross-Site Scripting341266
CVE-2023-24488Citrix Gateway and Citrix ADC - Cross-Site Scripting340099 , 340147 , 341099 , 341266 , 342259 , 360151 , 390722
CVE-2023-24733PMB 7.4.6 - Cross-Site Scripting340147 , 341266 , 342259 , 350148
CVE-2023-24737PMB v7.4.6 - Cross-Site Scripting340147 , 341266 , 342259 , 350148
CVE-2023-27008ATutor < 2.2.1 - Cross Site Scripting344363 , 346755 , 350148
CVE-2023-27641L-Soft LISTSERV 16.5 - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-2813Wordpress Multiple Themes - Reflected Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2023-2822Ellucian Ethos Identity CAS - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-29489cPanel < 11.109.9999.116 - Cross-Site Scripting340099 , 340147 , 341099 , 346755
CVE-2023-2949OpenEMR < 7.0.1 - Cross-site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2023-29623Purchase Order Management v1.0 - Cross Site Scripting (Reflected)333141 , 340147 , 340148 , 342259 , 346755
CVE-2023-30210OURPHP <= 7.2.0 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2023-30212OURPHP <= 7.2.0 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-30256Webkul QloApps 1.5.2 - Cross-site Scripting333141 , 340149 , 341256 , 346755 , 347198
CVE-2023-3169tagDiv Composer < 4.2 - Stored Cross-Site Scripting380026
CVE-2023-3479Hestiacp <= 1.7.7 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-35155XWiki - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198
CVE-2023-35156XWiki >= 6.0-rc-1 - Cross-Site Scripting346755 , 350148
CVE-2023-35158XWiki - Cross-Site Scripting346755 , 350148
CVE-2023-35159XWiki >= 3.4-milestone-1 - Cross-Site Scripting346755 , 350148
CVE-2023-35160XWiki >= 2.5-milestone-2 - Cross-Site Scripting346755 , 350148
CVE-2023-35161XWiki >= 6.2-milestone-1 - Cross-Site Scripting346755 , 350148
CVE-2023-35162XWiki < 14.10.5 - Cross-Site Scripting346755 , 350148
CVE-2023-3521FOSSBilling < 0.5.3 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-36287Webkul QloApps 1.6.0 - Cross-site Scripting350148
CVE-2023-36289Webkul QloApps 1.6.0 - Cross-site Scripting333141 , 340149 , 341256 , 346755
CVE-2023-36306Adiscon LogAnalyzer v.4.1.13 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-36346POS Codekop v2.0 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2023-37728IceWarp Webmail Server v10.2.1 - Cross Site Scripting333141 , 341256 , 342259 , 346755 , 347198
CVE-2023-38192SuperWebMailer 9.00.0.01710 - Cross-Site Scripting340147 , 340148 , 342259 , 346755
CVE-2023-38194SuperWebMailer - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-3843mooDating 1.2 - Cross-site scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3844MooDating 1.2 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3845MooDating 1.2 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3846MooDating 1.2 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3847MooDating 1.2 - Cross-Site scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3848MooDating 1.2 - Cross-site scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3849mooDating 1.2 - Cross-site scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-38501CopyParty v1.8.6 - Cross Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148 , 390722
CVE-2023-38875PHP Login System 2.0.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-38964Academy LMS 6.0 - Cross-Site Scripting333141 , 342259 , 347198 , 350147 , 350148
CVE-2023-39598IceWarp Email Client - Cross Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147
CVE-2023-39600IceWarp 11.4.6.0 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-39676PrestaShop fieldpopupnewsletter Module - Cross Site Scripting341266 , 346755
CVE-2023-39700IceWarp Mail Server v10.4.5 - Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-40750PHPJabbers Yacht Listing Script v1.0 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-40751PHPJabbers Fundraising Script v1.0 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-40752PHPJabbers Make an Offer Widget v1.0 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-4110PHPJabbers Availability Booking Calendar 5.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4111PHPJabbers Bus Reservation System 1.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4112PHPJabbers Shuttle Booking Software 1.0 - Cross Site Scripting340147 , 341266 , 346755
CVE-2023-4113PHPJabbers Service Booking Script 1.0 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4114PHP Jabbers Night Club Booking 1.0 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4115PHPJabbers Cleaning Business 1.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4116PHPJabbers Taxi Booking 2.0 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4136CrafterCMS Engine - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2023-41538PHPJabbers PHP Forum Script 3.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-41621Emlog Pro v2.1.14 - Cross-Site Scripting346755 , 350148
CVE-2023-4173mooSocial 3.1.8 - Reflected XSS340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-4174mooSocial 3.1.6 - Reflected Cross Site Scripting333141 , 340099 , 340147 , 341099 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-42343OpenCMS - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-43325MooSocial 3.1.8 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-43326MooSocial 3.1.8 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-44012mojoPortal v.2.7.0.0 - Cross-Site Scripting333141 , 341256 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148
CVE-2023-44352Adobe Coldfusion - Cross-Site Scripting340099 , 340147 , 341099 , 341266 , 346755 , 347198
CVE-2023-4451Cockpit - Cross-Site Scripting340099 , 341099 , 346755 , 347198
CVE-2023-4547SPA-Cart eCommerce CMS 1.9.0.3 - Cross-Site Scripting333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-45542MooSocial 3.1.8 - Cross-Site Scripting340147 , 341266 , 342259 , 350147 , 350148
CVE-2023-46732XWiki < 14.10.14 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-47684Essential Grid <= 3.1.0 - Cross-Site Scripting341266 , 346755
CVE-2023-48728WWBN AVideo 11.6 - Cross-Site Scripting340147 , 340148 , 341245 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-49293Vite dev server - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-49489KodeExplorer 4.51 - Reflective Cross Site Scripting (XSS)342259 , 346755
CVE-2023-49494DedeCMS v5.7.111 - Cross-Site Scripting333141 , 340087 , 340095 , 340099 , 340149 , 341099 , 341256 , 342259 , 346755
CVE-2023-4973Academy LMS 6.2 - Cross-Site Scripting340147 , 346755 , 350148
CVE-2023-5244Microweber < V.2.0 - Cross-Site Scripting346755 , 380026 , 393655
CVE-2023-5863phpMyFAQ < 3.2.0 - Cross-site Scripting333141 , 340248 , 342259 , 346755 , 350148
CVE-2023-6275TOTVS Fluig Platform - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-6379OpenCMS 14 & 15 - Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-6568Mlflow - Cross-Site Scripting334168 , 391213
CVE-2024-0250Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect340162 , 340163
CVE-2024-12585PropertyHive < 2.1.1 - Cross-Site Scripting341266 , 346755
CVE-2024-13727MemberSpace WordPress - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-24131SuperWebMailer 9.31.0.01799 - Cross-Site Scripting341266 , 346755
CVE-2024-25669CaseAware a360inc - Cross-Site Scripting347198
CVE-2024-28734Coda v.2024Q1 - Cross-Site Scripting340112 , 340113 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-3231Popup4Phone <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-33326LumisXP - Cross-site Scripting340147 , 341266 , 342259
CVE-2024-35693WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755 , 347198
CVE-2024-35694Wordpress WPMobile.App >= 11.42 - Cross-Site Scripting340147 , 341266
CVE-2024-37259WP Extended < 3.0.0 - Stored Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755
CVE-2024-55218IceWarp Server 10.2.1 - Cross-Site Scripting333141 , 341256 , 342259 , 346755
CVE-2024-6892Journyx 11.5.4 - Reflected Cross Site Scripting333141
CVE-2025-1303Plugin Oficial – Getnet para WooCommerce <= 1.8.0 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2025-2609MagnusBilling Login Logs - Cross-Site Scripting333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2025-27506NocoDB < 0.258.0 - Reflected XSS in Password Reset341266 , 347198
CVE-2025-32970XWiki WYSIWYG API - Open Redirect340162 , 340163
CVE-2025-46349YesWiki Reflected XSS via File Upload333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-46549YesWiki <= 4.5.1 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2025-46550YesWiki < 4.5.4 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2025-47204Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-48954Discourse OAuth Social Login - Cross-site Scripting333141 , 341256 , 342259 , 344362 , 346755 , 347198 , 350148 , 390712
CVE-2025-5301ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-54589Copyparty <=1.18.6 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-6174WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)340147 , 341266 , 342259
CVE-2026-25616Blesta <= 5.13.1 - Cross-Site Scripting340112 , 346755 , 350148
CVE-2026-29183SiYuan Note - Cross-Site Scripting300013 , 340147 , 341266 , 347198
CVE-2025-46565Vite Dev Server - Information Exposure390709
CVE-2024-13609WordPress 1 Click Migration Plugin < 2.3 - Information Exposure350590 , 390716
CVE-2025-41242Spring Framework - Path Traversal347009
CVE-2010-0467Joomla! Component CCNewsLetter - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-4982Forescout CounterACT 6.3.4.1 - Open Redirect340162 , 340163
CVE-2012-6499WordPress Plugin Age Verification v0.4 - Open Redirect392301
CVE-2020-5775Canvas LMS v2020-07-29 - Blind Server-Side Request Forgery340162 , 340163
CVE-2018-13980Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2025-10090Jinher OA - SQL Injection344366 , 361149
CVE-2025-6403Code-Projects School Fees Payment System 1.0 - SQL Injection340157 , 360147 , 360148 , 380026 , 380122
CVE-2025-7160Zoo Management System 1.0 - SQL Injection340145 , 340156
CVE-2025-9744Loan Management System 1.0 - SQL Injection340156 , 341145
CVE-2017-14186FortiGate FortiOS SSL VPN Web Portal - Cross-Site Scripting346755 , 350148
CVE-2018-12095OEcms 3.1 - Cross-Site Scripting340147 , 340148 , 341266 , 346755
CVE-2018-15917Jorani Leave Management System 0.6.5 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-8024Apache Spark UI - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-11370Carel pCOWeb <B1.2.4 - Cross-Site Scripting342259
CVE-2020-12262Intelbras TIP200/TIP200LITE/TIP300 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2020-20285ZZcms - Cross-Site Scripting333141 , 340003 , 340099 , 341099 , 342259
CVE-2020-35774twitter-server Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-31250CHIYU TCP/IP Converter - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2022-0378Microweber Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2022-25489Atom CMS v2.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2023-34537Hoteldruid 3.0.5 - Cross-Site Scripting340130 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-33724SOPlanning 1.52.00 Cross Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-52762Ganglia Web Interface (v3.7.3 - v3.7.6) - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-52763Ganglia Web Interface (v3.7.3 - v3.7.5) - Cross-Site Scripting333141 , 340149 , 341256 , 342259 , 346755 , 347198
CVE-2026-1207Django RasterField - SQL Injection341245
CVE-2014-8676SO Planning 1.32 - Multiple Vulnerabilities331028 , 340007 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344360 , 344363 , 344370 , 347009 , 360147 , 360148 , 360153 , 390709 , 390726 , 392647
CVE-2014-9609Netsweeper 4.0.8 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2015-5471Swim Team <= v1.44.10777 - Local File Inclusion344360 , 347009 , 390709
CVE-2018-16059WirelessHART Fieldgate SWG70 3.0 - Local File Inclusion392301
CVE-2018-3167Oracle E-Business Suite - Blind SSRF392301
CVE-2019-17503Kirona-DRS 5.5.3.5 - Information Disclosure312863 , 340147 , 340148 , 341266 , 342259 , 344370 , 346755 , 390716
CVE-2019-18393Ignite Realtime Openfire <4.42 - Local File Inclusion344365 , 347019
CVE-2019-8446Jira Improper Authorization392301
CVE-2020-11798Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal340007 , 344360 , 347009
CVE-2020-13886Intelbras TIP 200/200 LITE/300 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2021-20150Trendnet AC2600 TEW-827DRU - Credentials Disclosure392301
CVE-2021-23241MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusion347009
CVE-2021-28377Joomla! ChronoForums 2.0.11 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2022-28666Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update392301
CVE-2023-2059DedeCMS 5.7.87 - Directory Traversal340007 , 347019
CVE-2023-30943Moodle - Cross-Site Scripting/Remote Code Execution333141 , 340007 , 340099 , 340147 , 340148 , 340149 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-41599JFinalCMS v5.0.0 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2024-11305Altenergy Power Control Software - SQL Injection340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2024-11587idcCMS V1.60 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2024-20404Cisco Finesse - Server-Side Request Forgery (SSRF)392301
CVE-2024-28397pyload-ng js2py - Remote Code Execution340014 , 344363 , 346755 , 360151 , 380026
CVE-2024-51977Brother MFC-L9570CDW - Information Disclosure390709
CVE-2024-7928FastAdmin < V1.3.4.20220530 - Path Traversal340007
CVE-2024-9007123Solar 1.8.4.5 - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-2127JoomlaUX JUX Real Estate 3.4.0 - Reflected XSS340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-2709Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-2711Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-2712Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-31486Vite server.fs.deny Bypass - Local File Inclusion347009 , 390709
CVE-2025-4078Wangshen SecGate 3600 Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2025-5569IdeaCMS <= 1.7 - SQL Injection341245
CVE-2011-0518LotusCMS 3.0 - Remote Code Execution340095 , 393655
CVE-2025-34032Moodle LMS Jmol Plugin <= 6.1 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2025-34141ETQ Reliance - Reflected XSS via SQLConverterServlet333141 , 340099 , 340147 , 341099 , 342259 , 347198
CVE-2025-41393Ricoh Web Image Monitor - Reflected XSS340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2025-53533Pi-hole Reflected XSS in 404-Error Page346755 , 347198
CVE-2026-27176MajorDoMo - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148 , 390501
CVE-2000-0114Microsoft FrontPage Extensions - Information Disclosure310226 , 392301
CVE-2006-3392Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure347009
CVE-2007-4504Joomla! RSfiles <=1.0.2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2008-4764Joomla! <=2.0.0 RC2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2008-6080Joomla! ionFiles 4.4.2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2008-6222Joomla! ProDesk 1.0/1.2 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2008-6668nweb2fax <=0.2.7 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2009-1496Joomla! Cmimarketplace 0.1 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2009-2100Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2009-5114WebGlimpse 2.18.7 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2010-0696Joomla! Component Jw_allVideos - Arbitrary File Retrieval340007 , 344360 , 347009 , 390709
CVE-2010-0942Joomla! Component com_jvideodirect - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0943Joomla! Component com_jashowcase - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0944Joomla! Component com_jcollection - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1081Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1302Joomla! Component DW Graph - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1304Joomla! Component User Status - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1305Joomla! Component JInventory 1.23.02 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1307Joomla! Component Magic Updater - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1308Joomla! Component SVMap 1.1.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1312Joomla! Component News Portal 1.5.x - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1314Joomla! Component Highslide 1.5 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1315Joomla! Component webERPcustomer - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1340Joomla! Component com_jresearch - 'Controller' Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1345Joomla! Component Cookex Agency CKForms - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1352Joomla! Component Juke Box 1.7 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1353Joomla! Component LoginBox - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1354Joomla! Component VJDEO 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1429Red Hat JBoss Enterprise Application Platform - Sensitive Information Disclosure382240
CVE-2010-1461Joomla! Component Photo Battle 1.0.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1491Joomla! Component MMS Blog 2.3.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1494Joomla! Component AWDwall 1.5.4 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1532Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1534Joomla! Component Shoutbox Pro - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1540Joomla! Component com_blog - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1601Joomla! Component JA Comment - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1657Joomla! Component SmartSite 1.0.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1658Joomla! Component NoticeBoard 1.3 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1659Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1714Joomla! Component Arcade Games 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1858Joomla! Component SMEStorage - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1982Joomla! Component JA Voice 2.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2018Lokomedia CMS - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2010-2307Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal347009
CVE-2010-3203Joomla! Component PicSell 1.0 - Arbitrary File Retrieval340007 , 344360
CVE-2011-0049Majordomo2 - SMTP/HTTP Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2011-1669WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI)340007 , 344360 , 347009 , 390709
CVE-2011-2780Chyrp 2.x - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2011-4804Joomla! Component com_kp - 'Controller' Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-0896Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access344360 , 347009 , 390709
CVE-2012-0981phpShowtime 2.0 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2012-099611in1 CMS 1.2.1 - Local File Inclusion (LFI)340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2013-5979Xibo 1.2.2/1.4.1 - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2013-7091Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2013-7240WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversal336461 , 340007 , 344360 , 381206
CVE-2014-4940WordPress Plugin Tera Charts - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2014-5111Fonality trixbox - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2014-5368WordPress Plugin WP Content Source Control - Directory Traversal336461 , 340007 , 344360 , 381206
CVE-2014-6308Osclass Security Advisory 3.4.1 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2014-8799WordPress Plugin DukaPress 2.5.2 - Directory Traversal336461 , 340007 , 344360 , 381206
CVE-2014-9119WordPress DB Backup <=4.5 - Local File Inclusion336461 , 340007 , 344360 , 381206 , 393759
CVE-2015-1579WordPress Slider Revolution - Local File Disclosure336461 , 337479 , 344360 , 381206
CVE-2015-2067Magento Server MAGMI - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2015-2166Ericsson Drutt MSDP - Local File Inclusion347009
CVE-2015-3897Bonita BPM Portal <6.5.3 - Local File Inclusion340007 , 344360
CVE-2015-4414WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2015-4666Xceedium Xsuite - Multiple Vulnerabilities320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347009 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2015-5531ElasticSearch <1.6.1 - Local File Inclusion347009 , 392301
CVE-2015-5688Geddy <13.0.8 - Local File Inclusion347009
CVE-2019-2588Oracle Business Intelligence - Path Traversal340007 , 344365 , 347019
CVE-2023-34259Kyocera TASKalfa printer - Path Traversal347009
CVE-2017-14651WSO2 Data Analytics Server 3.1.0 - Cross-Site Scripting333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2020-9314Oracle iPlanet Web Server 7.0.x - Image Injection340162 , 340163
CVE-2023-0563Bank Locker Management System - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2023-45671Frigate < 0.13.0 Beta 3 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2005-3128SquirrelMail Address Add 1.4.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2005-4385Cofax <=2.0RC3 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2007-2449Apache Tomcat 4.x-7.x - Cross-Site Scripting340147 , 341266 , 346755
CVE-2007-5728phpPgAdmin <=4.1.1 - Cross-Site Scripting340147 , 341266 , 346755
CVE-2008-2398AppServ Open Project <=2.5.10 - Cross-Site Scripting333141 , 341256 , 342259 , 346755
CVE-2008-5587phpPgAdmin <=4.2.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2008-6465Parallels H-Sphere 3.0.0 P9/3.1 P1 - Cross-Site Scripting333141 , 340149 , 342259 , 346755 , 347198 , 360030
CVE-2008-6982Devalcms 1.4a - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2009-1872Adobe Coldfusion <=8.0.1 - Cross-Site Scripting340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2010-0982Joomla! Component com_cartweberp - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2010-1217Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1313Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-5278MODx manager - Local File Inclusion340007 , 390613 , 390614
CVE-2011-4618Advanced Text Widget < 2.0.2 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2011-5106WordPress Plugin Flexible Custom Post Type < 0.1.7 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2012-4253MySQLDumper 1.24.4 - Directory Traversal340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-4547AWStats 6.95/7.0 - 'awredir.pl' Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2012-4889ManageEngine Firewall Analyzer 7.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2013-6281WordPress Spreadsheet - Cross-Site Scripting340147 , 341266 , 342259
CVE-2014-100004Sitecore CMS - Cross-Site Scripting333141 , 347198
CVE-2014-2908Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-9444Frontend Uploader <= 0.9.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147
CVE-2015-1880Fortinet FortiOS <=5.2.3 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2015-2068Magento Server Mass Importer - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2015-3337Elasticsearch - Local File Inclusion347009
CVE-2018-18777Microstrategy Web 7 - Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2020-7318McAfee ePolicy Orchestrator <5.10.9 Update 9 - Cross-Site Scripting333141 , 341256 , 342259 , 346755 , 347198
CVE-2024-34061Changedetection.io <=v0.45.21 - Cross-Site Scripting333141 , 340130 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-4348osCommerce v4.0 - Cross-site Scripting340147 , 340148 , 342259 , 350147 , 350148
CVE-2025-22214Landray EIS SQL注入漏洞340155 , 341155 , 341245
CVE-2013-5528Cisco Unified Communications Manager 7/8/9 - Directory Traversal344360 , 347009 , 390709
CVE-2014-5258webEdition 6.3.8.0 - Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2019-19411Huawei Firewall - Local File Inclusion347009 , 390709
CVE-2012-0991OpenEMR 4.1 - Local File Inclusion340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2025-55523Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download344360 , 347009 , 390709
CVE-2025-0133PAN-OS - Reflected Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147
CVE-2025-10210ChanCMS <= 3.3.0 - SQL Injection340157 , 340159 , 341245 , 360147 , 360148
CVE-2025-8266ChanCMS <= 3.1. - Remote Code Execution345240 , 380026
CVE-2018-10818LG NAS Devices - Remote Code Execution340014
CVE-2022-29299SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting341266
CVE-2022-29301SolarView Compact 6.00 - 'pow' Cross-Site Scripting341266
CVE-2022-38322Temenos Transact - Cross-Site Scripting333141
CVE-2023-1434Odoo - Cross-Site Scripting341266
CVE-2025-32101UNA CMS <= 14.0.0-RC4 - PHP Object Injection390501 , 390614