
CVE-2025-63820
Proof-of-concept of vulnerability found in Totolink A720R router

Proof-of-concept of vulnerability found in Totolink A720R router
Username Enumeration in Trivision NC-227WF


CVE-2025-2539 - WordPress File Away <= 3.9.9.0.1 - Arbitrary File Read

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

CVE-2023-30765 / ZDI-23-905 - Delta Electronics Infrasuite Device Master Privilege Escalation

lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…

CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.

exploit of CVE-2022-0847 which directly remove password of the root account

ThinkAdmin v5 v6 任意文件读取漏洞利用,可自定义字典爆破

Bludit 3.9.2 auth bruteforce bypass

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

Strapi Framework, 3.0.0-beta.17.4

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

CVE-2020-28874

Possible Account Takeover | Brute Force Ability

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

Proof-of-concept demonstrating plaintext password storage vulnerability in Digisol DG-GR1321 routers, enabling credential exposure and unauthorized…