
CVE-2024-50961
Remote attacker can access sensitive data exposed on the URL

Remote attacker can access sensitive data exposed on the URL

Proof-of-concept exploit for stored cross-site scripting (XSS) vulnerability in Code-Projects Blood Bank V1.0 via unsanitized profile parameters,…

Hack The Box - Silentium machine writeup | CVE-2025-58434, CVE-2025-59528, CVE-2025-8110

Proof-of-concept for CVE-2024-48427: SQL injection in Sourcecodester Packers and Movers Management System v1.0. Exploits the id parameter to execute…

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

CVE-2024-42657 An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of…


CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Cross Site Scripting on sanitization-management-system

Best house rental management system Local file contains vulnerability

Documentation of a SQL injection vulnerability in Todesk v1.1 via the title parameter, enabling remote information disclosure through crafted URL…

School Fees Management System v1.0 - Incorrect Access Control - Directory Listing

Privilege Escalation in Teachers Record Management System using CodeIgnitor

CVE-2024-42658 An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookies…

Unauthenticated remote code execution exploit for Vehicle Management System in PHP via unrestricted file upload in newdriver.php and newvehicle.php,…

CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in…

Technical disclosure and proof-of-concept for SQL injection in PuneethReddyHC event-management v1.0, detailing affected endpoint, payloads, and…

Proof-of-concept exploit for CVE-2022-36163, a format string vulnerability in pdftoroff hovacui 1.1.0 PDF reader, demonstrating local…