
CVE-2019-12475
Stored XSS in MicroStrategy Web prior to 10.4.6

Stored XSS in MicroStrategy Web prior to 10.4.6

Authenticated XSS in Microstrategy Web - Versions prior to 10.1 patch 10

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'filter' in the endpoint…

A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts…

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

FlatPress 1.3. is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which…

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

It was identified that the https://github.com/Volmarg/personal-management-system application is vulnerable to CSRF attacks.

Multiple cross-site scripting (XSS) vulnerabilities in /customer_support/ajax.php?action=save_customer in Customer Support System 1.0 allow…

Exploit for KNet 1.04b Web Server Buffer Overflow SEH

this exemple of application permet to test the vunerability CVE_2017-5638

Exploits Apache HTTP Server CVE-2021-42013 for path traversal and CGI-based remote code execution during penetration testing.

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Ally – Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path

Webkit uxss exploit (CVE-2017-7089)

Proof of concept showing how to exploit the CVE-2018-11759
