
CVE-2026-11387
Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

DVR username password recovery.

A vulnerability, which was classified as critical, was found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -

Remote Command Injection Vulnerability (CVE-2007-2447), allows remote attackers to execute arbitrary commands by specifying a Samba username…

Zimbra Collaboration Suite Username Enumeration

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

Username Enumeration in Trivision NC-227WF

Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -

just remeber how small mistake in santisize username could give yoy root access to the full machine

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

Windows ProfSvc 0day

IBM/Lotus Domino exploitation

PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM

Exploit Win10Pcap Driver to enable some Privilege in our process token ( local Privilege escalation )