Vulnerabilities
50 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-30007 +1 in the same advisory: …30008 | HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands a HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in is_dns_record_format_valid() combined with unsafe eval-based parsing in update_domain_zone() to prematurely close a variable assignment string and achieve full root code execution on the underlying host in a single DNS record creation step. NVD description · AI analysis pending | 8.7 group max | 3% |
| — | ||
| CVE-2026-35184 | EcclesiaCRM is CRM Software for church management. EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0. NVD description · AI analysis pending | 8.7 | <1% | PoC |
| — | |
| CVE-2026-34456 | Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using a victim’s email address and gain full access to the victim's account without knowing their password. This results in a full account takeover with no prior authentication required. This issue has been patched in version 26.2.0-beta.5. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-61506 | An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint. An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2024-0241 | encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter. NVD description · AI analysis pending | 7.5 | 1% | PoC ×2 |
| — | |
| CVE-2023-48887 | A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request. A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2023-46820 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Iulia Cazan Image Regenerate & Select Crop.This issue affects Image Regenerate & Sel Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Iulia Cazan Image Regenerate & Select Crop.This issue affects Image Regenerate & Select Crop: from n/a through 7.3.0. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2023-5839 | Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2023-4517 | Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6. Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-5084 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-3479 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8. Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2021-33396 | Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via ind Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via index.php. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2023-23465 | Media CP Media Control Panel latest version. Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2022-45942 | A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4. A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4. NVD description · AI analysis pending | 8.8 | 22% | PoC ×2 |
| — | |
| CVE-2022-38931 | A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the url parameter. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2022-2542 | The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2022-2541 | The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2022-35150 | Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-30071 | A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a cra A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2021-30070 | An issue was discovered in HestiaCP before v1.3.5. An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2022-2636 +1 in the same advisory: …2626 | Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — | |
| CVE-2022-2550 | OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. NVD description · AI analysis pending | 8.8 | 48% | PoC |
| — | |
| CVE-2022-1509 | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. NVD description · AI analysis pending | 8.8 | 5% | PoC |
| — | |
| CVE-2022-0986 | Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2022-0838 +1 in the same advisory: …0752 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2022-0753 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-25873 | A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 which allows attackers to arbitrarily A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 which allows attackers to arbitrarily delete folders on the server via the "id" parameter. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2021-3797 | hestiacp is vulnerable to Use of Wrong Operator in String Comparison hestiacp is vulnerable to Use of Wrong Operator in String Comparison NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-27231 | Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different custome Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages. NVD description · AI analysis pending | 5.4 | 1% | PoC |
| — | |
| CVE-2020-10375 | An issue was discovered in New Media Smarty before 9.10. An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these obfuscated passwords in the second column. NOTE: this is unrelated to the popular Smarty template engine product. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2020-10966 | In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover b In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name. NVD description · AI analysis pending | 6.5 | 2% | PoC |
| — | |
| CVE-2019-7568 | An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request. An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-19793 | jiacrontab 1.4.5 allows remote attackers to execute arbitrary commands via the crontab/task/edit?addr=localhost%3a20001 command and args parameters, as demonstr jiacrontab 1.4.5 allows remote attackers to execute arbitrary commands via the crontab/task/edit?addr=localhost%3a20001 command and args parameters, as demonstrated by command=cat&args=/etc/passwd in the POST data. NVD description · AI analysis pending | 7.2 | 2% | PoC |
| — | |
| CVE-2018-16724 +1 in the same advisory: …16725 | An issue is discovered in baijiacms V4. An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2018-14089 | An issue was discovered in a smart contract implementation for Virgo_ZodiacToken, an Ethereum token. An issue was discovered in a smart contract implementation for Virgo_ZodiacToken, an Ethereum token. In this contract, 'bool sufficientAllowance = allowance =' (which was intended). An attacker can transfer from any address to his address, and does not need to meet the 'allowance > value' condition. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2018-13646 | The mintToken function of a smart contract implementation for Datiac, an Ethereum token, has an integer overflow that allows the owner of the contract to set th The mintToken function of a smart contract implementation for Datiac, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-10503 | An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edituser, changing the administrator password via op=changepwd, or deleting an account via op=deleteuser. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-10249 | baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account. baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-10219 | baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request. baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2018-10178 | The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisitedSites comma The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisitedSites command. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2017-17526 | Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allo Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2017-8870 | Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file. Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file. NVD description · AI analysis pending | 7.8 | 14% | PoC |
| — | |
| CVE-2017-8869 | Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file. Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file. NVD description · AI analysis pending | 7.8 | 16% |
| — |