- CVE-2025-11235 - Progress MOVEit Transfer - Unverified Password Change
- CVE-2025-43862 - DIFY - Unauthorized Access and Modification of APP Orchestration
- CVE-2025-32795 - DIFY - Insecure User Role Access Control for APP Editing
- CVE-2025-32796 - DIFY - Unauthorized APP Enable/Disable via API
- CVE-2025-32790 - DIFY - Insecure User Role Access Control for APP DSL Exporting
- CVE-2025-43854 - DIFY - DIFY vulnerable to Clickjacking Attack
- CVE-2025-2129 - Mage-AI - Insecure Default Authentication Setup Leading to Zero-Click RCE
- CVE-2023-39610 - TP-Link Tapo C100 - HTTP Denial-Of-Service
- CVE-2023-2479 - Appium Desktop - Zero-Click Remote Code Execution
- CVE-2022-1177 - OPENEMR - Accounting User Can Download Patient Reports
- CVE-2022-1178 - OPENEMR - Stored Cross Site Scripting
- CVE-2022-1179 - OPENEMR - Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting
- CVE-2022-1180 - OPENEMR - Reflected Cross Site Scripting
- CVE-2022-1181 - OPENEMR - Stored Cross Site Scripting
- CVE-2022-1459 - OPENEMR - Non-Privilege User Can View Patient’s Disclosures
- CVE-2022-1461 - OPENEMR - Non Privilege User can Enable or Disable Registered
- CVE-2022-2493 - OPENEMR - Missing Function Level Access Control
- CVE-2021-39192 - Ghost CMS >= 4.0.0 & <= 4.9.0 - Privilege escalation: all users can access Admin-level API keys
zn9988/publications
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|