0xBlackash
114 exploits
Active since Apr 2014
Squid: Memory disclosure in FTP gateway
net: skbuff: propagate shared-frag marker through frag-transfer helpers
Heap Use-After-Free in the PKCS7_verify() Function
Google Chrome - Out-of-Bounds Access
Linux Kernel < 5.15.200 Use-After-Free in nft_map_catchall_activate
Microsoft Defender Elevation of Privilege Vulnerability
Google Android <16-qpr2 - Auth Bypass
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
FreeScout <=1.8.206 - Authenticated RCE
smb: client: reject userspace cifs.spnego descriptions
CVSS 7.1
net: openvswitch: reject oversized nested action attrs
CVSS 7.8
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Microsoft Windows 10 Version 1607 - Active Directory Certificate Services Elevation of Privilege Vulnerability
CVSS 8.8
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Authenticated Remote Code Execution via SAML
CVSS 9.9
xfs: resample the data fork mapping after cycling ILOCK
CVSS 7.8
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
CVSS 9.8
Sonicwall SMA1000 - Server-Side Request Forgery (SSRF)
CVSS 10.0
rtmutex: Use waiter::task instead of current in remove_waiter()
CVSS 7.8
UniFi Network Application 9.0.118-10.1.89, 10.2.97 - Path Traversal
CVSS 10.0
Openeclass < 4.1 - Unrestricted File Upload
CVSS 7.2
Langflow validate exec_globals - Unauthenticated Root Code Execution
CVSS 9.8
Oracle HTTP Server & WebLogic Proxy Plug-in 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 - Unauthenticated Access Control
CVSS 10.0
KVM: x86: Fix shadow paging use-after-free due to unexpected role
CVSS 8.8
Linux Kernel eventpoll - Use-After-Free
CVSS 7.8
NetScaler - Insufficient Input Validation Leading to Memory Overread
CVSS 7.5