0xBlackash
48 exploits
Active since Apr 2014
FreeScout <=1.8.206 - Authenticated RCE
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
ProjeQtor < 12.4.4 Unauthenticated SQL Injection via Login
CVSS 9.8
Zimbra Collaboration <10.2 - LFI
CVSS 8.8
Oracle HTTP Server - Improper Access Control
CVSS 10.0
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
CVSS 8.8
Fortinet FortiSandbox < 5.0.5 - Path Traversal
CVSS 9.8
xz <5.6.0 - Code Injection
CVSS 10.0
n8n <1.123.17, <2.5.2 - Command Injection
CVSS 9.9
CrushFTP - Authentication Bypass
CVSS 9.8
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8
Openeclass < 4.1 - Unrestricted File Upload
CVSS 7.2
Fortinet FortiSandbox < 4.4.8 - Command Injection
CVSS 9.8
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
CVSS 9.1
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVSS 4.8
nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
CVSS 9.8
Zammad has a server-side template injection leading to RCE via AI Agent
CVSS 7.2
Erlang OTP Pre-Auth RCE Scanner and Exploit
CVSS 10.0
Exposed Dangerous Method or Function in GitLab
CVSS 8.5
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
CVSS 8.8
EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
CVSS 9.8
Twonky Server Log Leak Authentication Bypass
CVSS 9.8