0xBlackash
86 exploits
Active since Apr 2014
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
CVSS 9.8
ChromaDB >=1.0.0 - Unauthenticated Remote Code Execution via Malicious Model Repository
rxrpc: fix oversized RESPONSE authenticator length check
CVSS 7.5
Microsoft Defender Elevation of Privilege Vulnerability
CVSS 7.8
ptrace: slightly saner 'get_dumpable()' logic
CVSS 7.1
Next.js: Server-side request forgery in applications using WebSocket upgrades
CVSS 8.6
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
FortiAuthenticator 8.0.0-8.0.2, 6.5.0-6.5.6, 6.6.0-6.6.8, 6.4.0-6.4.10 - Improper Access Control
CVSS 9.8
phpvms: /importer authorization bypass causing full database wipe
CVSS 9.4
Cisco Secure Firewall Management Center 6.4.0.13-6.4.0.18, 7.0.0 - RCE via Java Deserialization
CVSS 10.0
LiteLLM: SQL injection in Proxy API key verification
CVSS 9.8
xfrm: esp: avoid in-place decrypt on shared skb frags
CVSS 8.8
Palo Alto PAN-OS User-ID Authentication Portal - Unauthenticated Root RCE
CVSS 9.8
Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS
CVSS 8.9
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
ProjeQtor < 12.4.4 Unauthenticated SQL Injection via Login
CVSS 9.8
Zimbra Collaboration Suite 10.0.0-10.0.17 - Unauthenticated Local File Inclusion via RestFilter Servlet
CVSS 8.8
Oracle HTTP Server & WebLogic Proxy Plug-in 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 - Unauthenticated Access Control
CVSS 10.0
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
CVSS 8.8
FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5 - Path Traversal via '../filedir'
CVSS 9.8
xz <5.6.0 - Code Injection
CVSS 10.0
n8n <1.123.17, <2.5.2 - Command Injection
CVSS 9.9
CrushFTP - Authentication Bypass
CVSS 9.8
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8