0xBlackash
114 exploits
Active since Apr 2014
n8n <1.123.17, <2.5.2 - Command Injection
CVSS 9.9
CrushFTP - Authentication Bypass
CVSS 9.8
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8
Openeclass < 4.1 - Unrestricted File Upload
CVSS 7.2
FortiSandbox 4.4.0-4.4.8 - OS Command Injection
CVSS 9.8
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
CVSS 9.1
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVSS 4.8
nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
CVSS 9.8
Zammad AI Agent - Server-Side Template Injection
CVSS 7.2
Exposed Dangerous Method or Function in GitLab
CVSS 8.5
Erlang OTP Pre-Auth RCE Scanner and Exploit
CVSS 10.0
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
CVSS 8.8
EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
CVSS 9.8
Twonky Server Log Leak Authentication Bypass
CVSS 9.8
OpenCode <1.0.216 - Command Injection
CVSS 8.8
UniFi Network Application 9.0.118-10.1.89, 10.2.97 - Path Traversal
CVSS 10.0
Fortinet FortiClientEMS 7.4.5-7.4.6 - Command Injection
CVSS 9.8
Langflow - Path Traversal Arbitrary File Write via upload_user_file
CVSS 8.8
Langflow validate exec_globals - Unauthenticated Root Code Execution
CVSS 9.8
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
CVSS 9.9
RCE on Grafana via sqlExpressions
CVSS 9.1
Insufficient input validation leading to memory overread
CVSS 9.8
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
CVSS 7.5
Spring Framework - Remote Code Execution via Data Binding
CVSS 9.8