0xgh057r3c0n
29 exploits
Active since Mar 2025
vBulletin 5.0.0-5.7.5 and 6.0.0-6.0.3 - Unauthenticated API Controller Method Invocation
CrushFTP - Authentication Bypass
Rejected
5 stars
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
Simple User Registration < 6.3 - Unauthenticated Privilege Escalation via User Meta Manipulation
Opal Estate Pro - Property Management and Submission <=1.7.5 - Privilege Escalation
Advanced Custom Fields: Extended <0.9.1.1 - RCE
OpenCode <1.0.216 - Command Injection
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload via image_upload_handle Function
WordPress Pie Register <3.7.1.4 - Auth Bypass
1 stars
Fortinet FortiWeb - SQL Injection
IBM Langflow OSS 1.0.0-1.10.0 - Unauthenticated Remote Code Execution
CVSS 9.8
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
CVSS 9.8
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
CVSS 9.8
HarmonyOS - Denial of Service via IPC Module Deserialization
CVSS 6.2
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CVSS 9.8
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
CVSS 9.8
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
CVSS 9.8
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
CVSS 9.8
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
CVSS 9.8
Langflow validate exec_globals - Unauthenticated Root Code Execution
CVSS 9.8
Citrix NetScaler ADC/Gateway 12.1-12.1-55.328, 13.1-13.1-37.235, 13.1-13.1-58.32 - Out-of-bounds Read
CVSS 7.5
Citrix NetScaler ADC/Gateway 12.1-12.1-55.328, 13.1-13.1-37.235, 13.1-13.1-58.32 - Out-of-bounds Read
CVSS 7.5
SureTriggers - All-in-One Automation Platform < 1.0.78 - Authentication Bypass
CVSS 8.1
Rejected