4rdr
7 exploits
Active since May 2024
bazarr < 1.4.3 - Unauthenticated Path Traversal via /api/swaggerui/static
CVSS 8.2
OrangeHRM 3.3.3 - SQL Injection via sortOrder Parameter
CVSS 8.1
Hyland Alfresco Platform 23.2.1-r96 - XSS
CVSS 6.1
AbanteCart 1.4.2 - Unauthenticated SQL Injection via tmpl_id Parameter
CVSS 9.8
NodeBB v4.3.0 - Unauthenticated SQL Injection via Search-Categories API Endpoint
CVSS 8.6
diskover-web v2.3.0 Community Edition - Stored Cross-Site Scripting in Administrative Settings Interface
CVSS 5.6
OPNsense <25.1.8 - Command Injection
CVSS 9.1