Acczdy
9 exploits
Active since Feb 2022
APISIX Admin API default access token RCE
AstrBot 3.4.4-3.5.12 - Path Traversal and Information Disclosure via Dashboard Feature
CVSS 7.5
MCP Inspector < 0.14.1 - Unauthenticated Remote Code Execution via Stdio Command Injection
Openfire authentication bypass with RCE plugin
CVSS 8.6
AutoGPT < 0.4.0 - Server-Side Template Injection via AgentOutputBlock Format String
CVSS 8.8
Cockpit < 2.4.1 - Unrestricted Upload of File with Dangerous Type
CVSS 8.8
chancms < 3.1.3 - Deserialization via getArticle Function
CVSS 6.3
Gogs < 0.13.4 - Remote Code Execution via .git Directory File Update
CVSS 9.8
CraftCMS - Remote Code Execution
CVSS 10.0