AikidoSec
18 exploits
Active since Jan 2015
Django 4.2-4.2.27 5.2-5.2.10 6.0-6.0.1 - SQL Injection via RasterField Band Index Parameter
Sequelize <2.0.0-rc7 - SQL Injection
6 stars
node-df 0.1.4 - Remote Code Execution via Unsanitized Input
ssh2 < 1.4.0 - OS Command Injection
fast-http - Path Traversal via fs.readFile in index.js
@firebase/util <0.3.4 - Code Injection
dot-prop <4.2.1, <5.1.1 - Prototype Pollution
FUXA <= 1.1.12 - SQL Injection via /api/signin
libuv 1.24.0-1.47.0 - Server-Side Request Forgery via Hostname Truncation
st module for Node.js < 0.2.5 - Path Traversal via Encoded Dot-Dot Sequences
mongoosejs/mongoose < 6.13.5 and >=8.0.0-rc0 <8.8.3 - Search Injection via $where in Match
Node.js 18.0-18.20.6 - Path Traversal in Windows Drive Name Handling
parse-git-config 3.0.0 - Exposure of Sensitive Information via expandKeys Function
canvg 4.0.2 - Remote Code Execution via StyleElement Constructor
axios < 1.8.2 - Server-Side Request Forgery via Absolute URL Handling
crud-query-parser < 0.1.0 - SQL Injection via TypeORM Order/Sort Parameter
6 stars
Kubio AI Page Builder <2.5.1 - Local File Inclusion
axios 1.3.2-1.7.3 - Server-Side Request Forgery via Path Relative URL Processing