AkkuS
99 exploits
Active since Nov 2018
AROX School-ERP Pro - Unauthenticated Remote Code Execution via import_stud.php and upload_fille.php
CVSS 9.8
Rejected
Servisnet Tessa 0.0.2 - Info Disclosure
CVSS 7.5
Servisnet Tessa 0.0.2 - Unauthenticated Authorization Bypass via User Data Endpoint
CVSS 9.8
Servisnet Tessa 0.0.2 - Unauthenticated User Addition via Authorization Header Manipulation
CVSS 9.8
Liferay Portal CE 7.1.2 GA3 - Command Injection
CVSS 7.2
Ericsson Network Location <2021-07-31 - Command Injection
CVSS 8.8
Zoho ManageEngine Apps Mgr <15 - SQL Injection
CVSS 9.8
ManageEngine OpManager < 12.4.034 - Unauthenticated Remote Command Execution via Default Credential Bypass
CVSS 9.8
ManageEngine Applications Manager 12.0-13.9 - SQL Injection via NewThresholdConfiguration.jsp resourceid Parameter
CVSS 8.8
ManageEngine Applications Manager < 14.2 - SQL Injection via NewThresholdConfiguration.jsp resourceid Parameter
CVSS 8.8
NewsBee CMS 1.4 - 'home-text-edit.php' SQL Injection
Webmin <= 1.962 - Authenticated Remote Command Execution via Package Updates Module
CVSS 8.8
Usermin 1.750 - Remote Command Execution (Metasploit)
TerraMaster Operating System <= 4.2.06 - Unauthenticated Remote Code Execution via Event Parameter in makecvs.php
CVSS 9.8
Jenkins 2.150.2 - Remote Command Execution (Metasploit)
Webmin < 1.910 - Authenticated Remote Command Execution via Package Updates Module
CVSS 8.8
BT CTROMS Terminal OS Port Portal CT-464 - Info Disclosure
CVSS 8.1
Webmin <= 1.920 - OS Command Injection via password_change.cgi Old Parameter
CVSS 9.8
OpenKM 6.3.2-6.3.7 - Unauthenticated Remote Code Execution via JSP File Upload
CVSS 7.2
Sahi Pro 8.0.0 - Unauthenticated Remote Code Execution via Player_setScriptFile
CVSS 9.8
QNAP TS-431 QTS < 4.2.2 - Remote Command Execution (Metasploit)
Webmin 1.900 - Remote Code Execution via Upload and Download Privilege Abuse
CVSS 7.8
Allied Telesis 8100L/8 Firmware - Stored Cross-Site Scripting via IPv4 Interface Editor
CVSS 6.1