Al1ex
43 exploits
Active since Mar 2017
GitLab 11.9.0-13.8.7 - Unauthenticated Remote Code Execution via ExifTool Image Parsing
F5 iControl REST Unauthenticated SSRF Token Generation RCE
Dirty Pipe Local Privilege Escalation via CVE-2022-0847
Oracle JD Edwards Enterpriseone Tools - Insecure Deserialization
MariaDB <10.2.37, 10.3.28, 10.4.18, 10.5.9 - RCE
jackson-databind 2.9.0-2.9.10.7 - Deserialization of Untrusted Data via JNDIConnectionPool
F5 BIG-IP iControl RCE via REST Authentication Bypass
Oracle WebLogic Server <14.1.1.0.0 - RCE
Apache Struts 2 Forced Multi OGNL Evaluation
Netapp Cloud Backup < 21.1.2 - Insecure Deserialization
VMware vRealize Operations Manager < 8.4 - Server-Side Request Forgery via API
Linux BPF Sign Extension Local Privilege Escalation
VoIPmonitor < 24.61 - Unauthenticated Remote Code Execution via SPOOLDIR Injection
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data via JNDIConnectionSource
Internet Information Services 6.0 - Remote Code Execution via WebDAV PROPFIND Request
BIG-IP 11.6.1-11.6.5.1 - Remote Code Execution via TMUI Undisclosed Pages
Oracle WebLogic Server 10.3.6.0, 12.1.3.0, 12.2.1.0-12.2.1.2 - Unauthenticated OS Command Injection via HTTP
Apache Struts 2.0.0-2.5.20 - Remote Code Execution via Forced Double OGNL Evaluation
SaltStack Salt < 2019.2.4 - Authenticated Path Traversal via ClearFuncs Methods
Oracle Access Manager unauthenticated Remote Code Execution
klog_server 2.4.1 - OS Command Injection via User Parameter
FasterXML jackson-databind <2.9.10.4 - Code Injection
Apache Kylin <4.0.0 - Info Disclosure
jackson-databind 2.0.0-2.9.9 - Unauthenticated Arbitrary File Read via JDOM Polymorphic Typing
SEOWON INTECH SLC-130,SLR-120S - RCE