Al1ex
43 exploits
Active since Mar 2017
FasterXML Jackson-Databind <2.9.10.4 - Code Injection
Xstream < 1.4.14 - OS Command Injection
Klogserver Klog Server < 2.4.1 - OS Command Injection
Oracle WebLogic wls-wsat Component Deserialization RCE
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
Linksys Re6500 Firmware < 1.0.012.001 - OS Command Injection
Wing FTP Server <6.2.3 - Privilege Escalation
Fasterxml Jackson-databind < 2.9.10.5 - Insecure Deserialization
XStream <1.4.15 - File Deletion
Fasterxml Jackson-databind < 2.6.7.5 - Insecure Deserialization
FasterXML jackson-databind <2.9.9 - Code Injection
Apache Log4j < 1.2.17 - Insecure Deserialization
Gitlab < 13.8.8 - Code Injection
CVSS 10.0
Wftpserver Wing FTP Server < 6.2.5 - Incorrect Permission Assignment
CVSS 7.8
F5 iControl REST Unauthenticated SSRF Token Generation RCE
CVSS 9.8
XStream <1.4.15 - SSRF
CVSS 6.3
Apache Jmeter < 4.0 - Cleartext Transmission
CVSS 9.8
F5 iControl REST Unauthenticated SSRF Token Generation RCE
CVSS 9.8