Al1ex
43 exploits
Active since Mar 2017
FasterXML Jackson-Databind <2.9.10.4 - Code Injection
XStream < 1.4.14 - Remote Code Execution via Blocklist Bypass
klog_server < 2.4.1 - Authenticated OS Command Injection via async.php Source Parameter
Oracle WebLogic wls-wsat Component Deserialization RCE
jackson-databind < 2.6.7.3, 2.9.0-2.9.3 - Unauthenticated Remote Code Execution via Malicious JSON Input
Linksys RE6500 Firmware < 1.0.012.001 - Unauthenticated Remote Code Execution via goform/setSysAdm
Wing FTP Server <6.2.3 - Privilege Escalation
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via org.jsecurity.realm.jndi.JndiRealmFactory
XStream <1.4.15 - File Deletion
jackson-databind 2.0.0-2.9.10.5 - Deserialization of Untrusted Data via JndiConfiguration
FasterXML jackson-databind <2.9.9 - Code Injection
Apache Log4j <= 1.2.17 - Deserialization of Untrusted Data via SocketServer
GitLab 11.9.0-13.8.7 - Unauthenticated Remote Code Execution via ExifTool Image Parsing
CVSS 10.0
Wing FTP Server < 6.2.5 - Session Cookie Exposure via Insecure Directory Permissions
CVSS 7.8
F5 iControl REST Unauthenticated SSRF Token Generation RCE
CVSS 9.8
XStream <1.4.15 - Server-Side Request Forgery via XML Unmarshalling
CVSS 6.3
Apache JMeter 2.x-3.x - Unauthenticated Remote Code Execution via Unsecured RMI Connection
CVSS 9.8
F5 iControl REST Unauthenticated SSRF Token Generation RCE
CVSS 9.8