Aljosha Judmayer
39 exploits
Active since Aug 2017
KNX ETS 4.1.5 Build 3246 - Remote Code Execution via Crafted KNXnet/IP UDP Packet
CVSS 9.8
KNX ETS 4.1.5 Build 3246 - Remote Code Execution via Crafted KNXnet/IP UDP Packet
CVSS 9.8
LibreChat RAG API Authentication Bypass
CVSS 8.0
LibreChat 0.8.1-rc2 - Authenticated JWT Scope Expansion to RAG API
CVSS 6.3
Checkmk 2.4.0-2.4.0p21/2.3.0-2.3.0p42 - XSS
CVSS 5.4
Suprema BioStar 2 2.9.11.6 - Auth Bypass
CVSS 4.8
phpwhois < 4.2.2 - Remote Code Execution via Crafted Whois Record
CVSS 9.8
Smarty < 3.1.33 - Path Traversal via Trusted Resource Directory Bypass
CVSS 7.5
Teltonika RUT9XX <00.04.233 - Command Injection
CVSS 9.8
Teltonika RUT9XX Firmware < 00.05.01.1 - Reflected Cross-Site Scripting via hotspotlogin.cgi
CVSS 6.1
Teltonika RUT9XX <00.04.233 - Privilege Escalation
CVSS 6.8
Ping Identity Agentless Integration Kit <1.5 - XSS
CVSS 6.1
All in One SEO Pack < 3.2.7 - Stored Cross-Site Scripting via SEO Description Placeholder
CVSS 5.4
WordPress Broken Link Checker <1.11.8 - XSS
CVSS 6.1
EU Cookie Law < 3.0.6 - Authenticated Stored Cross-Site Scripting via Configuration Options
CVSS 4.8
Events Manager < 5.9.5 - Stored Cross-Site Scripting via Shortcode Map Style Attribute
CVSS 5.4
Easy FancyBox < 1.8.18 - Stored Cross-Site Scripting in Settings Menu
CVSS 4.8
Monsta FTP < 2.10.1 - Stored Cross-Site Scripting in Language Setting
CVSS 6.1
Monsta FTP < 2.10.1 - Server-Side Request Forgery via Web Fetch Functionality
CVSS 9.8
Monsta FTP < 2.10.1 - Arbitrary File Read and Write via Path Traversal
CVSS 9.8
CloudLinux CageFS <7.1.1-1 - Code Injection
CVSS 7.8
CloudLinux CageFS <7.0.8.2 - Info Disclosure
CVSS 4.4
Shibboleth oidc_op < 3.0.4 - Server-Side Request Forgery via request_uri Parameter
CVSS 8.2
vtiger CRM < 7.4.0 - Stored Cross-Site Scripting via Email Template Modules
CVSS 5.4
MOKOSmart MKGW1 BLE Gateway <1.1.1 - Privilege Escalation
CVSS 8.8