Andrej Šimko
26 exploits
Active since Jan 2021
Tufin SecureChange <R19.3 HF3 & R20-1 HF1 - Stored XSS
CVSS 6.1
Tufin SecureChange <R19.3 HF3 & R20-1 HF1 - Stored XSS
CVSS 4.8
Tufin SecureTrack < R20-2 GA - Stored/XSS
CVSS 5.9
Tufin SecureTrack < R20-2 GA - Stored/XSS
CVSS 5.9
Tufin SecureTrack < R20-2 GA - Stored/XSS
CVSS 5.9
OpenIAM 4.1.0-4.2.0.2 - Stored Cross-Site Scripting in Add New User Feature
CVSS 6.1
OpenIAM 4.1.0-4.2.0.2 - Path Traversal in Batch Task
CVSS 5.3
OpenIAM 4.1.0-4.2.0.2 - Remote Code Execution via Groovy Script
CVSS 9.8
OpenIAM <4.2.0.3 - Privilege Escalation
CVSS 9.8
OpenIAM <4.2.0.3 - Privilege Escalation
CVSS 8.1
Tufin SecureTrack < R20-2 - Cross-Site Request Forgery
CVSS 8.8
Tufin SecureTrack - Info Disclosure
CVSS 4.3
Tufin SecureChange <R20-2 GA - IDOR
CVSS 5.7
SmartStream Transaction Lifecycle Management Reconciliation Premium < 3.1.0 - Cross-Site Scripting
CVSS 5.4
Trace Financial CRESTBridge <6.3.0.02 - XSS
CVSS 5.4
Trace Financial CRESTBridge <6.3.0.02 - SQL Injection
CVSS 8.8
Trace Financial Crest Bridge <6.3.0.02 - XSS
CVSS 5.4
Trace Financial CRESTBridge <6.3.0.02 - SQL Injection
CVSS 8.8
Annex Cloud Loyalty Experience Platform < 2021.1.0.1 - Authenticated Insecure Direct Object Reference
CVSS 4.3
Annex Cloud Loyalty Experience Platform <2021.1.0.1 - Privilege Escalation
CVSS 8.8
Annexcloud Loyalty Experience Platform < 2021.1.0.1 - Incorrect Permission Assignment
CVSS 4.3
LabCup <v2_next_18022 - Privilege Escalation
CVSS 3.1
Tricentis qTest < 10.4 - Authenticated Stored Cross-Site Scripting
CVSS 5.4
Bolt < 5.7 - Denial of Service via Foldername Parameter
CVSS 9.1
Backdrop CMS < 1.22.0 - Username Enumeration via Password Reset Request
CVSS 5.3