Beatriz Fresno Naumova
17 exploits
Active since Oct 2023
Madara WordPress <2.2.2 - Local File Inclusion
CVSS 9.8
Zhiyuan OA Web Application System - Unauthenticated Arbitrary File Upload and Remote Code Execution via wpsAssistServlet
Grafana < 10.4.18 - XSS
CVSS 7.6
Kubernetes ingress-nginx mirror annotations - Controller Code Execution
CVSS 8.8
Kubernetes ingress-nginx auth-tls-match-cn - Controller Code Execution
CVSS 8.8
Kubernetes ingress-nginx - Pod Network Remote Code Execution
CVSS 9.8
Windows 10 1507-22H2 and Windows 11 22H2 - Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
Windows 10 1507-22H2 and Windows 11 22H2 - Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
aiohttp - Directory Traversal
CVSS 5.9
Soosyze CMS 2.0 - Brute-Force Login via Unrestricted Authentication Attempts
CVSS 5.4
sourcefabric rpi-jukebox-rfid < 2.8.0 - Cross-Site Scripting via Custom Script Parameter
CVSS 3.5
sourcefabric rpi-jukebox-rfid < 2.8.0 - OS Command Injection via Playlist Parameter
CVSS 6.3
Lingdang CRM < 8.6.5.4 - SQL Injection via getvaluestring Parameter
CVSS 6.3
ingress-nginx < 1.11.5 and 1.12.0 - Remote Code Execution via auth-url Annotation Injection
CVSS 8.8
D-Link DIR-825 Firmware < 2.10 - Buffer Overflow via apply.cgi countdown_time Argument
CVSS 8.8
Redis 2.8.0-6.2.18 - Authenticated Remote Code Execution via HyperLogLog String Parsing
CVSS 7.0
Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
CVSS 7.8