CerberusMrXi
17 exploits
Active since Dec 2021
HTTP/2 - Denial of Service via Rapid Stream Reset
cPanel and WHM Authentication Bypass via Login Flow
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
React Server Components <19.2.0 - RCE
Apache HTTP Server < 2.4.52 - Buffer Overflow in mod_lua Multipart Parser
CVSS 9.8
Invision Community 4.7.20 - (calendar/view.php) SQL Injection
Fortinet FortiWeb unauthenticated RCE
CVSS 9.8
Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
CVSS 9.1
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
CVSS 5.0
SQL Injection in Nessus via Malicious Scan Result File Import
CVSS 3.3
MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys
CVSS 7.6
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
CVSS 5.9
Contest Gallery Plugin <28.1.4 - SQL Injection
CVSS 7.5
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
MCPJam inspector < 1.4.3 - Remote Code Execution via HTTP Request
CVSS 9.8
Webkul Krayin CRM 2.2.x - Authenticated RCE
CVSS 9.9