Chocapikk
106 exploits
Active since Apr 2017
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
Sharepoint Dynamic Proxy Generator Unauth RCE
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
Atlassian Confluence Unauthenticated Remote Code Execution
Zimbra Collaboration <8.8.15-9.0.0-10.0.9-10.1.1 - Command Injection
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L - OS Command Injection via nas_sharing.cgi System Parameter
Geoserver unauthenticated Remote Code Execution
WordPress Backup Migration Plugin PHP Filter Chain RCE
Citrix NetScaler ADC/Gateway 12.1-55.300/13.0-92.19 Info Disclosure
Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) - Command Injection
Craft CMS Twig Template Injection RCE via FTP Templates Path
Adobe Commerce and Magento - XML External Entity Injection to Code Execution
PAN-OS >=10.1.0 <10.1.14 - Authenticated Privilege Escalation to Root via Management Interface
React Server Components <19.2.0 - RCE
VICIdial Authenticated Remote Code Execution
VICIdial Agent Interface - Authenticated Root Command Execution
TeamCity < 2023.11.4 - Authentication Bypass
PHP CGI Argument Injection Remote Code Execution
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) - Command Injection
Ivanti SAML - Server Side Request Forgery (SSRF)
NextGen Healthcare Mirth Connect <4.4.1 - RCE
LoadMaster 7.2.48.1-7.2.48.9 - Unauthenticated OS Command Injection
Telesquare TLR-2005KSH - Remote Command Execution
SPIP <4.3.2-4.1.18 - Command Injection