Chocapikk
106 exploits
Active since Apr 2017
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
MajorDoMo < 2023-11-15 - Remote Code Execution via thumb.php Shell Metacharacters
SPIP porte_plume - Unauthenticated PHP Code Execution
Widget Options WordPress Plugin <= 4.0.7 - Authenticated Remote Code Execution
Ivanti Connect Secure Unauthenticated Remote Code Execution
Moodle 4.1.0-4.1.2 - Unauthenticated Arbitrary Folder Creation via TinyMCE Loader
Apache OFBiz XML-RPC Java Deserialization
CraftCMS - Remote Code Execution
CVE-2024-20767 - Adobe Coldfusion Arbitrary File Read
WordPress Royal Elementor Addons RCE
Atlassian Confluence SSTI Injection
Webmin <= 1.920 - OS Command Injection via password_change.cgi Old Parameter
Hash Form - Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload via file_upload_action Function
RustFS <1.0.0-alpha.78 - Auth Bypass
Citrix NetScaler ADC/Gateway 12.1-12.1-55.328, 13.1-13.1-37.235, 13.1-13.1-58.32 - Out-of-bounds Read
Vinchin Backup & Recovery <7.2 - Authenticated RCE
Minio <RELEASE.2023-03-20T20-16-18Z - Info Disclosure
PHPUnit < 4.8.28 and 5.x < 5.6.3 - Remote Code Execution via HTTP POST Data
Wireless IP Camera (P2P) Firmware - Unauthenticated Credential Exposure via Empty Login Parameters
SPIP < 4.2.1 - Remote Code Execution via Form Value Deserialization
Fortinet Fortiproxy < 7.0.7 - Authentication Bypass
ZITADEL < 4.7.1 - Unauthenticated Server-Side Request Forgery via x-zitadel-forward-host Header
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
Citrix NetScaler ADC and Gateway - Unauthenticated Remote Code Execution
Monsta FTP < 2.11 - Unauthenticated Arbitrary File Upload