Chocapikk
111 exploits
Active since Apr 2017
KramerAV VIAWare - Privilege Escalation
Windmill < 1.603.3 - Unauthenticated Path Traversal via Get Log File Endpoint
NextGen Healthcare Mirth Connect <4.4.1 - RCE
SPIP Saisies 5.4.0-5.11.0 - Remote Code Execution
Sudo <1.9.17p1 - Privilege Escalation
SPIP <4.3.2-4.1.18 - Command Injection
Mocodo Online < 4.2.6 - Remote Code Execution via SQL Case Input Field
magnusbilling 6.0.0-7.2.9 - Unauthenticated OS Command Injection
F5 BIG-IP iControl RCE via REST Authentication Bypass
WSO2 Arbitrary File Upload to RCE
FreeSWITCH <1.10.1 - Info Disclosure
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
CVSS 10.0
diskoverdata diskover-community <=2.3.5 - CSRF
CVSS 8.8
Geoserver unauthenticated Remote Code Execution
CVSS 9.8
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
CVSS 10.0
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVSS 9.8
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
CVSS 10.0
v2board / Xboard Authentication Token Exposure via loginWithMailLink
CVSS 9.1
NextGen Healthcare Mirth Connect <4.4.1 - RCE
CVSS 9.8
NextGen Healthcare Mirth Connect <4.4.1 - RCE
CVSS 9.8
FreeSWITCH <1.10.1 - Info Disclosure
CVSS 9.8
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
CVSS 10.0
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
CVSS 10.0
PAN-OS >=10.1.0 <10.1.14 - Authenticated Privilege Escalation to Root via Management Interface
CVSS 7.2
Adobe Commerce and Magento - XML External Entity Injection to Code Execution
CVSS 9.8