Exploit Intelligence Platform
64 exploits
Active since Mar 2022
ChromaDB >=1.0.0 - Unauthenticated Remote Code Execution via Malicious Model Repository
6 stars
VMware Fusion >=2025H2 <2026H1 - Privilege Escalation via SETUID Binary TOCTOU Race Condition
GitLab CE/EE <14.6.5-14.8.2 - Info Disclosure
cPanel and WHM Authentication Bypass via Login Flow
OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
OpenSSH < 10.3 - Always-Incorrect Control Flow Implementation in Authorized Keys Principals Handling
Pi-hole Web <6.0 savesettings.php - Command Injection
Windows Kernel - Privilege Escalation
Red Hat Enterprise Linux 10 - Improper Access Control via systemd-machined RegisterMachine D-Bus Method
WeKnora <0.2.12 - RCE via SQL Injection
OpenClaw <2026.2.2 - Command Injection
Apache Airflow Providers Snowflake <6.4.0 - Special Element Injection
Foundation Agents MetaGPT - Code Injection
Apache Zeppelin 0.8.2-0.11.0 - Remote Code Execution via Configuration Override
Exim < 4.96.2 - Unauthenticated Remote Code Execution via SMTP Service
Apache DolphinScheduler <3.2.2 - RCE
Apache Kafka 2.3.0-3.9.0 - Authenticated Remote Code Execution via SASL JAAS LDAP Deserialization
Apache HugeGraph < 1.7.0 - Remote Code Execution via Hessian Deserialization
Mattermost 9.11.0-9.11.7, 10.2.0-10.2.2, 10.3.0-10.3.2, 10.4.0-10.4.1 - SQL Injection via Boards Reordering
Apache Continuum - Command Injection
Hugging Face smolagents - Deserialization
Dataease <= 2.10.12 - Remote Code Execution via Impala JDBC Connection String JNDI Injection
Apache OFBiz < 24.09.02 - Unauthenticated Remote Code Execution via Scrum Plugin
Mattermost <11.0.2, 10.12.1, 10.11.4, 10.5.12 - Auth Bypass
Apache NiFi <2.6.0 - Deserialization