Exploit Intelligence Platform
64 exploits
Active since Mar 2022
FUXA < 1.2.8 - Unauthenticated Authentication Bypass and Remote Code Execution via Referer Header Spoofing
GitLab CE/EE <18.0.6-18.2.2 - Code Injection
Foundation Agents MetaGPT - Deserialization
Open WebUI - Authenticated Remote Code Execution via install_frontmatter_requirements Function
Open WebUI - Authenticated Remote Code Execution via load_tool_module_by_id Function
Langflow - Unauthenticated Remote Code Execution via eval_custom_component_code
Upsonic - Unauthenticated Remote Code Execution via Cloudpickle Deserialization in add_tool Endpoint
Apache Druid 0.17.0-35.x - Authentication Bypass via LDAP Anonymous Bind
OpenClaw <2026.2.14 - Path Traversal
MLflow - Unauthenticated Authentication Bypass via Default Credentials in basic_auth.ini
Centreon Open Tickets <25.10.3 - Path Traversal
hoppscotch < 2026.2.0 - Unauthenticated Infrastructure Configuration Overwrite via Onboarding Endpoint
Vikunja < 2.1.0 - Persistent Account Takeover via Password Reset Token Reuse
OpenStack Vitrage <12.0.1,13.0.0,14.0.0,15.0.0 - Code Injection
GNU inetutils <=2.7 - Privilege Escalation
Vim < 9.2.0073 - OS Command Injection via netrw Plugin SCP URL Handler
LibreNMS < 26.2.0 - SQL Injection via IPv6 Address Search in ajax_table.php
Apache Continuum - Command Injection
Kibana - Remote Code Execution via YAML Deserialization in AI Tools Amazon Bedrock Connector
ruby-saml <=1.12.2 and 1.13.0-1.16.0 - Unauthenticated SAML Signature Verification Bypass
Strapi 5.0.0-5.5.1 - Unauthenticated Private Field Exposure via Lookup Operator
Grafana Image Renderer 1.0.0-4.0.16 - Remote Code Execution via CSV Endpoint File Path Parameter
Mattermost <11.0.2, 10.12.1, 10.11.4, 10.5.12 - Auth Bypass
Hugging Face smolagents - Deserialization
Mattermost 9.11.0-9.11.7, 10.2.0-10.2.2, 10.3.0-10.3.2, 10.4.0-10.4.1 - SQL Injection via Boards Reordering