HORKimhab
260 exploits
Active since Oct 1988
exiftool <=13.49 - Command Injection
N-able N-central - Incomplete Patch Leads to Administrative Account Takeover
CVSS 8.1
Hancom AnySign4PC - Path Traversal and Arbitrary File Deletion via getPFXFolderList Parameter
CVSS 7.5
JIT miscompilation in the JavaScript Engine: JIT component
CVSS 4.3
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
CVSS 10.0
OpenHands is Vulnerable to Command Injection through its Git Diff Handler
CVSS 7.6
net/sched: act_api: use RCU with deferred freeing for action lifecycle
CVSS 7.8
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
CVSS 9.8
n8n <2.10.1/2.9.3/1.123.22 - Command Injection
CVSS 9.9
Wavlink WL-NU516U1 nas.cgi ftext stack-based overflow
CVSS 8.8
Microsoft Bing Images Remote Code Execution Vulnerability
CVSS 9.8
Remote Code Execution in fastjson 1.2.68–1.2.83
CVSS 9.0
Microsoft Windows 10 Version 1607 - Active Directory Certificate Services Elevation of Privilege Vulnerability
CVSS 8.8
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
xfs: resample the data fork mapping after cycling ILOCK
CVSS 7.8
Microsoft SharePoint Remote Code Execution Vulnerability
CVSS 9.8
Sandbox Escape in ServiceNow AI Platform
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
CVSS 9.8
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php
CVSS 9.8
Realtek SD Card Reader <10.0.26100.21374 - DoS
CVSS 6.5
Realtek RtsPer < 10.0.22000.21355 and RtsUer < 10.0.22000.31274 - Kernel Address Leak via Driver Logs
CVSS 5.5
Sonicwall SMA1000 - Improper Control of Generation of Code ('Code Injection')
CVSS 7.2
Sonicwall SMA1000 - Server-Side Request Forgery (SSRF)
CVSS 10.0
SunOS - Privilege Escalation via Writable utmp File