HORKimhab
260 exploits
Active since Oct 1988
ImageMagick <6.9.3-10 & <7.0.1-1 - RCE
CVSS 8.4
GutenKit < 2.1.0 - Unauthenticated Arbitrary File Upload via install-active-plugin Endpoint
CVSS 9.8
Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via copy_post_image()
CVSS 9.8
Advanced Custom Fields: Extended <0.9.1.1 - RCE
CVSS 9.8
CraftCMS - Remote Code Execution
CVSS 10.0
Rejected
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution via sneeit_articles_pagination_callback
CVSS 9.8
MetInfo CMS 7.9-8.1 - Unauthenticated PHP Code Injection
CVSS 9.8
goodoneuz/pay-uz <= 2.2.24 - Unauthenticated Remote Code Execution via Payment API Endpoint
CVSS 9.8
MaxSite CMS <109.1 - Code Injection
CVSS 7.3
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
ptrace: slightly saner 'get_dumpable()' logic
CVSS 7.1
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
CVSS 9.8
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
CVSS 9.8
NVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API
CVSS 9.8
Nacos < 1.4.1 - Authentication Bypass via User-Agent Spoofing
CVSS 8.6
Helm 4.0.0-4.1.3 Plugin Metadata - Arbitrary File Write
CVSS 8.6
Microsoft Windows HTTP.sys HTTP/2 - Denial of Service
CVSS 7.5
Zimbra Collaboration - Cross-Site Scripting (XSS)
CVSS 6.1
Zimbra Collaboration Suite 8.8.0-8.8.14 - Stored Cross-Site Scripting in Classic Web Client
CVSS 6.1
Citrix ShareFile Storage Zones Controller - Unauthenticated Remote Compromise
CVSS 9.8
Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
CVSS 9.1
Zimbra - Cross-Site Scripting via ICS Files
CVSS 5.4
ThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload
CVSS 5.3
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
CVSS 9.8