HORKimhab
260 exploits
Active since Oct 1988
Bitcoin Core 0.14-28.x - Auth Bypass
CVSS 7.5
Simple-File-List Plugin <4.2.2 - RCE
CVSS 9.8
WordPress File Manager Unauthenticated Remote Code Execution
CVSS 10.0
WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle()
CVSS 9.8
BerqWP < 2.2.42 - Unauthenticated Arbitrary File Upload via store_javascript_cache.php
CVSS 8.1
WavePlayer WP <3.8.0 - Unauthenticated RCE
CVSS 9.8
Custom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to Remote Code Execution
CVSS 7.3
Microsoft Defender Elevation of Privilege Vulnerability
CVSS 7.8
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CVSS 9.8
NGINX Open-Source ngx_http_v3_module vulnerability
CVSS 8.1
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
CVSS 9.8
Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
CVSS 9.8
Ubiquiti INC UniFi Connect Application < 3.4.20 - Improper Access Control
CVSS 10.0
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 10.0
Gitea Docker image trusts spoofable reverse-proxy headers by default
CVSS 9.8
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12
CVSS 9.8
KVM: x86: Fix shadow paging use-after-free due to unexpected role
CVSS 8.8
Langflow < 1.9.2 - Authenticated Insecure Direct Object Reference
CVSS 8.4
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
CVSS 9.8
LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVSS 8.8
rtmutex: Use waiter::task instead of current in remove_waiter()
CVSS 7.8
Tenda Firmware httpd - Hidden Backdoor Authentication
CVSS 9.8
WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
CVSS 7.8
KVM: x86: Fix shadow paging use-after-free due to unexpected role
CVSS 8.8
Gitea Composer package source links use insufficient permission checks
CVSS 8.2