HORKimhab
260 exploits
Active since Oct 1988
FortiSandbox 4.4.0-4.4.8 - OS Command Injection
CVSS 9.8
FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5 - Path Traversal via '../filedir'
CVSS 9.8
Cisco NX-OS Software - Command Injection
CVSS 6.0
SmarterTools SmarterMail <9511 - Auth Bypass
CVSS 9.8
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
CVSS 6.5
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
CVSS 8.8
Litespeed Technologies cPanel Plugin < 2.4.8 - UNIX Symbolic Link (Symlink) Following
CVSS 8.5
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
CVSS 9.8
Palo Alto Networks Cloud Ngfw - Command Injection
CVSS 7.2
PeopleSoft Enterprise PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution via Updates Environment Management
CVSS 9.8
Heap Use-After-Free in the PKCS7_verify() Function
CVSS 8.8
Microsoft Windows 10 Version 1607 - Windows BitLocker Security Feature Bypass Vulnerability
CVSS 6.8
Langflow - Path Traversal Arbitrary File Write via upload_user_file
CVSS 8.8
Ivanti Sentry - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 10.0
Ivanti Sentry - Authentication Bypass Using an Alternate Path or Channel
CVSS 9.9
ServiceNow AI Platform - Unauthenticated Remote Code Execution in Sandbox
protobufjs-cli: Code injection in pbjs static output from crafted schema names
CVSS 8.7
protobufjs: Code generation gadget after prototype pollution
CVSS 8.1
protobufjs: Prototype injection in generated message constructors
CVSS 5.3
protobufjs: Process-wide denial of service through unsafe option paths
CVSS 7.5
protobufjs: Denial of service through unbounded protobuf recursion
CVSS 7.5
Veeam Backup And Replication < 12.3.2 - Deserialization of Untrusted Data
Fortinet FortiSandbox - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 9.8
protobufjs: Denial of service from crafted field names in generated code
CVSS 5.3
LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVSS 8.8