HermesNA-1
200 exploits
Active since Jun 2026
Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure
Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()`
Coolify: Cross-team application domain enumeration via domains_by_server endpoint
Coolify: Authenticated RCE via command injection in CA certificate management feature
Session fixation in KTM System e-BOK
1 stars
Cross-Site Request Forgery (CSRF) in KTM System e-BOK
1 stars
Weak Password Requirements in KTM System e-BOK
1 stars
Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK
1 stars
Over-inclusive team membership expansion in GitHub App authentication provider for Rancher
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge bytes
UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated
UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check
SAML Authentication Replay in Rancher
Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
1 stars
Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler
1 stars
Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook
1 stars
Samverschueren Decode-uri-component < 0.5.0 - Uncontrolled Resource Consumption
1 stars
Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
Rejected
1 stars
Siemens Mendix Studio Pro 10.11 - Improper Control of Generation of Code ('Code Injection')
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
ColdFusion | Improper Input Validation (CWE-20)
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service