Hex0rc1st
21 exploits
Active since Feb 2026
PostgreSQL <18.2, 17.8, 16.12, 15.16, 14.21 - RCE
Microsoft Windows 11 Version 24H2 - Windows Kernel Elevation of Privilege Vulnerability
Microsoft Windows 10 Version 1607 - Windows Storage Spaces Controller Elevation of Privilege Vulnerability
Microsoft Windows 11 Version 24H2 - Windows Kernel Elevation of Privilege Vulnerability
Apache ActiveMQ Broker < 5.19.6 and 6.0.0 to before 6.2.5 - Remote Code Execution
Palo Alto PAN-OS User-ID Authentication Portal - Unauthenticated Root RCE
Google Android <16-qpr2 - Auth Bypass
cPanel and WHM Authentication Bypass via Login Flow
GitHub Enterprise Server RCE via Git Push Option Injection
Fortinet FortiClientEMS 7.4.5-7.4.6 - Command Injection
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
Windows Snipping Tool Spoofing Vulnerability
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Vim modeline bypass via various options affects Vim < 9.2.0276
Google Chrome < 146.0.7680.178 - Use-After-Free in Dawn
Windows File Server - Privilege Escalation
Google Chrome < 146.0.7680.75 - Out-of-bounds Write in Skia via Crafted HTML Page
Vim < 9.2.0272 - Remote Code Execution via %{expr} Injection in Tabpanel