James Horseman
18 exploits
Active since May 2022
F5 BIG-IP iControl RCE via REST Authentication Bypass
VMware Aria Operations for Logs - RCE
Palo Alto Networks Expedition 1.2.0-1.2.95 - Authenticated OS Command Injection
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
FortiSIEM 6.7.0-6.7.10, 7.0.0-7.0.4, 7.1.0-7.1.8, 7.3.0-7.3.4, 7.4.0 - OS Command Injection via TCP Requests
Enhancesoft osTicket 1.17.0-1.17.6 and 1.18.0-1.18.2 - Unauthenticated Arbitrary File Read via Ticket PDF Export
N-able N-Central Authentication Bypass and XXE Scanner
N-central <2025.4 - Info Disclosure
2 stars
VMware vRealize Log Insight 3.0-4.8 - Unauthenticated Exposure of Sensitive Session Information
CVSS 5.3
VMware vRealize Log Insight 3.0-4.8 - Unauthenticated Path Traversal and Remote Code Execution
CVSS 9.8
VMware vRealize Log Insight 3.0-4.8 - Unauthenticated Remote Code Execution via Broken Access Control
CVSS 9.8
Fortra GoAnywhere MFT Unauthenticated Remote Code Execution
CVSS 9.8
Fortinet Forticlient Endpoint Management Server - SQL Injection
CVSS 9.8
Ivanti Endpoint Manager < 2022 - Privilege Escalation or Remote Code Execution
CVSS 9.8
Ivanti EPM RecordGoodApp SQLi RCE
CVSS 8.8
F5 BIG-IP iControl RCE via REST Authentication Bypass
CVSS 9.8
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
CVSS 9.8
Lexmark <2023-02-19 - Info Disclosure
CVSS 8.1