Kairo-one

4 exploits Active since Aug 2019
CVE-2020-26217 NOMISEC HIGH WORKING POC
Xstream < 1.4.14 - OS Command Injection
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
2 stars
CVSS 8.0
CVE-2023-26469 NOMISEC CRITICAL WORKING POC
Jorani 1.0.0 - Path Traversal
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
CVSS 9.8
CVE-2020-14343 NOMISEC CRITICAL WORKING POC
Pyyaml < 5.4 - Improper Input Validation
A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.
CVSS 9.8
CVE-2015-9331 NOMISEC HIGH WORKING POC
Soflyy WP All Import < 3.2.4 - Security Feature Bypass
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
CVSS 7.5