Kirill

2 exploits Active since Feb 2022
CVE-2022-25297 WRITEUP HIGH WRITEUP
drogonframework/drogon <1.7.5 - Path Traversal
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.
CVSS 7.5
CVE-2025-29072 WRITEUP HIGH WRITEUP
Nethermind Juno < 0.12.5 - Integer Overflow
An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-lang-starknet-classes" library could allow remote attackers to trigger an infinite loop (and high CPU usage) by submitting a malicious Declare v2/v3 transaction. This results in a denial-of-service condition for affected Starknet full-node implementations.
CVSS 7.5