Michal Čihař
74 exploits
Active since Oct 2012
Weblate < 5.16.1 - Unauthorized Addon Information Exposure via REST API
CVSS 4.3
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
CVSS 5.0
Weblate: Arbitrary File Read via Symlink
CVSS 7.7
Weblate: SSRF via Project-Level Machinery Configuration
CVSS 5.0
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
CVSS 5.0
Weblate: Improper access control for pending tasks in API
CVSS 3.1
Weblate < 5.16.1 - Unauthorized Addon Information Exposure via REST API
CVSS 4.3
Weblate <5.16.0 - Command Injection
CVSS 6.6
phpMyAdmin <4.0.5 - CSRF
phpMyAdmin <4.0.10.13, <4.4.15.3, <4.5.4 - Info Disclosure
CVSS 5.3
Weblate < 4.11 - Stored Cross-Site Scripting via User Name and Language Fields
CVSS 5.4
Weblate 4.14-5.6.1 - Path Traversal via Project Backup Restore
CVSS 4.4
Weblate < 5.12 - Excessive Authentication Attempts via Second Factor Endpoint
CVSS 4.9
Weblate < 5.12 - Unauthorized Exposure of User IP Address in Audit Log Notifications
CVSS 5.3
Weblate < 5.13.1 - Insufficient Session Expiration during Second Factor Verification
CVSS 6.5
Weblate < 5.13.3 - Open Redirect via Redir Parameter
CVSS 6.1
Weblate < 5.13.3 - Open Redirect via Redir Parameter
CVSS 6.1
Weblate < 5.15 - Incorrect User Management via Invitation Acceptance
CVSS 9.8
Weblate < 5.15.1 - Path Traversal via Git Configuration Overwrite
CVSS 9.1
Weblate < 5.15.2 - Unauthenticated Screenshot Access via Direct HTTP Request
CVSS 7.5
wlc < 1.17.0 - Improper Certificate Validation
CVSS 2.5
wlc < 1.17.0 - Exposure of Sensitive Information via Unscoped API Key
CVSS 5.3
wlc < 1.17.2 - Path Traversal via Multi-Translation Download
CVSS 8.0
phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - RCE
CVSS 9.8