Milad Karimi (Ex3ptionaL)
27 exploits
Active since Apr 2022
Google Chrome <136.0.7103.113 - Info Disclosure
WordPress Theme Travelscape 1.0.3 Arbitrary File Upload
CVSS 9.8
WordPress Background Image Cropper 1.2 Remote Code Execution
CVSS 9.8
WP Travel Kit Travelscape - WordPress Seotheme Remote Code Execution Unauthenticated
CVSS 9.8
WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated
CVSS 7.5
AVAST Antivirus 25.11 - Unquoted Service Path
AnyDesk 7.0.15,9.0.1 - Code Injection
ESET Endpoint Antivirus < 8.1.2062.0 - Local Privilege Escalation via File Deletion
CVSS 7.8
ESET Endpoint Antivirus < 8.1.2062.0 - Local Privilege Escalation via File Deletion
CVSS 7.8
Outline 1.6.0 - Privilege Escalation
CVSS 7.8
SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
Windows 10 1507 < 10.0.10240.19926 and 1607 < 10.0.14393.5921 - Use-After-Free in Win32k
CVSS 7.8
Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquoted Service Path
Windows Kernel - Privilege Escalation
CVSS 7.8
Windows Common Log File System Driver - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
Windows Ancillary Function Driver - Privilege Escalation
CVSS 7.8
Windows Hyper-V NT Kernel Integration VSP - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
Oracle Database 12c Release 1 - Unquoted Service Path
WordPress < 6.2 - Unauthenticated Directory Traversal via wp_lang Parameter
CVSS 5.4
Membership For WooCommerce <2.1.7 - Unauthenticated RCE
CVSS 9.8
Tatsu Wordpress Plugin RCE
CVSS 8.1
WordPress LiteSpeed Cache - Unauthenticated Privilege Escalation to Admin
CVSS 9.8
Drupal 10.3.0-10.3.5 - Full Path Disclosure via Missing hash_salt File
CVSS 5.3
WonderCMS Remote Code Execution
CVSS 6.1
Fortinet FortiWeb - SQL Injection
CVSS 9.8