Milad karimi
37 exploits
Active since Apr 2022
ProtonVPN v4.4.1 - Unquoted Service Path
WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
CVSS 9.8
WordPress Theme Travelscape 1.0.3 Arbitrary File Upload
CVSS 9.8
WordPress Background Image Cropper 1.2 Remote Code Execution
CVSS 9.8
WP Travel Kit Travelscape - WordPress Seotheme Remote Code Execution Unauthenticated
CVSS 9.8
WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated
CVSS 7.5
WordPress International Sms Contact Form 7 Integration 1.2 XSS
CVSS 6.1
WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php
CVSS 6.1
WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php
CVSS 6.1
Drupal avatar_uploader 7.x-1.0-beta8 Reflected XSS
CVSS 6.1
AnyDesk 7.0.15,9.0.1 - Code Injection
ESET Endpoint Antivirus < 8.1.2062.0 - Local Privilege Escalation via File Deletion
CVSS 7.8
ESET Endpoint Antivirus < 8.1.2062.0 - Local Privilege Escalation via File Deletion
CVSS 7.8
Outline 1.6.0 - Privilege Escalation
CVSS 7.8
Pinger 1.0 - Remote Code Execution via Ping and Socket Parameter Injection
CVSS 9.8
WPForms < 1.7.8 - Stored Cross-Site Scripting via Slider Import Search Feature
CVSS 6.1
Oracle VM VirtualBox < 7.0.16 - Privilege Escalation via Core Component
CVSS 7.8
SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
Oracle Database 12c Release 1 - Unquoted Service Path
Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquoted Service Path
Windows Kernel - Privilege Escalation
CVSS 7.8
Windows Common Log File System Driver - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
Windows Ancillary Function Driver - Privilege Escalation
CVSS 7.8
Windows 10 1507 < 10.0.10240.19926 and 1607 < 10.0.14393.5921 - Use-After-Free in Win32k
CVSS 7.8
VMware Workstation 15 Pro - Denial of Service