Mr-xn
25 exploits
Active since Mar 2021
Zabbix 5.4.0-5.4.7 - Unauthenticated Authentication Bypass via SAML Session Spoofing
1Panel < 2.0.6 - Remote Code Execution via Incomplete Certificate Verification
Geoserver unauthenticated Remote Code Execution
Spring Framework - Remote Code Execution via Data Binding
APISIX Admin API default access token RCE
Apache Airflow < 2.4.0 - Authenticated Remote Code Execution via Run ID Parameter
Adobe Commerce <2.4.3-p1, <2.3.7-p2 - RCE
Minio <RELEASE.2023-03-20T20-16-18Z - Info Disclosure
Apache OFBiz <18.12.14 - Path Traversal
Apache OFBiz <18.12.13 - Path Traversal
Oracle WebLogic Server 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Path Traversal via HTTP
Grafana Plugin Path Traversal
TP-LINK TL-WR840N(ES)_V6.20_180709 - Remote Code Execution via oal_wan6_setIpAddr Function
SolarView Compact Firmware <= 6.00 - Remote Command Execution via downloader.php
Splunk 9.0.0-9.0.9 - Path Traversal via /modules/messaging/ Endpoint
Microsoft Exchange ProxyLogon RCE
Tp-Link ER7206 Omada - Command Injection
snapd < 2.61.1 - Race Condition in must_mkdir_and_open_with_perms
1Panel < 2.0.6 - Remote Code Execution via Incomplete Certificate Verification
Unauthenticated SQL Injection in dotCMS Publish Audit API
1Panel < 2.0.6 - Remote Code Execution via Incomplete Certificate Verification
CVSS 8.1
Apache OFBiz forgotPassword/ProgramExport RCE
CVSS 9.8
Minio <RELEASE.2023-03-20T20-16-18Z - Auth Bypass
CVSS 8.8
GoAhead 4.0.0-4.1.3 and 5.x < 5.1.5 - Unrestricted File Upload via CGI Environment Variable Tunneling
CVSS 9.8
Apache OFBiz <18.12.13 - Path Traversal
CVSS 9.8