MrTiz

2 exploits Active since Feb 2020
CVE-2023-35671 NOMISEC MEDIUM WRITEUP
Google Android - Improper Privilege Management
In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
73 stars
CVSS 5.5
CVE-2020-0688 NOMISEC HIGH WORKING POC
Microsoft Exchange Server - Authentication Bypass
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
22 stars
CVSS 8.8