Pari Malam
30 exploits
Active since Apr 2022
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
Chamilo unauthenticated command injection in PowerPoint upload
Chamilo unauthenticated command injection in PowerPoint upload
WSO2 Arbitrary File Upload to RCE
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
WSO2 Arbitrary File Upload to RCE
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
Openfire authentication bypass with RCE plugin
Openfire authentication bypass with RCE plugin
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L - OS Command Injection via nas_sharing.cgi System Parameter
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L - OS Command Injection via nas_sharing.cgi System Parameter
Jenkins cli Ampersand Replacement Arbitrary File Read
SPIP < 4.2.1 - Remote Code Execution via Form Value Deserialization
Apache Superset Signed Cookie Priv Esc
Jenkins cli Ampersand Replacement Arbitrary File Read
SPIP < 4.2.1 - Remote Code Execution via Form Value Deserialization
Apache Superset Signed Cookie Priv Esc
MStore API < 3.9.2 - Unauthenticated Authentication Bypass via Listing REST API
PaperCut MF and NG 8.0-20.1.7 - Unauthenticated Remote Code Execution via SetupCompleted
Apache OFBiz forgotPassword/ProgramExport RCE
Apache OFBiz forgotPassword/ProgramExport RCE
MStore API < 3.9.2 - Unauthenticated Authentication Bypass via Listing REST API
PaperCut MF and NG 8.0-20.1.7 - Unauthenticated Remote Code Execution via SetupCompleted
Juniper Networks Junos OS on EX Series <20.4R3-S9 - PHP External Variable Modification
CVSS 5.3