Pooya Parsa
7 exploits
Active since Dec 2022
srvx is vulnerable to middleware bypass via absolute URI in request line
CVSS 4.8
h3 Event Stream Fields - Server-Sent Events Injection
CVSS 7.5
nuxt/framework - Reflected Cross-Site Scripting
CVSS 6.1
nuxt/framework - DOM-based Cross-Site Scripting
CVSS 6.1
unjs/ipx <1.3.2, 2.0.0-2.1.0, 3.0.0-3.1.0 - Path Traversal via Path Prefix Bypass
CVSS 9.8
nanotar <= 0.2.0 - Path Traversal and Arbitrary File Write via Crafted Tar Archive
CVSS 9.8
h3 < 1.15.5 - HTTP Request Smuggling via Transfer-Encoding Header Case Mismatch
CVSS 8.9