R3DXPLOIT(JIMMY)

2 exploits Active since Mar 2018
CVE-2018-8021 NOMISEC CRITICAL WORKING POC
Apache Superset < 0.23 - Remote Code Execution via Pickle Deserialization
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.
106 stars
CVSS 9.8
CVE-2018-7600 VULNCHECK_XDB CRITICAL WORKING POC
Drupal Drupalgeddon 2 Forms API Property Injection
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CVSS 9.8