Rahul Sreenivasan (Tr0j4n)
47 exploits
Active since Mar 2025
funadmin <7.1.0-rc4 - Deserialization
Quiz Maker < 6.7.0.56 - Unauthenticated SQL Injection via Spoofed IP Headers
Google Chrome <143.0.7499.110 - Memory Corruption
Notepad++ < 8.8.9 - Download of Code Without Integrity Check in WinGUp Updater
Camaleon CMS < 2.9.1 - Privilege Escalation via Mass Assignment in UsersController
10 stars
Sudo <1.9.17p1 - Privilege Escalation
Uxper Sala - Startup & SaaS WordPress Theme <=1.1.4 - Privilege Escalation via Account Takeover
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
Pterodactyl Panel < 1.11.11 - Unauthenticated Remote Code Execution via Locale Endpoint
Google Chrome < 137.0.7151.68 - Out-of-bounds Read and Write in V8
1Panel < 2.0.6 - Remote Code Execution via Incomplete Certificate Verification
React Server Components <19.2.0 - RCE
vaahcms 2.3.1 - Cross-Site Scripting via UserBase.php storeAvatar() Upload Method
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
Gogs < 0.13.3 - Local Code Execution via PutContents API Symbolic Link Handling
User Language Switch <1.6.10 - SSRF
Neo4j < 2026.01 - Cross-Site Scripting via Query Log Unicode Character Escaping
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CleanTalk Spam Protection <= 6.71 - Unauthenticated Arbitrary Plugin Installation via DNS Spoofing
AdForest theme <6.0.12 - Auth Bypass
BeyondTrust Privileged Remote Access < 25.1 and Remote Support < 25.3.2 - Unauthenticated Remote Code Execution
Google Chrome <144.0.7559.132 - Heap Corruption
Nukegraphic CMS 3.1.2 - Authenticated Stored Cross-Site Scripting in User Profile Name Field
10 stars
MediaTek Modem - Input Validation Denial of Service
yuan1994 tpadmin <1.3.12 - Deserialization