Rahul Sreenivasan (Tr0j4n)
47 exploits
Active since Mar 2025
Microsoft Windows Shell - Protection Mechanism Failure
Azure Conversation Authoring Client Library - Remote Code Execution via Untrusted Data Deserialization
METIS WIC <= oscore 2.1.234-r18 - RCE
Gogs < 0.13.4 - Authenticated Path Traversal via Wiki Update old_title Parameter
ChurchCRM < 6.7.2 - Authenticated SQL Injection via PaddleNumEditor.php PerID Parameter
Vendure < 3.5.3 - Timing Attack Enumerating Valid Usernames via NativeAuthenticationStrategy
n8n < 1.123.10 and 2.0.0-2.5.0 - Authenticated OS Command Injection and Arbitrary File Read via Git Node
PolarLearn <0-PRERELEASE-15 - Info Disclosure
CAI Framework <= 0.5.10 - Remote Code Execution via Argument Injection in find_file Tool
llama-stack < 0.4.0rc3 - Sensitive Information Exposure in Initialization Log
Group-Office < 6.8.150 - Authenticated Remote Code Execution via tmp_file Parameter
Frigate < 0.16.4 - Remote Command Execution via go2rtc exec Directive
taklaxbr/zai_shell < 9.0.3 - Unauthenticated Remote Code Execution via P2P Terminal Sharing
Tenda G300-F <16.01.14.2 - Command Injection
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
vaultwarden < 1.35.3 - Incorrect Authorization via Organization Ciphers Endpoint
Hyland OnBase - Unauthenticated RCE
Richie < 3.3.0 - Observable Timing Discrepancy in HMAC Signature Verification
LibreNMS < 26.2.0 - SQL Injection via IPv6 Address Search in ajax_table.php
Mercator < 2026.02.22 - Authenticated Stored Cross-Site Scripting via Unescaped Blade Directives
rldns 1.3 - Denial of Service via Heap-Based Out-of-Bounds Read
Quiz Maker < 6.7.0.56 - Unauthenticated SQL Injection via Spoofed IP Headers
CVSS 5.9