RedTeam Pentesting GmbH
54 exploits
Active since Jul 2007
Apache Tomcat 7.0.27-7.0.104, 8.5.0-8.5.56, 9.0.0.M1-9.0.36, 10.0.0-M1-M6 DoS via WebSocket Frame Payload Length
WatchGuard Authentication Gateway and Single Sign-On Client - Authentication Bypass via Protocol Communication
STARFACE < 7.3.0.10 - Authentication Bypass via Password Hash
Apache Tomcat 7.0.27-7.0.104, 8.5.0-8.5.56, 9.0.0.M1-9.0.36, 10.0.0-M1-M6 DoS via WebSocket Frame Payload Length
CVSS 7.5
Cisco RV320 and RV325 Firmware 1.4.2.15-1.4.2.21 - Authenticated Remote Code Execution via HTTP POST Request
CVSS 7.2
myfactory FMS < 7.1-912 - Cross-Site Scripting via UID Parameter
CVSS 6.1
EntryPass N5200 Active Network Control Panel - Unauthenticated Sensitive Information Exposure via /4 Endpoint
Cisco RV320 and RV325 Firmware 1.4.2.15-1.4.2.21 - Authenticated Remote Code Execution via HTTP POST Request
CVSS 7.2
Ladon 0.6.1-0.9.39 - XML External Entity Injection in SOAP Request Handlers
CVSS 9.8
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
CVSS 7.5
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
CVSS 7.5
Moodle Remote Code Execution (CVE-2024-43425)
CVSS 8.1
webEdition CMS <6.3.8-s1 - SQL Injection
Akronymmanager < 0.5.0 - Authenticated SQL Injection via id Parameter
SugarCRM < 6.1.3 - Authenticated Information Disclosure via ShowDuplicates Action
Relay Ajax Directory Manager relayb01-071706/1.5.1/1.5.3 - Arbitrary File Upload
Papoo 3.x - Upload Images Arbitrary File Upload
Papoo CMS 3.7.3 - (Authenticated) Arbitrary Code Execution
Owl Intranet Engine 1.00 - 'userid' Authentication Bypass
Mapbender 2.4.4 - SQL Injection via mod_gazetteer_edit.php gaz Parameter
Mapbender 2.4-2.4.4 - Remote Code Execution via mapFiler.php Factor Parameter
IceWarp eMail Server < 9.3.0 - Cross-Site Scripting via Email Body or RSS Feed Elements
IceWarp eMail Server < 9.3.0 - Cross-Site Scripting via Email Body or RSS Feed Elements
IceWarp eMail Server < 9.4.2 - CRLF Injection via Forgot Password XML Subject
myfactory FMS < 7.1-912 - Cross-Site Scripting via Error Parameter
CVSS 6.1