Reisen_1943
59 exploits
Active since Feb 2024
Eastnets PaymentSafe <2.5.26.0 - XSS
picklescan <0.0.21 - Code Injection
Cisco Identity Services Engine and ISE-PIC - Unauthenticated Arbitrary File Upload and Remote Code Execution
Camaleon CMS < 2.9.1 - Privilege Escalation via Mass Assignment in UsersController
2 stars
Windows File Explorer - Exposure of Sensitive Information to an Unauthorized Actor
iPadOS < 17.7.6 - Arbitrary File System Modification
Cacti Graph Template authenticated RCE versions prior to 1.2.29
XWiki Platform - Remote Code Execution
mailcow: dockerized <2025-01a - Info Disclosure
axios < 1.8.2 - Server-Side Request Forgery via Absolute URL Handling
Below < 0.9.0 - Privilege Escalation via World-Writable Log Directory
Apache Camel <4.10.2 - Command Injection
CrushFTP - Authentication Bypass
macOS < 15.5 - Sandbox Escape via Vulnerable Code Removal
Erlang OTP Pre-Auth RCE Scanner and Exploit
PyTorch < 2.6.0 - Remote Code Execution via torch.load with weights_only=True
Linux Kernel - Time-of-check Time-of-use Race Condition in POSIX CPU Timers
PNETLab 4.2.10 - Path Traversal via HTTP Request File Path Manipulation
2 stars
Python <3.14 - Path Traversal
StoreKeeper <14.4.4 - Unrestricted Upload
Android - Use-After-Free in Chrome Sandbox Escape
DataEase < 2.10.10 - Authentication Bypass via Case Insensitivity
TOTOLINK T6 4.1.5cu.748_B20211015 - Missing Authentication via Form_Login
CVSS 8.8
TOTOLINK LR350 <= 9.3.5u.6369 - Authorization Bypass via authCode Parameter
CVSS 5.3
TOTOLINK T6 4.1.5cu.748_B20211015 - Command Injection
CVSS 6.3