SEC Consult
94 exploits
Active since Dec 2005
Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities
I_ Librarian 4.6/4.7 - Command Injection / Server Side Request Forgery / Directory Enumeration / Cross-Site Scripting
I_ Librarian 4.6/4.7 - Command Injection / Server Side Request Forgery / Directory Enumeration / Cross-Site Scripting
ClipBucket < 4.0.0 - Release 4902 - Command Injection / File Upload / SQL Injection
ClipBucket < 4.0.0 - Release 4902 - Command Injection / File Upload / SQL Injection
Afian AB FileRun 2017.03.18 - Multiple Vulnerabilities
Navetti PricePoint 4.6.0.0 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
Symantec SCSP <5.2.9, SDCS:SA <6.0 MP1 - Auth Bypass
Plex Media Server < 0.9.9.2 - Server-Side Request Forgery and Authentication Bypass via X-Plex-Url Header
Oracle WebCenter Sites - Info Disclosure
Navetti PricePoint 4.6.0.0 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
Navetti PricePoint 4.6.0.0 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
FirePass SSL VPN - Local File Inclusion
Sawmill Enterprise < 8.1.7.3 - Multiple Vulnerabilities
Apache Struts 2.0.0-2.3.16 - Remote Code Execution via DebuggingInterceptor
Ansible Tower < 2.0.4 - Unauthenticated Sensitive Information Exposure via WebSocket Connection
Echo < 2.1.1 and 3.x < 3.0.b6 - XML External Entity Injection
Sophos Web Appliance <3.7.8.2 - XSS
Libmodplug ReadS3M - Stack Overflow
Apache CXF 2.5.0-2.5.9, 2.6.0-2.6.6, 2.7.0-2.7.3 - Denial of Service via Crafted XML
Airlock WAF 4.2.4 - Overlong UTF-8 Sequence Bypass
Bitdefender GravityZone < 5.1.5.386 - Path Traversal via Web Console or Update Server
Horde IMP <= 4.0.4 - Cross-Site Scripting via UTF16 Null Character Handling
GParted <0.15.0 - Command Injection
Opera < 8.54 - Remote Code Execution via Stylesheet Attribute Length Check Bypass