Sina Kheirkhah
29 exploits
Active since Aug 2021
PHP CGI Argument Injection Remote Code Execution
VMWare Aria Operations for Networks (vRealize Network Insight) pre-authenticated RCE
Fortinet FortiWeb - SQL Injection
Fortinet FortiManager <7.6.0 - RCE
Veeam Backup Enterprise Manager - Auth Bypass
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
Ivanti Connect Secure <22.7R2.5 - RCE
Cleo Harmony, VLTrader, and LexiCom < 5.8.0.21 - Unrestricted File Upload and Remote Code Execution
Veeam Recovery Orchestrator - Auth Bypass
Fortinet FortiSIEM - OS Command Injection
Progress WhatsUp Gold < 23.1.3 - Unauthenticated Remote Code Execution via ExportUtilities.Export.GetFileWithoutZip
WhatsUp Gold < 23.1.3 - Improper Access Control in InstallController.SetAdminPassword
SysAid On-Prem <= 23.3.40 - XML External Entity
VMWare Aria Operations for Networks (vRealize Network Insight) SSH Private Key Exposure
Dell Unity Operating Environment < 5.5.1.0 - Unauthenticated OS Command Injection
cPanel and WHM Authentication Bypass via Login Flow
PHP CGI Argument Injection Remote Code Execution
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
CVSS 9.1
VMWare Aria Operations for Networks (vRealize Network Insight) SSH Private Key Exposure
CVSS 9.8
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
Joomla! EkRishta 2.10 Persistent XSS and SQL Injection
CVSS 8.2
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
WhatsUp Gold SQL Injection (CVE-2024-6670)
CVSS 9.8