Sonny
26 exploits
Active since Jun 2022
Juniper Networks Junos OS on EX Series <20.4R3-S9 - PHP External Variable Modification
FortiProxy 7.0.0-7.0.19 and 7.2.0-7.2.12 - Authentication Bypass via Node.js Websocket Module
FortiProxy 7.0.0-7.0.19 and 7.2.0-7.2.12 - Authentication Bypass via Node.js Websocket Module
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
CrushFTP 10.0.0-10.8.4 and 11.0.0-11.3.3 - Unauthenticated Remote Admin Access via AS2 Validation Bypass
Cleo Harmony, VLTrader, and LexiCom < 5.8.0.21 - Unrestricted File Upload and Remote Code Execution
Commvault Command Center Innovation Release <11.38.20 - Path Traversal
Mitel MiCollab < 9.8.1.201 - Unauthenticated Path Traversal in NuPoint Unified Messaging
Ivanti Endpoint Manager Mobile <= 12.5.0.0 - Unauthenticated Authentication Bypass via API
FreePBX 15.0-15.0.65 - Unauthenticated Authentication Bypass and Remote Code Execution
Apache HTTP Server 2.4.0-2.4.53 - HTTP Request Smuggling via mod_proxy_ajp
Palo Alto Networks PAN-OS 10.2 11.0 11.1 11.2 - Unauthenticated Authentication Bypass
NAKIVO Backup & Replication < 11.0.0.88174 - Absolute Path Traversal via getImageByPath
Ivanti Sentry - Authentication Bypass Using an Alternate Path or Channel
BMC FootPrints ITSM 20.20.02-20.24.01.001 - VIEWSTATE Deserialization Code Execution
Ivanti Sentry - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 10.0
Juniper Networks Junos OS on EX Series <20.4R3-S9 - PHP External Variable Modification
CVSS 5.3
EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
CVSS 9.8
NAKIVO Backup & Replication < 11.0.0.88174 - Absolute Path Traversal via getImageByPath
CVSS 8.6
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
CVSS 7.3
Juniper Junos OS Multiple Versions - Unauthenticated Remote Code Execution via PHPRC
CVSS 9.8
ConnectWise ScreenConnect < 23.9.8 - Authentication Bypass
CVSS 10.0
Juniper Networks Junos OS - Path Traversal
CVSS 5.3
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
CVSS 7.2
Juniper Junos OS on SRX Series < 22.4R3 - Unauthenticated Arbitrary File Upload via J-Web
CVSS 5.3