Spencer McIntyre
131 exploits
Active since Mar 1998
GNU Bash < 4.3 - Remote Code Execution via Malformed Environment Variable Function Definitions
CVSS 9.8
Rejected
Rejected
Windows 10 and 11 and Windows Server 2019 - Denial of Service via SMBv3 FileNormalizedNameInformation Request
CVSS 7.5
Netwin SurgeFTP <23c8 - Command Injection
Netwin SurgeFTP <23c8 - Command Injection
Netlogon Weak Cryptographic Authentication
CVSS 5.5
SAP NetWeaver AS JAVA - Missing Authentication Check
CVSS 10.0
Citrix NetScaler ADC/Gateway 12.1-55.300/13.0-92.19 Info Disclosure
CVSS 9.4
Telerik Report Server Auth Bypass and Deserialization RCE
CVSS 9.8
Titan FTP Administrative Password Disclosure
Apache Log4j < 2.12.2 - Remote Code Execution
CVSS 9.0
Windows Server LSA Spoofing (2004 < 10.0.19041.1165, 2019 < 10.0.17763.2114)
CVSS 7.5
LifeSize Room Appliance Software - Remote Code Execution via gateway.php LSRoom_Remoting.doCommand
Apache Superset Signed Cookie Priv Esc
CVSS 8.9
PHPMailer Sendmail Argument Injection
CVSS 9.8
Mirth Connect Deserialization RCE
CVSS 9.8
Netwin SurgeFTP <23c8 - Command Injection
TorchServe 0.1.0-0.8.1 - Server-Side Request Forgery via Model URL Parameter
CVSS 10.0
Confluence - Remote Code Execution
CVSS 9.8
ForgeRock Access Management < 6.5.4 & OpenAM 9.0.0-14.6.3 - RCE via Jato PageSession Deserialization
CVSS 9.8
ManageEngine OpManager < 125203 - Remote Code Execution via Smart Update Manager Servlet
CVSS 9.8
Log4Shell HTTP Header Injection
CVSS 10.0
Log4Shell HTTP Header Injection
CVSS 10.0
Spring Cloud Function < 3.1.6 - Remote Code Execution via SpEL Routing Expression
CVSS 9.8