Synacktiv
30 exploits
Active since Feb 2018
Linux Kernel 3.13-4.14.322 - Out-of-bounds Write in nftables nft_byteorder
Livewire 3.0.0-3.6.3 - Unauthenticated Remote Code Execution via Component Property Hydration
Microsoft Configuration Manager 2403, 2409, 2503 - Remote Code Execution
HP Integrated Lights-Out 4 Firmware < 2.53 - Authentication Bypass and Remote Code Execution
ruby-saml <=1.12.2 and 1.13.0-1.16.0 - Unauthenticated SAML Signature Verification Bypass
ManageEngine ADSelfService Plus CVE-2021-40539
TP-Link Archer A7 AC1750 1.0.15 - RCE
Ubuntu Linux < 18.04 and < 20.10 - Use-After-Free in Shiftfs
iPadOS < 14.4 - Privilege Escalation via Race Condition
iPadOS < 14.2 - Memory Disclosure via Mach Message Trailers
Exim < 4.92.2 - Remote Code Execution via Trailing Backslash
iPadOS < 15.7.6 - Race Condition Leading to Privilege Escalation
FortiAnalyzer and FortiManager < 6.2.3 - Use of Hard-coded Cryptographic Key
FortiOS < 5.6.10 - Use of Hard-coded Credentials in Configuration Backup
Netmake ScriptCase <9.12.006 - Command Injection
Netmake ScriptCase <9.12.006 - Auth Bypass
Exim < 4.90.1 - Remote Code Execution via base64d Buffer Overflow
Microsoft Configuration Manager 2503 < 5.00.9135.1003 - Authenticated SQL Injection
Fortinet FortiAnalyzer-BigData <7.4.1 - Info Disclosure
Fortinet FortiManager Path Traversal via Crafted HTTP Requests
WordPress < 4.9.9 and 5.x < 5.0.1 - Authenticated Remote Code Execution via Image Metadata
Linux Kernel 4.13 through 4.13.7 - Sandbox Escape via waitid
Snipe-IT < 8.1.18 - Unauthenticated Deserialization of Untrusted Data
Snipe-IT < 8.1.18 - Cross-Site Scripting
Microsoft Configuration Manager SQL Injection (2403<5.00.9128.1035, 2409<5.00.9132.1029, 2503<5.00.9135.1008)
CVSS 8.8