Takahiro Yokoyama
19 exploits
Active since Apr 2022
Langflow < 1.8.0 - Remote Code Execution via CSV Agent Node
CVSS 9.8
D-Tale RCE
CVSS 9.8
judge0 1.13.0 - Arbitrary File Write and Remote Code Execution via Symlink Attack
CVSS 10.0
Ray < 2.8.1 - Unauthenticated Local File Inclusion via Static Directory
CVSS 7.5
Langflow AI - Unauthenticated Remote Code Execution
CVSS 9.8
BentoML >=1.3.4 <1.4.3 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
Appsmith < 1.52 - Authenticated Remote Code Execution via PostgreSQL Datasource Query
CVSS 9.8
Anyscale Ray 2.6.3 and 2.8.0 - Remote Code Execution via Job Submission API
CVSS 9.8
Selenium Grid < 4.0.0 - Cross-Site Request Forgery via Non-JSON Content Types
CVSS 8.8
Local Privilege Escalation via CVE-2023-0386
CVSS 7.8
BentoML < 1.4.8 - Remote Code Execution via Insecure Deserialization
CVSS 9.8
Judge0 <1.13.1 - Privilege Escalation
CVSS 10.0
LibreNMS Authenticated RCE (CVE-2024-51092)
CVSS 9.1
PowerShellEmpire Arbitrary File Upload (Skywalker)
CVSS 9.8
InvokeAI 5.3.1-5.4.2 - Remote Code Execution via Unsafe Model File Deserialization
CVSS 9.8
Unauthenticated RCE in NetAlertX
CVSS 10.0
Rejected
Selenium Grid < 4.0.0 - Cross-Site Request Forgery via Non-JSON Content Types
CVSS 8.8
Ray < 2.8.1 - Unauthenticated Remote Code Execution via CPU Profile URL Parameter
CVSS 9.8