ThatNotEasy
16 exploits
Active since Apr 2022
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
Chamilo unauthenticated command injection in PowerPoint upload
WSO2 Arbitrary File Upload to RCE
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
Openfire authentication bypass with RCE plugin
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L - OS Command Injection via nas_sharing.cgi System Parameter
Jenkins cli Ampersand Replacement Arbitrary File Read
Apache Superset Signed Cookie Priv Esc
SPIP < 4.2.1 - Remote Code Execution via Form Value Deserialization
OpenSSH - DoS
Apache OFBiz forgotPassword/ProgramExport RCE
PaperCut MF and NG 8.0-20.1.7 - Unauthenticated Remote Code Execution via SetupCompleted
MStore API < 3.9.2 - Unauthenticated Authentication Bypass via Listing REST API
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
WordPress File Sharing Plugin <2.0.3 - XSS
CVSS 4.4
Juniper Networks Junos OS on EX Series <20.4R3-S9 - PHP External Variable Modification
CVSS 5.3