ThemeHackers
33 exploits
Active since Feb 2024
Windows TCP/IP - Remote Code Execution
Windows File Explorer - Exposure of Sensitive Information to an Unauthorized Actor
Windows PowerShell - Unauthenticated Command Injection
Microsoft 365 Apps and Office 2016-2019 - Remote Code Execution via Moniker Link
React Server Components <19.2.0 - RCE
Vite - Arbitrary File Read
D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L - OS Command Injection via cgi_user_add name Parameter
Windows File Explorer - Exposure of Sensitive Information to an Unauthorized Actor
Mikrotik RouterOS 6.40.5-6.49.10 - DoS
pgAdmin < 9.10 - Remote Code Execution via PLAIN-Format Dump File Restore
Next.js Middleware Bypass
Azure Storage Resource Provider - SSRF
Next.js Middleware Bypass
Termix 1.7.0-1.9.0 - Stored Cross-Site Scripting via SVG File Preview
Azure Storage Resource Provider - SSRF
Fortra GoAnywhere MFT < 7.6.3 - Deserialization of Untrusted Data via License Servlet
D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L - OS Command Injection via cgi_user_add name Parameter
Mikrotik RouterOS 6.40.5-6.49.10 - DoS
CVSS 7.5
Termix 1.7.0-1.9.0 - Stored Cross-Site Scripting via SVG File Preview
CVSS 8.0
Windows File Explorer - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
Azure Storage Resource Provider - SSRF
CVSS 9.9
Next.js Middleware Bypass
CVSS 9.1
Vite - Arbitrary File Read
CVSS 5.3
Fortra GoAnywhere MFT < 7.6.3 - Deserialization of Untrusted Data via License Servlet
CVSS 10.0
WinRAR < 7.13 - Path Traversal and Arbitrary Code Execution via Malicious Archive
CVSS 8.8