Tom
14 exploits
Active since Aug 1998
Hertzbeat < 1.6.0 - SQL Injection via Metric Download Endpoint
CVSS 7.5
Hertzbeat < 1.6.0 - SQL Injection via Metric Download Endpoint
CVSS 7.5
firecrawl < 2.0.1 - Authenticated Server-Side Request Forgery via Webhook Configuration
CVSS 6.3
evmos < 17.0.0 - Arbitrary Token Minting via State Synchronization Race Condition
CVSS 9.1
evmos < 18.0.0 - Incorrect Spendable Balance Calculation in Vesting Token Delegation
CVSS 3.5
evmos < 18.1.0 - Always-Incorrect Control Flow Implementation in ICS20 Transfer
CVSS 7.5
evmos < 18.0.0 - Clawback Vesting Account Bypass via Ethereum Transaction Precompile
CVSS 3.5
evmos < 18.0.0 - Improper Authorization via Vested Token Validator Creation
CVSS 3.5
evmos < 19.0.0 - Incorrect Authorization via Vesting Account Funder Address
CVSS 8.8
Hertzbeat < 1.6.0 - SQL Injection via Metric Download Endpoint
CVSS 7.5
firecrawl < 2.0.1 - Authenticated Server-Side Request Forgery via Webhook Configuration
CVSS 6.3
F5 BIG-IP and BIG-IQ - Authenticated Privilege Escalation via iCall Script or Handler
faxsurvey - Remote Command Execution via Shell Metacharacters in Query String
F5 BIG-IP and BIG-IQ - Authenticated Privilege Escalation via iCall Script or Handler