Valentin Lobstein
108 exploits
Active since Nov 2013
CyberPanel Multi CVE Pre-auth RCE
CVSS 10.0
CyberPanel <2.3.5 - Command Injection
CVSS 10.0
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
CVSS 10.0
SureTriggers - All-in-One Automation Platform < 1.0.78 - Authentication Bypass
CVSS 8.1
Gladinet CentreStack & Triofox <16.12.10420.56791 - Code Injection
CVSS 9.8
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVSS 9.8
v2board / Xboard Authentication Token Exposure via loginWithMailLink
CVSS 9.1
Hashgraph Guardian 3.5.0 Unsandboxed JavaScript Execution RCE
CVSS 8.8
VICIdial Agent Interface - Authenticated Root Command Execution
CVSS 8.8
vBulletin 5.0.0-5.7.5 and 6.0.0-6.0.3 - Unauthenticated API Controller Method Invocation
CVSS 10.0
GiveWP Unauthenticated Donation Process Exploit
CVSS 9.8
Vinchin Backup & Recovery 5.0-7.0 - OS Command Injection
CVSS 9.8
openDCIM < 23.04 - Authenticated SQL Injection via Config::UpdateParameter
CVSS 8.8
openDCIM 23.04 - Privilege Escalation
CVSS 8.8
openDCIM < 23.04 - OS Command Injection via fac_Config.dot Parameter
CVSS 9.8
WWBN AVideo < 24.0 - Unauthenticated SQL Injection via catName Parameter in JSON POST Request
CVSS 9.8
FreeScout <=1.8.206 - Authenticated RCE
CVSS 10.0
FreeScout < 1.8.206 - Authenticated Remote Code Execution via .htaccess Upload
CVSS 8.8
AVideo < 7.0 - Unauthenticated OS Command Injection via base64Url GET Parameter
CVSS 9.8
FreePBX 17.0.2.36-17.0.3 - Authenticated OS Command Injection via SSH Connection Test
CVSS 7.2
SPIP Saisies 5.4.0-5.11.0 - Remote Code Execution
CVSS 9.8
Amidaware Tactical RMM <=1.3.1 - SSTI
CVSS 8.8
MajorDoMo - Unauthenticated Remote Code Execution via Update URL Poisoning
CVSS 9.8
MajorDoMo - Unauthenticated OS Command Injection via rc/index.php Race Condition
CVSS 9.8
MajorDoMo - Unauthenticated Remote Code Execution via Admin Console Eval
CVSS 9.8