Valentin Lobstein
108 exploits
Active since Nov 2013
ollama < 0.1.34 - Path Traversal via Model Path Digest Validation Bypass
CVSS 8.8
Kramer VIAware < 2021-08 - Remote Code Execution via ajaxPages/writeBrowseFilePathAjax.php
CVSS 9.8
Apache 2.4.49/2.4.50 Traversal RCE
CVSS 9.8
Xorcom CompletePBX <= 5.2.35 - Authenticated Path Traversal via Backup and Restore Functionality
CVSS 6.5
WordPress WP Fastest Cache Unauthenticated SQLi (CVE-2023-6063)
CVSS 7.5
N-able N-Central Authentication Bypass and XXE Scanner
CVSS 7.5
VICIdial Authenticated Remote Code Execution
CVSS 9.8
WordPress TI WooCommerce Wishlist SQL Injection (CVE-2024-43917)
CVSS 9.3
WordPress Ultimate Member SQL Injection (CVE-2024-1071)
CVSS 9.8
Xorcom CompletePBX Arbitrary File Read and Deletion via systemDataFileName
CVSS 8.3
LearnPress - WordPress LMS Plugin <4.2.7 - SQL Injection
CVSS 10.0
Splunk Enterprise <9.0.7-9.1.2 - RCE
CVSS 8.0
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
CVSS 9.8
CyberPanel < 2.3.8 - Unauthenticated OS Command Injection via DNS/FTP getresetstatus Endpoint
CVSS 10.0
stamparm/maltrail <=0.54 - Command Injection
GeoServer WMS GetMap XXE Arbitrary File Read
CVSS 8.2
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
CVSS 9.8
WordPress Depicter Plugin SQL Injection (CVE-2025-2011)
CVSS 7.5
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE
CVSS 9.0
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
CVSS 9.8
VICIdial Authenticated Remote Code Execution
CVSS 9.8
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVSS 9.8
WordPress WP Time Capsule Arbitrary File Upload to RCE
CVSS 9.8
GiveWP <= 3.14.1 - Unauthenticated PHP Object Injection via give_title
CVSS 10.0
King Addons for Elementor - Privilege Escalation
CVSS 9.8