Valentin Lobstein
99 exploits
Active since Nov 2013
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
CVSS 9.9
Magento SessionReaper
CVSS 9.1
Advanced Custom Fields: Extended <0.9.1.1 - RCE
CVSS 9.8
vBulletin - RCE
CVSS 9.0
Web Check - Command Injection
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
CVSS 9.8
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
CVSS 9.8
Rejected
King Addons for Elementor - Privilege Escalation
CVSS 9.8
Givewp < 3.14.2 - Insecure Deserialization
CVSS 10.0
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVSS 9.8
VICIdial Authenticated Remote Code Execution
CVSS 9.8
Spip < 3.2.18 - Insecure Deserialization
CVSS 9.8
Invisioncommunity < 5.0.7 - Remote Code Execution
CVSS 10.0
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE
CVSS 9.0
ICTBroadcast - Command Injection
Craft CMS Twig Template Injection RCE via FTP Templates Path
CVSS 9.8
Shenzhen Aitemi M300 Wi-Fi Repeater - Command Injection
Xorcom CompletePBX <5.2.35 - Command Injection
CVSS 8.8
Mjdm Majordomo < 2023-11-15 - Command Injection
CVSS 9.8
Vinchin Backup And Recovery < 7.0 - Hard-coded Credentials
CVSS 9.8
CraftCMS - Remote Code Execution
CVSS 10.0
Apache HTTP Server < 9.2.6.0 - Path Traversal
CVSS 9.8
Zyxel Firewall SUID Binary Privilege Escalation
CVSS 9.8