VeryLazyTech
21 exploits
Active since Jan 2024
D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L - OS Command Injection via cgi_user_add name Parameter
Rejetto HTTP File Server - Template injection
Sonatype Nexus Repository <3.68.1 - Path Traversal
Telerik Report Server Auth Bypass and Deserialization RCE
Langflow AI - Unauthenticated Remote Code Execution
Jenkins cli Ampersand Replacement Arbitrary File Read
Check Point Quantum Gateway - Information Disclosure
Cleo Harmony, VLTrader, and LexiCom < 5.8.0.21 - Unrestricted File Upload and Remote Code Execution
PDF Generator Addon - Path Traversal
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal via wfu_file_downloader.php
CentralSquare CryWolf - Path Traversal
jsonpath-plus < 10.2.0 - Remote Code Execution via Unsafe vm Usage
Fortinet FortiWeb unauthenticated RCE
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
FoxCMS v.1.2.5 - Remote Code Execution
D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L - OS Command Injection via cgi_user_add name Parameter
CVSS 8.1
Rejetto HTTP File Server - Template injection
CVSS 9.8
Telerik Report Server Auth Bypass and Deserialization RCE
CVSS 9.8
Sonatype Nexus Repository <3.68.1 - Path Traversal
CVSS 7.5
FoxCMS v.1.2.5 - Remote Code Execution
CVSS 9.8
Langflow AI - Unauthenticated Remote Code Execution
CVSS 9.8