Vulnmachines
38 exploits
Active since Jan 2019
Apache 2.4.49/2.4.50 Traversal RCE
Oracle WebLogic Server 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Path Traversal via HTTP
Apache HTTP Server 2.4.49-2.4.50 - Path Traversal and Remote Code Execution via Alias-like Directives
VMware Workspace ONE Access CVE-2022-22954
Spring Cloud Gateway Remote Code Execution
Atlassian Confluence Server and Data Center - OGNL Injection
ImageMagick 7.1.0-49 - Info Disclosure
Spring Data MongoDB - Code Injection
F5 BIG-IP iControl RCE via REST Authentication Bypass
Drupal Core < 7.62 - Remote Code Execution via phar:// Stream Wrapper
HAProxy <2.6 - HTTP Request Smuggling
ManageEngine Desktop Central < 10.1.2137.8 - Unauthenticated Sensitive Information Exposure via HTTP Redirect
WordPress 5.6.0-5.7.0 - Authenticated XML External Entity Injection via Media Library File Upload
Metabase - Path Traversal and Local File Inclusion via Custom GeoJSON Map URL
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
Atlassian Confluence Unauthenticated Remote Code Execution
Atlassian Bitbucket Server/Data Center <7.6.17/<7.17.10/<7.21.4/<8....
Confluence - Remote Code Execution
Atlassian Questions For Confluence - Hardcoded Credentials
Oracle WebLogic Server <14.1.1.0.0 - RCE
Apache Druid < 0.20.0 - Authenticated Remote Code Execution via JavaScript Code Injection
VMware vRealize Operations Manager < 8.4 - Server-Side Request Forgery via API
Cisco IOX XE Unauthenticated RCE Chain
Apache Commons Text 1.5-1.9 - Remote Code Execution via String Interpolation
Zabbix 5.4.0-5.4.7 - Unauthenticated Authentication Bypass via SAML Session Spoofing