Vulnmachines
38 exploits
Active since Jan 2019
VoIPmonitor < 24.61 - Unauthenticated Remote Code Execution via SPOOLDIR Injection
Pega Infinity 8.2.1-8.5.2 - Authentication Bypass via Password Reset
Log4Shell HTTP Header Injection
Apache Spark UI - Privilege Escalation
Microsoft OMI Management Interface Authentication Bypass
Mahara 20.10 - Cross-Site Request Forgery via Inbox Mail Deletion
Laminas Project laminas-http <2.14.2 - Code Injection
Code Snippets < 2.14.0 - Cross-Site Request Forgery via Import Menu
Apache OFBiz 17.12.03 - Deserialization of Untrusted Data and Cross-Site Scripting via XML-RPC Requests
Spring Cloud Netflix Hystrix Dashboard - Remote Code Execution via Request URI Path SpringEL Injection
Citrix ADC (NetScaler) Directory Traversal Scanner
Log4Shell HTTP Header Injection
CVSS 10.0
GitLab 10.5-13.10.4 - Unauthenticated Server-Side Request Forgery via Webhook Internal Network Requests
CVSS 6.8