Yazan Abu-Nadi
13 exploits
Active since May 2025
Totara LMS <=v19.1.5 - HTML Injection
CVSS 8.0
Totara LMS <=v19.1.5 - Incorrect Access Control
CVSS 9.8
Totara LMS <=v19.1.5 - Email Bombing
CVSS 9.8
ARIS < 10.0.23.0.3587512 - Remote Code Execution via Crafted PDF Upload
CVSS 6.8
ARIS < 10.0.23.0.3587512 - Resource Exhaustion via Unrestricted File Upload
CVSS 6.5
Ascertia SigningHub <= 8.6.8 - Authenticated Email Bombing via Password Reset Function
CVSS 9.8
Ascertia SigningHub <= 8.6.8 - Authenticated Email Bombing via Invite User Function
CVSS 4.3
Flytxt NEON-dX < 0.0.1 - Brute Force Attack via UserId Parameter
CVSS 5.4
SigningHub < 8.6.8 - Arbitrary File Upload via Crafted PDF File
CVSS 9.8
SigningHub < 8.6.8 - Unauthenticated User Account Creation and Denial of Service
CVSS 7.1
SigningHub < 8.6.8 - Authentication Bypass via Brute Force Attack
CVSS 9.8
SigningHub < 8.6.8 - Denial of Service via UploadStreamDocument Rate Limit Bypass
CVSS 7.5
SigningHub < 8.6.8 - Unauthenticated Brute-Force Attack via OTP Verification Endpoint
CVSS 8.1