Zach Hanley
23 exploits
Active since May 2022
F5 BIG-IP iControl RCE via REST Authentication Bypass
VMware Aria Operations for Logs - RCE
Paloaltonetworks Expedition < 1.2.96 - OS Command Injection
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
Fortinet Fortisiem < 7.1.9 - OS Command Injection
Enhancesoft Osticket < 1.17.7 - Injection
N-able N-Central Authentication Bypass and XXE Scanner
N-central <2025.4 - Info Disclosure
2 stars
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
CVSS 9.8
Traccar - Unrestricted File Upload
CVSS 8.5
Vmware Vrealize Log Insight < 4.8 - Path Traversal
CVSS 9.8
Vmware Vrealize Log Insight < 4.8 - Information Disclosure
CVSS 5.3
Vmware Vrealize Log Insight < 4.8 - Improper Access Control
CVSS 9.8
SolarWinds Web Help Desk - Hardcoded Credential
CVSS 9.1
Fortra GoAnywhere MFT Unauthenticated Remote Code Execution
CVSS 9.8
Fortinet Forticlient Endpoint Management Server - SQL Injection
CVSS 9.8
Ivanti Endpoint Manager < 2022 - Improper Input Validation
CVSS 9.8
Fortinet FortiNAC keyUpload.jsp arbitrary file write
CVSS 9.8
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
CVSS 9.8
Paloaltonetworks Expedition < 1.2.96 - OS Command Injection
CVSS 6.5
Lexmark <2023-02-19 - Info Disclosure
CVSS 8.1
Fortinet Fortiproxy < 7.0.7 - Authentication Bypass
CVSS 9.8
Fortinet Fortiproxy < 7.0.7 - Authentication Bypass
CVSS 9.8