aalex954

2 exploits Active since May 2018
CVE-2025-36911 NOMISEC HIGH WORKING POC
Android - Unauthenticated Information Disclosure via Key-Based Pairing Logic Error
In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.
3 stars
CVSS 7.1
CVE-2015-9235 NOMISEC CRITICAL WORKING POC
jsonwebtoken < 4.2.2 - Authentication Bypass via Algorithm Confusion
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).
2 stars
CVSS 9.8