absholi7ly
22 exploits
Active since Apr 2024
Tomcat Partial PUT Java Deserialization
Ivanti Connect Secure <22.7R2.5 - RCE
Apache Tomcat 9.0.76-9.0.102, 10.1.10-10.1.39, 11.0.0-M2-11.0.5 - Denial of Service via HTTP Priority Header Memory Leak
Microsoft Edge Chromium < 124.0.2478.109 - Exposure of Private Personal Information
LiteSpeed Cache < 6.5.0.1 - Unauthenticated Authentication Bypass via Insufficiently Protected Credentials
WinRAR < 7.12 - Remote Code Execution via Path Traversal in Archive File Handling
Telegram < 10.14.5 - Malicious App Disguised as Video via EvilVideo Vulnerability
Atlassian Confluence Data Center and Server - Remote Code Execution
8theme XStore <9.3.5 - SQL Injection
Apache ActiveMQ 5.16.0-5.16.7, 5.17.0-5.17.6, 5.18.0-5.18.6 - Denial of Service via OpenWire Buffer Size Validation
Apache HTTP Server 2.4.35-2.4.63 - Access Control Bypass via TLS 1.3 Session Resumption
Apache NiFi 1.10.0-2.0.0 - Authenticated Missing Authorization for Parameter Contexts and Controller Services
FreeRDP <3.5.0, <2.11.6 - Memory Corruption
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
Fortinet FortiAnalyzer 7.0.0-7.0.15, 7.2.0-7.2.11, 7.4.0-7.4.9, 7.6.0-7.6.5 - Authentication Bypass via FortiCloud SSO
Node.js 20.0.0-20.19.3, 22.0.0-22.17.0, 24.0.0-24.4.0 - Path Traversal via Windows Device Names in path.join
TP-Link TL-WR845N Firmware < 250401 - Use of Hard-coded Credentials
Tomcat Partial PUT Java Deserialization
PrestaAddons m4pdf <3.3.2 - Code Injection
jsPDF < 4.2.0 - Code Injection via addJS Method
CVSS 8.1
xml-crypto 4.0.0-5.9.9 - Improper Verification of Cryptographic Signature via KeyInfo Element
CVSS 10.0
Tomcat Partial PUT Java Deserialization
CVSS 9.8