adminlove520
124 exploits
Active since Jan 2024
Atlassian Confluence SSTI Injection
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
File Management Feature - Unauthenticated RCE
lodash vulnerable to Code Injection via `_.template` imports key names
TrueConf Client Update Integrity Verification Bypass
Tandoor Recipes Vulnerable to Host Header Injection
Tandoor Recipes Affected by Private Recipe Exposure and Unauthorized Modification
mm/mseal: update VMA end correctly on merge
3 stars
SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution
DigitalOcean Droplet Agent - Command Injection
Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php
Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`
Yadea T5 Electric Bicycles 2024 - Auth Bypass
STProcessMonitor 11.11.4.0 - DoS
Apple Ipados < 18.4 - Out-of-Bounds Write
Modelcontextprotocol Inspector < 0.14.1 - Missing Authentication
2 stars
Python Setuptools < 78.1.1 - Path Traversal
FreeFloat FTP Server 1.0 - Buffer Overflow
WavePlayer WP <3.8.0 - Unauthenticated RCE
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
MediaWiki <1.39.14, 1.43.4, 1.44.1 - XSS
Apple Airplay Audio Software Development Kit - Memory Corruption
Google Chrome < 128.0.6613.84 - Memory Corruption
AMI's SPx - Auth Bypass
Gogs < 0.13.0 - Remote Code Execution