adminlove520
199 exploits
Active since Jan 2024
Atlassian Confluence SSTI Injection
Google Chrome <147.0.7727.55 - Type Confusion
Microsoft Windows Shell - Protection Mechanism Failure
Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
Hyland Alfresco Content Services < 25.3 - Unauthenticated Arbitrary File Read via Resource Endpoint
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
Craft CMS <= 5.9.5 - Missing Authorization in Migrate Endpoint
Windows SMB Server - Privilege Escalation
Apache HTTP Server: http2: double free and possible RCE on early reset
Google Android <16-qpr2 - Auth Bypass
Palo Alto PAN-OS User-ID Authentication Portal - Unauthenticated Root RCE
MagicMirror²: Unauthenticated SSRF via /cors endpoint
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
Apache MINA: CWE-502 Deserialization of Untrusted Data (take 2)
ePower epower.ie - Denial of Service via WebSocket Authentication Request Flood
pac4j-jwt <4.5.9/5.7.9/6.3.3 - Auth Bypass
Temporary Login <= 1.0.0 - Authentication Bypass to Account Takeover
BeyondTrust Privileged Remote Access < 25.1 and Remote Support < 25.3.2 - Unauthenticated Remote Code Execution
Microsoft Defender Elevation of Privilege Vulnerability
ActivityManagerService - Privilege Escalation
Apktool: Path Traversal to Arbitrary File Write
Windows SMB Server - Privilege Escalation
crypto: algif_aead - Revert to operating out-of-place
BentoPDF: Stored XSS via Markdown Editor Leading to Persistent File Exfiltration
4 stars