adminlove520
199 exploits
Active since Jan 2024
BentoPDF: Stored XSS via Markdown Editor Leading to Persistent File Exfiltration
4 stars
OP-TEE 3.13.0-4.10.0 - Out-of-bounds Read in PKCS#11 TA Heap via Bad Template Parameter
cPanel and WHM Authentication Bypass via Login Flow
NSA GRASSMARLIN Improper Restriction of XML External Entity Reference
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
Mozilla Firefox and Thunderbird 140.10 and 150 - IndexedDB Information Disclosure
Midi-Synth <1.1.0 - Unauthenticated RCE
GitHub Enterprise Server RCE via Git Push Option Injection
Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
Augmentt 1.0 - Privilege Escalation
Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
Lightspeed Classroom 5.1.2.1763770643 - Auth Bypass
net: skb: fix cross-cache free of KFENCE-allocated skb head
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
Zyxel VMG3625-T50B <5.50(ABPM.9.7)C0 - Command Injection
FUXA < 1.2.10 - Unauthenticated Path Traversal and Arbitrary File Write
Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS
GLPI 11.0.0-11.0.5 Templates - Admin Remote Code Execution
Google Android - Heap Buffer Overflow
Gogs <=0.13.4 - Privilege Escalation
apache-airflow-providers-amazon < 9.22.0 - Origin Validation Error in AWS Auth Manager
Apache APISIX: forward auth plugin allows header injection
Google Chrome < 146.0.7680.75 - Out-of-bounds Write in Skia via Crafted HTML Page
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution