adminlove520
199 exploits
Active since Jan 2024
musl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
Lenovo Diagnostics < 5.26.0 and Lenovo Vantage < 4.7.1.4 - Authenticated Arbitrary File Write via Hardware Scan
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
FortiSandbox 4.4.0-4.4.8 - OS Command Injection
File Browser 2.0.0-2.63.1 Hook Runner - Command Injection
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Go-getter may allow to arbitrary filesystem reads through git operations
UniFi Network Application 9.0.118-10.1.89, 10.2.97 - Path Traversal
FreeScout <1.8.212 Open Tracking Endpoint - Insecure Direct Object Reference
Ollama Model Pull API download.go server-side request forgery
React Server Components 19.0.0-19.0.4 19.1.0-19.1.5 19.2.0-19.2.4 - Denial of Service via Crafted HTTP Requests
OWASP CRS <4.22.0-3.3.8 - Info Disclosure
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
Django < 6.0.4, 5.2.13, 4.2.30 - MultiPartParser Base64 Upload Denial of Service
pjsip < 2.16 - Buffer Overflow in PJNATH ICE Session via Long Username
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
iOS and iPadOS < 18.7.7 - Use-After-Free
Cisco Secure Firewall Management Center 6.4.0.13-6.4.0.18, 7.0.0 - RCE via Java Deserialization
Angular CLI <21.2.0-rc.1, 21.0.0-21.1.4, 20.0.0-20.3.16, <19.2.21 - SSRF via Unvalidated Headers
3 stars
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization