adminlove520
200 exploits
Active since Jan 2024
File Management Feature - Unauthenticated RCE
lodash vulnerable to Code Injection via `_.template` imports key names
Tandoor Recipes Affected by Private Recipe Exposure and Unauthorized Modification
TrueConf Client Update Integrity Verification Bypass
Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`
Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php
Tandoor Recipes Vulnerable to Host Header Injection
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
DigitalOcean Droplet Agent - Command Injection
mm/mseal: update VMA end correctly on merge
SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution
Yadea T5 Electric Bicycles 2024 - Auth Bypass
Safetica STProcessMonitor 11.11.4.0 - Authenticated Denial of Service via IOCTL Handler
Apache HTTP Server: mod_http2 denial of service
iPadOS < 18.4 - Out-of-bounds Write
MCP Inspector < 0.14.1 - Unauthenticated Remote Code Execution via Stdio Command Injection
2 stars
setuptools < 78.1.1 - Path Traversal and Arbitrary File Write via PackageIndex
FreeFloat FTP Server 1.0 - Buffer Overflow
WavePlayer WP <3.8.0 - Unauthenticated RCE
MotionEye <= 0.43.1b4 - Authenticated Configuration Command Injection
MediaWiki <1.39.14, 1.43.4, 1.44.1 - XSS
AirPlay Audio and Video SDK < 2.7.1 and < 3.6.0.126 - Denial of Service via Memory Corruption
n8n Workflow Expression Remote Code Execution
ThrottleStop.sys - Privilege Escalation
2 stars
SUSE Linux Enterprise Module for Development Tools - Denial of Service via HTTP/2 Stream Reset