adminlove520
199 exploits
Active since Jan 2024
Crafty Controller - Authenticated Remote Code Execution via Webhook Template Injection
picklescan <0.0.21 - Code Injection
Cisco Identity Services Engine and ISE-PIC - Unauthenticated Arbitrary File Upload and Remote Code Execution
Camaleon CMS < 2.9.1 - Privilege Escalation via Mass Assignment in UsersController
2 stars
Apache HTTP Server 2.4.35-2.4.63 - Access Control Bypass via TLS 1.3 Session Resumption
NVIDIA CUDA Toolkit - Buffer Overflow
Windows File Explorer - Exposure of Sensitive Information to an Unauthorized Actor
iPadOS < 17.7.6 - Arbitrary File System Modification
Cacti Graph Template authenticated RCE versions prior to 1.2.29
XWiki Platform - Remote Code Execution
mailcow: dockerized <2025-01a - Info Disclosure
FortiOS SSL VPN <7.6.2, 7.4.6, 7.2.10, 7.0.16, 6.4 - Info Disclosure
axios < 1.8.2 - Server-Side Request Forgery via Absolute URL Handling
Below < 0.9.0 - Privilege Escalation via World-Writable Log Directory
Apache Camel <4.10.2 - Command Injection
CrushFTP - Authentication Bypass
macOS < 15.5 - Sandbox Escape via Vulnerable Code Removal
Erlang OTP Pre-Auth RCE Scanner and Exploit
PyTorch < 2.6.0 - Remote Code Execution via torch.load with weights_only=True
Sudo <1.9.17p1 - Privilege Escalation
Langflow AI - Unauthenticated Remote Code Execution
Avast Antivirus 25.1.981.6-25.3 - Privilege Escalation via Integer Overflow
HPE OneView unauthenticated RCE
Linux Kernel - Time-of-check Time-of-use Race Condition in POSIX CPU Timers
PNETLab 4.2.10 - Path Traversal via HTTP Request File Path Manipulation
2 stars