adminlove520
199 exploits
Active since Jan 2024
Safari < 26.2 - Type Confusion via Malicious Web Content
Python <3.14 - Path Traversal
StoreKeeper <14.4.4 - Unrestricted Upload
Android - Use-After-Free in Chrome Sandbox Escape
DataEase < 2.10.10 - Authentication Bypass via Case Insensitivity
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
Notepad++ <8.8.1 - Privilege Escalation
Redis < 6.2.20, 8.2.1-8.2.2 - Authenticated Use-After-Free via Lua Script Garbage Collector Manipulation
Ollama 0.6.7 - Cross-Domain Token Exposure via WWW-Authenticate Header Realm
JGM Pandoc 3.6.4 - Server-Side Request Forgery via Crafted iframe
Cursor < 1.3 - Remote Code Execution via MCP Configuration File Tampering
Adobe Experience Manager Forms < 6.5.23.0 - Unauthenticated Arbitrary Code Execution via Misconfiguration
nestjs/devtools-integration < 0.2.1 - Remote Code Execution via Unsafe JavaScript Sandbox
React Server Components <19.2.0 - RCE
React Server Components <19.3 - Info Disclosure
React Server Components <19.2.1 - DoS
Reolink 8.18.12 - Command Injection via Crafted Folder Name
Reolink 8.18.12 - Authentication Bypass via Client-Side Lock Screen Password Property
Reolink Desktop App 8.18.12 - Info Disclosure
Reolink desktop app - Info Disclosure
Windows Server 2012, 2016, 2019, 2022, 2025 - Unauthenticated RCE via Deserialization
Microsoft Configuration Manager 2403 < 5.00.9128.1037 - Authentication Bypass by Spoofing
Fortinet FortiOS/FortiProxy/FortiSwitchManager SAML Signature Verification Bypass
Nagios Fusion <2024R2 - Auth Bypass
Nagios Fusion <2024R2 - Session Hijacking