brianwrf
14 exploits
Active since Jan 2017
WordPress < 4.9.9 and 5.x < 5.0.1 - Authenticated Remote Code Execution via Image Metadata
Samba is_known_pipename() Arbitrary Module Load
Apache Karaf < 4.1.7 and 4.2.0-4.2.2 - XML External Entity Injection via Features XML Deployer
Apache Struts 2.0.0-2.3.33 and 2.5-2.5.10.1 - Remote Code Execution via Freemarker Tag Expression
Rejected
18 stars
Apache Struts 2 Namespace Redirect OGNL Injection
Apache Tika 0.1-1.18 - XML External Entity Injection
Joomla! 3.7.x - SQL Injection
python-gnupg 0.4.3 - Improper Input Validation
Magento < 2.0.6 - Unauthenticated PHP Object Injection via Serialized Shopping Cart Data
Oracle WebLogic Server <12.2.1.3 - RCE
CVSS 9.8
Oracle WebLogic Server <12.2.1.3 - RCE
CVSS 9.8
Oracle WebLogic Server <12.2.1.3 - RCE
CVSS 9.8
Apache Struts 2.0.0-2.3.33 and 2.5-2.5.10.1 - Remote Code Execution via Freemarker Tag Expression
CVSS 9.8