c0nyy
49 exploits
Active since Feb 2024
Below < 0.9.0 - Privilege Escalation via World-Writable Log Directory
Apache Camel <4.10.2 - Command Injection
CrushFTP - Authentication Bypass
macOS < 15.5 - Sandbox Escape via Vulnerable Code Removal
Erlang OTP Pre-Auth RCE Scanner and Exploit
PyTorch < 2.6.0 - Remote Code Execution via torch.load with weights_only=True
Linux Kernel - Time-of-check Time-of-use Race Condition in POSIX CPU Timers
PNETLab 4.2.10 - Path Traversal via HTTP Request File Path Manipulation
2 stars
Python <3.14 - Path Traversal
StoreKeeper <14.4.4 - Unrestricted Upload
Android - Use-After-Free in Chrome Sandbox Escape
DataEase < 2.10.10 - Authentication Bypass via Case Insensitivity
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
Notepad++ <8.8.1 - Privilege Escalation
Ollama 0.6.7 - Cross-Domain Token Exposure via WWW-Authenticate Header Realm
Cursor < 1.3 - Remote Code Execution via MCP Configuration File Tampering
Adobe Experience Manager Forms < 6.5.23.0 - Unauthenticated Arbitrary Code Execution via Misconfiguration
React Server Components <19.3 - Info Disclosure
Nagios Fusion <2024R2 - Session Hijacking
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
Imithemes Real Spaces - WordPress Properties Directory Theme <= 3.6 - Privilege Escalation
ThrottleStop.sys - Privilege Escalation
2 stars
TOTOLINK T6 4.1.5cu.748_B20211015 - Missing Authentication via Form_Login
CVSS 8.8
TOTOLINK LR350 <= 9.3.5u.6369 - Authorization Bypass via authCode Parameter
CVSS 5.3