d0rb
26 exploits
Active since Jul 2021
Windows Error Reporting Service - Privilege Escalation
OpenSSH - DoS
libcurl 7.69.0-8.4.0 - Heap-Based Buffer Overflow in SOCKS5 Proxy Handshake
Moodle 4.1.0-4.1.2 - Unauthenticated Arbitrary Folder Creation via TinyMCE Loader
FortiOS/FortiProxy Out-of-bounds Write Vulnerability
WordPress 6.0-6.5.2 - Stored Cross-Site Scripting via Avatar Block Display Name
Microsoft Outlook - Remote Code Execution
Apache CloudStack 4.5.0-4.18.2.1 - Authentication Bypass via SAML Response Spoofing
macOS < Ventura 13.6.3 - Privilege Escalation
Microsoft Edge Chromium < 121.0.2277.83 - Elevation of Privilege
.NET Framework - Elevation of Privilege via ASP.NET
tinyproxy 1.10.0 and 1.11.1 - Unauthenticated Use-After-Free in HTTP Connection Headers Parsing
lindell17 - Private Key Extraction via Abort Handling in Lindell17 TSS Protocol
QNAP QTS and QuTS hero - Remote Code Execution via Stack-based Buffer Overflow
Ninja Forms < 3.6.26 - Unauthenticated Reflected Cross-Site Scripting
Fluent Bit 2.0.7-3.0.3 - Heap-based Buffer Overflow in HTTP Server Trace Request Parsing
Jorani 1.0.0 - Path Traversal and Remote Code Execution
Apache RocketMQ update config RCE
Adobe Commerce and Magento - XML External Entity Injection to Code Execution
CVSS 9.8
mooSocial mooStore 3.1.6 - Cross-Site Scripting
CVSS 3.5
ownCloud Phpinfo Reader
CVSS 10.0
Citrix NetScaler ADC and Gateway - Unauthenticated Remote Code Execution
CVSS 9.8
FortiSIEM 6.6.0-6.6.2 - OS Command Injection via Crafted API Requests
CVSS 10.0
InfiniteWP Client <= 1.11.1 - Authenticated Sensitive Information Exposure via admin_notice Function
CVSS 7.5
Windows Print Spooler - Remote Code Execution via Privileged File Operations
CVSS 8.8