developerfred

2 exploits Active since Jul 2019
CVE-2022-31199 NOMISEC CRITICAL WORKING POC
Netwrix Auditor < 10.5 - Unauthenticated Remote Code Execution via User Activity Video Recording Component
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
CVSS 9.8
CVE-2019-14206 NOMISEC HIGH WORKING POC
Nevma Adaptive Images <0.6.67 - Privilege Escalation
An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php.
CVSS 7.5