dinosn
29 exploits
Active since Jan 2019
Spring Cloud Function < 3.1.6 - Remote Code Execution via SpEL Routing Expression
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Unauthorized Data Access via T3/IIOP
Oracle WebLogic Server <14.1.1.0.0 - RCE
Citrix NetScaler ADC/Gateway 12.1-55.300/13.0-92.19 Info Disclosure
Ghost 3.24.0-6.19.0 - Info Disclosure
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Oracle WebLogic Server <14.1.1.0.0 - Unauthorized Access
Oracle WebLogic Server <14.1.1.0.0 - RCE
Next.js: Server-side request forgery in applications using WebSocket upgrades
Heap-based Buffer Overflow in MariaDB
Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE (take 2)
Tutor LMS < 3.9.6 - Unauthenticated SQL Injection via Coupon Code Parameter
CVSS 7.5
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
CVSS 8.8
WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter
CVSS 8.6
WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter
CVSS 8.6
Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
CVSS 8.8
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
CVSS 8.8
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
CVSS 10.0
ZeroMQ libzmq < 4.0.9, 4.1.x < 4.1.7, 4.2.x < 4.3.2 - Unauthenticated Stack Overflow via CURVE Encryption/Authentication
CVSS 9.8
libzmq 4.2.0-4.2.4 and 4.3.0 - Authenticated Integer Overflow to Remote Code Execution in v2_decoder.cpp
CVSS 8.8
ProFTPD < 1.3.10rc1 - Remote Code Execution
CVSS 8.1
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
CVSS 8.8
Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
CVSS 8.8