dwisiswant0
50 exploits
Active since Mar 2018
Microsoft Exchange ProxyLogon RCE
Next.js: Cross-site scripting in beforeInteractive scripts with untrusted input
Next.js: Middleware / Proxy bypass in Pages Router applications using i18n
Next.js: Middleware / Proxy bypass through dynamic route parameter injection
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Next.js: Cache poisoning in React Server Component responses
Next.js: Denial of Service in the Image Optimization API
Next.js: Server-side request forgery in applications using WebSocket upgrades
Next.js: Denial of Service via connection exhaustion in applications using Cache Components
Next.js: Cross-site scripting in App Router applications using CSP nonces
Next.js: Cache poisoning via collisions in React Server Component cache-busting
Next.js: Middleware / Proxy redirects can be cache-poisoned
React Server Components <19.2.0 - RCE
Apache Struts 2.0.0-2.5.32 - Path Traversal and Remote Code Execution via File Upload
Microsoft Office Word MSDTJS
BIG-IP 11.6.1-11.6.5.1 - Remote Code Execution via TMUI Undisclosed Pages
WordPress import-xml-feed <2.0.1 - SSRF
Apache OFBiz XML-RPC Java Deserialization
Drupal Drupalgeddon 2 Forms API Property Injection
Apache OFBiz 17.12.03 - Deserialization of Untrusted Data and Cross-Site Scripting via XML-RPC Requests
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
Nodemailer < 7.0.11 - Denial of Service via Crafted Email Address Header
FrankenPHP <1.11.2 - Info Disclosure
Traefik < 3.6.8 - Unauthenticated Denial of Service via STARTTLS Request Bypass
Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Docker API Hooks Parameter