dyeat
48 exploits
Active since Jun 2016
ActiveMQ web shell upload
CVSS 9.8
Log4Shell HTTP Header Injection
CVSS 10.0
Apache OFBiz < 18.12.10 - Unauthenticated Remote Code Execution via XML-RPC
CVSS 9.8
Apache OFBiz XML-RPC Java Deserialization
CVSS 9.8
Apache Solr < 7.1 - Remote Code Execution via XXE in XML Query Parser
CVSS 9.8
Apache Tomcat 7.0.0-7.0.81, 8.0.0.RC1-8.0.46, 8.5.0-8.5.22, 9.0.0.M1-9.0.0 - Remote Code Execution via JSP Upload
CVSS 8.1
Apache 2.4.49/2.4.50 Traversal RCE
CVSS 9.8
Cisco IOX XE Unauthenticated RCE Chain
CVSS 10.0
Citrix NetScaler ADC and Gateway - Unauthenticated Remote Code Execution
CVSS 9.8
CrushFTP < 10.7.1 - Unauthenticated Server-Side Template Injection
CVSS 9.8
TP-Link Archer AX21 Firmware < 1.1.4 - Unauthenticated Command Injection via Country Parameter
CVSS 8.8
Drupal Drupalgeddon 2 Forms API Property Injection
CVSS 9.8
Eclipse Jetty - Information Disclosure
CVSS 5.3
F5 BIG-IP iControl RCE via REST Authentication Bypass
CVSS 9.8
F5 BIG-IP 13.1.0-13.1.4 - Unauthenticated Remote Command Execution via Configuration Utility Bypass
CVSS 9.8
FortiSIEM 6.6.0-6.6.2 - OS Command Injection via Crafted API Requests
CVSS 10.0
FortiOS 5.0.0-5.0.13 and FortiProxy 1.0.0-1.0.6 - Heap-Based Buffer Overflow via SSL-VPN Requests
CVSS 9.8
FortiOS/FortiProxy SSL-VPN Heap-based Buffer Overflow
CVSS 9.8
GeoServer WMS GetMap XXE Arbitrary File Read
CVSS 8.2
GitLab 11.9.0-13.8.7 - Unauthenticated Remote Code Execution via ExifTool Image Parsing
CVSS 10.0
Gladinet CentreStack & Triofox <16.12.10420.56791 - Code Injection
CVSS 9.8
Grafana Plugin Path Traversal
CVSS 7.5
Honeywell PM43 Firmware < P10.19.050004 - Command Injection via Printer Web Page Modules
CVSS 9.9
Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) - Command Injection
CVSS 9.1
Ivanti Endpoint Manager Mobile < 11.8.1.1 - Unauthenticated Authentication Bypass
CVSS 9.8