dyeat
48 exploits
Active since Jun 2016
Jenkins cli Ampersand Replacement Arbitrary File Read
CVSS 9.8
Joomla! 3.7.x - SQL Injection
CVSS 9.8
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
CVSS 5.3
Jorani 1.0.0 - Path Traversal and Remote Code Execution
CVSS 9.8
Juniper Networks Junos OS on EX Series <20.4R3-S9 - PHP External Variable Modification
CVSS 5.3
Ignition < 2.5.2 - Unauthenticated Remote Code Execution via file_get_contents() and file_put_contents()
CVSS 9.8
Windows 10, 11, and Server - Remote Code Execution
CVSS 9.8
Milesight <v35.3.0.7 - Info Disclosure
CVSS 7.5
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
CVSS 7.5
mongo-express < 0.54.0 - Remote Code Execution via toBSON Method
CVSS 9.9
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
Node.js <8.6.0 - Directory Traversal
CVSS 7.5
ownCloud Phpinfo Reader
CVSS 10.0
PHP CGI Argument Injection Remote Code Execution
CVSS 9.8
PHPUnit < 4.8.28 and 5.x < 5.6.3 - Remote Code Execution via HTTP POST Data
CVSS 9.8
pyLoad js2py Python Execution
CVSS 9.8
React Server Components <19.2.0 - RCE
CVSS 10.0
Redhat Cloudforms < 2.12.4 - Information Disclosure
CVSS 7.5
Ruby On Rails File Content Disclosure (
CVSS 7.5
Splunk Enterprise <9.0.7-9.1.2 - RCE
CVSS 8.0
ACME mini-httpd < 1.30 - Unauthenticated Arbitrary File Read
CVSS 6.5
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
xfrm: esp: avoid in-place decrypt on shared skb frags
CVSS 8.8