exploitintel
84 exploits
Active since Mar 2022
Apache InLong <2.2.0 - Deserialization
Apache Kafka 2.3.0-3.9.0 - Authenticated Remote Code Execution via SASL JAAS LDAP Deserialization
Apache CXF < 3.6.8 - Remote Code Execution via JMS Configuration
Apache Airflow Providers Snowflake <6.4.0 - Special Element Injection
Apache Ranger <=2.7.0 - Auth Bypass
HashiCorp Vault 0.8.0-1.16.22, 1.17.0-1.19.6, 1.20.0 - Authenticated RCE via Plugin Directory
Redis 8.2.0-8.2.2 - Stack-based Buffer Overflow via XACKDEL Command
Foundation Agents MetaGPT - Code Injection
Upsonic - Unauthenticated Remote Code Execution via Cloudpickle Deserialization in add_tool Endpoint
GitLab AI Gateway <18.6.1-18.8.0 - DoS/Code Execution
Apache Druid 0.17.0-35.x - Authentication Bypass via LDAP Anonymous Bind
OpenClaw <2026.2.14 - Path Traversal
LibreNMS < 26.2.0 - SQL Injection via IPv6 Address Search in ajax_table.php
Centreon Open Tickets <25.10.3 - Path Traversal
hoppscotch < 2026.2.0 - Unauthenticated Infrastructure Configuration Overwrite via Onboarding Endpoint
Vikunja < 2.1.0 - Persistent Account Takeover via Password Reset Token Reuse
OpenStack Vitrage <12.0.1,13.0.0,14.0.0,15.0.0 - Code Injection
GNU inetutils <=2.7 - Privilege Escalation
WeGIA < 3.6.5 - Authenticated Remote Code Execution via Database Restore Filename
Vim < 9.2.0073 - OS Command Injection via netrw Plugin SCP URL Handler
MLflow - Unauthenticated Authentication Bypass via Default Credentials in basic_auth.ini
Apache Continuum - Command Injection
Kibana - Remote Code Execution via YAML Deserialization in AI Tools Amazon Bedrock Connector
ruby-saml <=1.12.2 and 1.13.0-1.16.0 - Unauthenticated SAML Signature Verification Bypass
Strapi 5.0.0-5.5.1 - Unauthenticated Private Field Exposure via Lookup Operator