exploitintel
84 exploits
Active since Mar 2022
Grafana Image Renderer 1.0.0-4.0.16 - Remote Code Execution via CSV Endpoint File Path Parameter
Mattermost <11.0.2, 10.12.1, 10.11.4, 10.5.12 - Auth Bypass
Hugging Face smolagents - Deserialization
Mattermost 9.11.0-9.11.7, 10.2.0-10.2.2, 10.3.0-10.3.2, 10.4.0-10.4.1 - SQL Injection via Boards Reordering
Apache HugeGraph < 1.7.0 - Remote Code Execution via Hessian Deserialization
Open Asset Import Library Assimp 5.4.3 - Out-of-Bounds Read in LWS File Handler
Apache InLong <2.1.0 - Deserialization
Next.js Middleware Bypass
Apache ActiveMQ NMS OpenWire Client <2.1.1 - Deserialization
Apache Seata 2.0.0-2.3.0 - Deserialization of Untrusted Data in Raft Cluster Mode
Invisioncommunity < 5.0.7 - Remote Code Execution
Mattermost <=10.5.5, <=9.11.15, <=10.8.0, <=10.7.2, <=10.6.5 - Authenticated Arbitrary File Write via Path Traversal
Conjur 1.19.5-1.21.1 and 13.1-13.4.1 - Authenticated Remote Code Execution via Template Injection
Apache Commons OGNL - Code Injection
Apache Seata <2.5.0 - Deserialization
Apache OFBiz < 24.09.02 - Unauthenticated Remote Code Execution via Scrum Plugin
Dataease <= 2.10.12 - Remote Code Execution via Impala JDBC Connection String JNDI Injection
Apache Druid <= 34.0.0 - Weak Cookie Signature Secret via ThreadLocalRandom
pyquokka <= 0.3.1 - Remote Code Execution via Unsafe Pickle Deserialization in FlightServer
Cal.com < 5.9.8 - Authentication Bypass via TOTP Code
Apache NiFi <2.6.0 - Deserialization
Apache Airflow Providers Edge3 < 2.0.0 - Remote Code Execution via Edge3 Worker RPC
FUXA < 1.2.8 - Unauthenticated Authentication Bypass and Remote Code Execution via Referer Header Spoofing
GitLab CE/EE <18.0.6-18.2.2 - Code Injection
Foundation Agents MetaGPT - Deserialization