gagaltotal
22 exploits
Active since Oct 2021
Rejected
1 stars
React Server Components <19.2.0 - RCE
Apache 2.4.49/2.4.50 Traversal RCE
CVSS 9.8
F5 NGINX Plus - NGINX Map Directive and Regex Matching Vulnerability
CVSS 8.1
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
CVSS 9.8
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
CVSS 5.9
rtmutex: Use waiter::task instead of current in remove_waiter()
CVSS 7.8
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
CVSS 9.8
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVSS 8.1
UniFi Network Application 9.0.118-10.1.89, 10.2.97 - Path Traversal
CVSS 10.0
Apache HTTP Server: http2: double free and possible RCE on early reset
CVSS 8.8
Ghost 3.24.0-6.19.0 - Info Disclosure
CVSS 9.4
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12
CVSS 9.8
Ivanti Sentry - Authentication Bypass Using an Alternate Path or Channel
CVSS 9.9
Ivanti Sentry - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 10.0
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
CVSS 7.8
xfrm: esp: avoid in-place decrypt on shared skb frags
CVSS 8.8
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
n8n Workflow Expression Remote Code Execution
CVSS 9.9
Fortinet FortiAnalyzer 7.0.0-7.0.15, 7.2.0-7.2.11, 7.4.0-7.4.9, 7.6.0-7.6.5 - Authentication Bypass via FortiCloud SSO
CVSS 9.8