geniuszly
21 exploits
Active since Mar 2017
Linux Kernel 6.4-6.6.4 - Use-After-Free in io_uring Buffer Ring Registration
HTML5 Video Player < 2.5.27 - Unauthenticated SQL Injection via REST Route Parameter
AVTECH AVM1203 Firmware < fullimg-1023-1007-1011-1009 - Unauthenticated OS Command Injection
CrushFTP < 10.7.1 - Unauthenticated Server-Side Template Injection
Nexxt Nebula 1200-AC <15.03.06.60 - Auth Bypass, Command Injection
Grav < 1.7.45 - Authenticated Server-Side Template Injection
Check Point Quantum Gateway - Information Disclosure
macOS - Use-After-Free
Arris TG2482A Firmware <= 9.1.103GEM9 - Remote Code Execution via Ping Utility
Nexxt Amp300 ARN02304U8 RCE via Ping Feature JSON Host Field
LiteSpeed Cache < 6.5.0.1 - Unauthenticated Authentication Bypass via Insufficiently Protected Credentials
PostgreSQL 9.3-11.2 - Authenticated OS Command Injection via COPY TO/FROM PROGRAM
Internet Information Services 6.0 - Remote Code Execution via WebDAV PROPFIND Request
TeamCity < 2023.11.4 - Authentication Bypass
Dogtag PKI - XML External Entity File Disclosure via Crafted HTTP Request
Tenda AC15 AC1900 15.03.05.19 - OS Command Injection via lanIp Parameter
PostgreSQL 9.3-11.2 - Authenticated OS Command Injection via COPY TO/FROM PROGRAM
CVSS 7.2
Tenda AC15 AC1900 15.03.05.19 - OS Command Injection via lanIp Parameter
CVSS 9.8
Dogtag PKI - XML External Entity File Disclosure via Crafted HTTP Request
CVSS 7.5
HTML5 Video Player < 2.5.27 - Unauthenticated SQL Injection via REST Route Parameter
CVSS 6.5
AVTECH AVM1203 Firmware < fullimg-1023-1007-1011-1009 - Unauthenticated OS Command Injection
CVSS 8.8