geo-chen
57 exploits
Active since Feb 2025
Overseerr 1.35.0 Authorization Bypass via pushSubscriptions API
CVSS 5.4
Fathom Lite 1.3.1 Stored XSS via /collect Endpoint
CVSS 6.1
Void 1.3.4 Path Traversal via AI Agent File-Reading Tools
CVSS 5.3
AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation
CVSS 4.2
h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API
CVSS 9.8
SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route
CVSS 9.1
Vanna 2.0.2 Path Traversal via FileSystemConversationStore
CVSS 8.6
Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
CVSS 8.8
Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint
CVSS 6.5
Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
CVSS 5.8
Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure
CVSS 4.3
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
CVSS 5.3
TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints
CVSS 6.5
Maybe 0.6.0 Missing Authorization via HostingsController show/update
CVSS 6.5
Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint
CVSS 9.8
YI Car Dashcam <3.88 - Info Disclosure
CVSS 9.8
70mai X200 Firmware < 2025-10-10 - Improper Authentication in Pairing
CVSS 7.3
70mai X200 <20251010 - Default Credentials
CVSS 7.3
Thinkware Car Dashcam F800 Pro <20250226 - Default Credentials
CVSS 2.0
Thinkware Car Dashcam F800 Pro <20250226 - Info Disclosure
CVSS 2.1
Thinkware Car Dashcam F800 Pro <20250226 - Info Disclosure
CVSS 6.3
Thinkware Car Dashcam F800 Pro <20250226 - DoS
CVSS 3.1
IROAD Dash Cam X5-X6 <20250308 - Auth Bypass
CVSS 9.8
BlackVue App 3.65 - Info Disclosure
CVSS 3.3
BlackVue App 3.65 - Sensitive Query String Exposure via API Handler
CVSS 3.7