h00die
198 exploits
Active since Jul 1997
Aerohive NetConfig 10.0r8a LFI and log poisoning to RCE
Apache NiFi 0.0.2-1.21.0 - Authenticated Remote Code Execution via H2 JDBC Database URL
Apache NiFi 0.0.2-1.21.0 - Authenticated Remote Code Execution via H2 JDBC Database URL
CVSS 8.8
OpenSSL 1.0.1-1.0.1l - Man-in-the-Middle Cipher Downgrade via DHE_EXPORT
CVSS 3.7
OpenSSL <1.0.1s, 1.0.2 before 1.0.2g - RCE
CVSS 5.9
SSL - Info Disclosure
Oracle Communications Application Session Controller 3.0.0-3.9.1 - Inadequate Encryption Strength via RC4 Algorithm
CVSS 5.9
OpenSSL 3.0.0-3.0.5 - NULL Pointer Dereference via Legacy Custom Cipher Handling
CVSS 7.5
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
CVSS 8.8
Agentejo Cockpit < 0.11.2 - NoSQL Injection via Auth Controller Check Function
CVSS 9.8
Linux kernel <3.19.0-21.21 - Privilege Escalation
CVSS 7.8
2021 Ubuntu Overlayfs LPE
CVSS 8.8
GameOver(lay) Privilege Escalation and Container Escape
CVSS 7.8
Linux Kernel 4.6.3 Netfilter Privilege Escalation
CVSS 7.8
University of Washington IMAP Toolkit 2007f - Command Injection
CVSS 7.5
Kaseya Unitrends Backup < 10.1 - Unauthenticated Command Injection via /api/hosts Parameter
CVSS 9.8
Eclipse Jetty 9.4.37-9.4.42, 10.0.1-10.0.5, 11.0.1-11.0.5 - Directory Traversal & Security Bypass via Encoded URI
CVSS 5.3
Rejected
CVSS 8.8
Overlayfs Privilege Escalation
CVSS 6.7
Polycom HDX System Software < 3.0.5 - Use of Hard-coded Credentials
CVSS 9.8
Unitrends UEB http api remote code execution
CVSS 9.8
Pi-hole Web interface <5.5.1 - Code Injection
CVSS 7.6
GitLab Password Reset Account Takeover
CVSS 10.0
Wordpress POST SMTP Account Takeover
CVSS 9.8
Brother DCP-J132W Firmware < 1.20 - Denial of Service via Malformed HTTP POST Request
CVSS 7.5