h00die
198 exploits
Active since Jul 1997
GitLab Password Reset Account Takeover
CVSS 10.0
Wordpress POST SMTP Account Takeover
CVSS 9.8
HP-UX - Unauthenticated Remote Login via Default Null Password
WooCommerce Payments < 4.8.2 and WooPayments < 5.6.2 - Unauthenticated Privilege Escalation via Request Forgery
CVSS 9.8
LimeSurvey Zip Path Traversals
CVSS 9.8
Strapi CMS Unauthenticated Password Reset
CVSS 9.8
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
CVSS 5.3
Icinga Web 2 <2.9.5 - Info Disclosure
CVSS 7.5
Wordpress Secure Copy Content Protection and Content Locking sccp_id Unauthenticated SQLi
CVSS 9.8
HP-UX - Unauthenticated Remote Login via Default Null Password
Synology DSM <6.1.3-15152 - Info Disclosure
CVSS 5.3
Wordpress BulletProof Security Backup Disclosure
CVSS 5.3
Wordpress RegistrationMagic task_ids Authenticated SQLi
CVSS 7.2
idangero chop_slider - Blind SQL Injection via id GET Parameter
CVSS 9.8
Total Upkeep - WordPress Backup Plugin <1.14.9 - Info Disclosure
CVSS 7.5
ES File Explorer File Manager < 4.1.9.7.4 - Unauthenticated Arbitrary File Read via TCP Port 59777
CVSS 8.1
Apache httpd <2.4.28 - Use After Free
CVSS 7.5
Easy WP SMTP < 1.4.4 - Administrator Account Takeover via Password Reset Link Exposure in Debug Log
CVSS 7.5
Paid Memberships Pro < 2.9.8 - Unauthenticated SQL Injection via Order REST Route Code Parameter
CVSS 9.8
VICIdial < 2.14b0.5-3555 - SQL Injection via AST Agent Time Sheet Agent Parameter
CVSS 6.4
LearnPress <3.2.6.7 - SQL Injection
CVSS 8.8
WPS Hide Login <1.9.1 - Info Disclosure
CVSS 7.5
Riverbed SteelHead VCX <9.6.0a - Path Traversal
Varnish < 2.1.0 - Unauthenticated Remote Code Execution via CLI vcl.inline Directive
SSL/TLS Version Detection
CVSS 3.4