h00die
198 exploits
Active since Jul 1997
WooCommerce Payments < 4.8.2 and WooPayments < 5.6.2 - Unauthenticated Privilege Escalation via Request Forgery
CVSS 9.8
Icinga Web 2 <2.9.5 - Info Disclosure
CVSS 7.5
Varnish < 2.1.0 - Unauthenticated Remote Code Execution via CLI vcl.inline Directive
HP-UX - Unauthenticated Remote Login via Default Null Password
Grafana Plugin Path Traversal
CVSS 7.5
WordPress <1.6.4 - SQL Injection/XSS
CVSS 9.8
Wordpress BulletProof Security Backup Disclosure
CVSS 5.3
Total Upkeep - WordPress Backup Plugin <1.14.9 - Info Disclosure
CVSS 7.5
Apache RocketMQ update config RCE
CVSS 9.8
Wordpress RegistrationMagic task_ids Authenticated SQLi
CVSS 7.2
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
CVSS 5.3
ColoradoFTP Server < 1.3 Build 8 - Path Traversal
SSH Version Scanner
CVSS 3.7
Juniper ScreenOS 6.2.0r15-6.2.0r18, 6.3.0r12-6.3.0r20 - Remote Admin Access via Hardcoded Password
CVSS 9.8
TeamViewer Unquoted URI Handler SMB Redirect
CVSS 8.8
SUSE Rancher < 2.5.16 - Authenticated Cleartext Storage of Sensitive Information via Kubernetes API
CVSS 9.9
Apache Superset Signed Cookie Priv Esc
CVSS 8.9
BQE BillQuick Web Suite 2018-2021 < 22.0.9.1 - Unauthenticated SQL Injection via txtID Parameter
CVSS 9.8
MongoDB Ops Manager <5.0.21, <6.0.12 - Info Disclosure
CVSS 3.1
GitLab Authenticated File Read
CVSS 10.0
X.org X11 - Unauthenticated Access Control Bypass via xhost Command
Eclipse Jetty - Information Disclosure
CVSS 5.3
Splunk < 7.0.1 - Unauthenticated Information Disclosure via Server Info Endpoint
CVSS 5.3
Jasmin Ransomware Web Server Unauthenticated SQL Injection
CVSS 6.5
Advantech WebAccess 8.1 Post Authentication Credential Collector
CVSS 9.8