h00die
198 exploits
Active since Jul 1997
Splunk < 7.0.1 - Unauthenticated Information Disclosure via Server Info Endpoint
CVSS 5.3
Eclipse Jetty - Information Disclosure
CVSS 5.3
Jasmin Ransomware Web Server Unauthenticated SQL Injection
CVSS 6.5
Jenkins cli Ampersand Replacement Arbitrary File Read
CVSS 9.8
Android Janus APK Signature bypass
CVSS 7.8
Polycom HDX Series - Command Injection
Polycom HDX Video End Points < 3.0.4 and UC APL < 2.7.1.j - Authenticated OS Command Injection via Ping Command
CVSS 8.8
WP Mobile Detector <3.5 - File Upload
CVSS 9.8
Cacti 1.2.12 - Authenticated SQL Injection via color.php filter Parameter
CVSS 7.2
pfSense < 2.2.6 - Authenticated OS Command Injection via Graph Parameter
CVSS 8.8
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
CVSS 8.8
Pi-hole < 3.3 - Authenticated OS Command Injection via Allowlist Domain Parameter
CVSS 8.8
Pi-hole < 4.3.2 - Authenticated Remote Code Execution via DHCP Static Lease
CVSS 7.2
WordPress Popular Posts <= 5.3.2 - Authenticated Arbitrary File Upload in Image.php
CVSS 8.8
Apache RocketMQ update config RCE
CVSS 9.8
Wordpress Plugin Catch Themes Demo Import RCE
CVSS 7.2
Moodle Authenticated Spelling Binary RCE
CVSS 9.1
Wordpress Drag and Drop Multi File Uploader RCE
CVSS 9.8
Primefaces Remote Code Execution Exploit
CVSS 9.8
Elementor Website Builder 3.6.0-3.6.2 - Authenticated Remote Code Execution via Onboarding Module AJAX Actions
CVSS 8.8
Werkzeug < 3.0.3 - Remote Code Execution via Debugger PIN Bypass
CVSS 7.5
AIT CSV import/export < 3.0.3 - Unauthenticated Arbitrary File Upload via upload-handler.php
CVSS 9.8
Moodle Teacher Enrollment Privilege Escalation to RCE
CVSS 8.8
Simple-File-List Plugin <4.2.2 - RCE
CVSS 9.8
Cockpit CMS NoSQLi to RCE
CVSS 9.8