hakaioffsec
13 exploits
Active since Feb 2024
Windows Kernel - Privilege Escalation
Kubernetes ingress-nginx mirror annotations - Controller Code Execution
Kubernetes ingress-nginx - Pod Network Remote Code Execution
ingress-nginx < 1.11.5 and 1.12.0 - Remote Code Execution via auth-url Annotation Injection
Kubernetes ingress-nginx auth-tls-match-cn - Controller Code Execution
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
Centreon Open Tickets <25.10 - Input Validation
Centreon Web <25.10.8 - Blind SQL Injection
Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import
Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
Centreon Open Tickets <25.10.3 - Path Traversal
Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui