hh-hunter
6 exploits
Active since Apr 2021
Java OpenWire - Deserialization RCE
CVSS 10.0
MLflow < 2.2.1 - Path Traversal via Backslash Sequence
CVSS 9.3
Spring Cloud Gateway Remote Code Execution
CVSS 10.0
Nacos < 1.4.1 - Authentication Bypass via User-Agent Spoofing
CVSS 8.6
GitLab 11.9.0-13.8.7 - Unauthenticated Remote Code Execution via ExifTool Image Parsing
CVSS 10.0
Workreap < 2.2.2 - Unauthenticated Arbitrary File Upload via AJAX Temp File Uploader
CVSS 9.8