iglocska
99 exploits
Active since Sep 2016
cerebrate < 1.4 - Username Enumeration
CVSS 5.3
MISP < 2.4.156 - Stored Cross-Site Scripting via Custom Auth Name
CVSS 4.8
MISP < 2.4.158 - Deserialization of Untrusted Data via PHAR
CVSS 9.8
MISP < 2.4.158 - Stored Cross-Site Scripting via LinOTP Login Field
CVSS 5.4
MISP < 2.4.158 - Stored Cross-Site Scripting in Galaxy Clusters
CVSS 5.4
MISP < 2.4.158 - Stored Cross-Site Scripting via Event Graph Tag Name
CVSS 5.4
MISP < 2.4.158 - Stored Cross-Site Scripting in Cerebrate View via URL Field
CVSS 4.8
MISP < 2.4.158 - Cross-Site Scripting in OrganisationsController
CVSS 6.1
MISP < 2.4.158 - Improper Authentication via Accept Header Manipulation
CVSS 7.5
MISP < 2.4.167 - Cross-Site Scripting in Template File Upload
CVSS 6.1
MISP < 2.4.167 - SQL Injection via IndexFilterComponent Parameter Handling
CVSS 9.8
MISP < 2.4.166 - Improper Handling of Exceptional Conditions via Order Parameter
CVSS 9.8
Cerebrate 1.14 - Privilege Escalation
CVSS 4.3
MISP < 2.4.176 - SQL Injection via AppModel Filter Mishandling
CVSS 9.8
MISP < 2.4.176 - Cross-Site Scripting via Parameter Parsing
CVSS 9.8
MISP <2.4.182 - Privilege Escalation
CVSS 9.8
MISP < 2.4.187 - Arbitrary File Upload via Logo Upload
CVSS 9.8
MISP <2.4.187 - File Upload Vulnerability
CVSS 9.8
MISP < 2.4.197 - Improper Access Control in BookmarksController
CVSS 6.5
MISP < 2.4.198 - Incorrect Authorization in Attribute Search
CVSS 4.3
MISP < 2.4.193 - Authenticated Stored Cross-Site Scripting via Menu Custom Right Link
CVSS 5.5
MISP < 2.4.193 - Authenticated Stored Cross-Site Scripting via menu_custom_right_link_html Parameter
CVSS 5.5
MISP < 2.4.193 - Cross-Site Scripting via REST Endpoint Response
CVSS 7.2
MISP < 2.5.24 - Invalid File Upload Validation in EventsController
CVSS 8.2