jakabakos
24 exploits
Active since Nov 2017
Artifex Ghostscript <10.01.2 - Privilege Escalation
Apache Struts 2.0.0-2.5.32 - Path Traversal and Remote Code Execution via File Upload
Apache OFBiz XML-RPC Java Deserialization
Microsoft Windows Search - Remote Code Execution
Apache Superset Signed Cookie Priv Esc
Rejetto HTTP File Server - Template injection
iText < 5.5.12 and 7.x < 7.0.3 - XML External Entity Injection
Adobe Commerce and Magento - XML External Entity Injection to Code Execution
Apache Airflow < 2.5.1 and Apache Airflow MySQL Provider < 4.0.0 - Command Injection
Anyscale Ray 2.6.3 and 2.8.0 - Remote Code Execution via Job Submission API
Mirth Connect Deserialization RCE
Adobe ColdFusion <2018 Update 15, 2021 Update 5 - RCE
Apache HugeGraph-Server - Remote Command Execution
CrushFTP < 10.7.1 - Unauthenticated Server-Side Template Injection
NextGen Healthcare Mirth Connect <4.4.1 - RCE
Cacti < 1.2.25 - Authenticated Remote Code Execution via SNMP Device Options
Apache Airflow < 2.4.0 - Authenticated Remote Code Execution via Run ID Parameter
Spring Framework - Remote Code Execution via Data Binding
Cacti 1.2.25 - Authenticated Blind SQL Injection via SNMP Notification Receivers
Geoserver unauthenticated Remote Code Execution
CVSS 9.8
PHP CGI Argument Injection Remote Code Execution
CVSS 9.8
Artifex Ghostscript <10.01.2 - Privilege Escalation
CVSS 7.8
Apache RocketMQ update config RCE
CVSS 9.8
Apache OFBiz < 18.12.10 - Unauthenticated Remote Code Execution via XML-RPC
CVSS 9.8