jheysel-r7
54 exploits
Active since Sep 2020
polkit < 0.119 - Unauthenticated Privilege Escalation via D-Bus Request
Apache OFBiz forgotPassword/ProgramExport RCE
CVSS 9.8
pyload-ng v0.5.0b3.dev85 - Remote Code Execution via Crafted HTTP Request
CVSS 9.8
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVSS 9.8
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVSS 8.8
Adobe Commerce and Magento - XML External Entity Injection to Code Execution
CVSS 9.8
SimpleHelp Path Traversal Vulnerability CVE-2024-57727
CVSS 7.5
SuiteCRM < 7.14.1 - SQL Injection
CVSS 9.1
pfBlockerNG < 2.1.4_26 - Remote Code Execution via HTTP Host Header
CVSS 9.8
Wordpress BookingPress bookingpress_front_get_category_services SQLi
CVSS 9.8
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE
CVSS 9.0
CVE-2024-20767 - Adobe Coldfusion Arbitrary File Read
CVSS 7.4
GLPI 10.0.0-10.0.17 - Unauthenticated SQL Injection via Inventory Endpoint
CVSS 7.5
dotcms 3.0-22.02 - Unauthenticated Path Traversal and Remote Code Execution via ContentResource API
CVSS 9.8
Apache Couchdb Erlang RCE
CVSS 9.8
Hitachi Vantara Pentaho <9.4.0.1-9.3.0.2 - SSRF
CVSS 8.6
Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
CVSS 9.8
ForgeRock Access Management < 6.5.4 & OpenAM 9.0.0-14.6.3 - RCE via Jato PageSession Deserialization
CVSS 9.8
SmarterMail < 100.0.9413 - Unauthenticated Arbitrary File Upload and Remote Code Execution
CVSS 10.0
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVSS 9.8
Apache OFBiz <18.12.13 - Path Traversal
CVSS 9.8
Apache RocketMQ update config RCE
CVSS 9.8
Geoserver unauthenticated Remote Code Execution
CVSS 9.8
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
CVSS 9.9
LiteSpeed Cache < 6.5.0.1 - Unauthenticated Authentication Bypass via Insufficiently Protected Credentials
CVSS 9.8