joshuavanderpoll
12 exploits
Active since Jan 2021
Ignition < 2.5.2 - Unauthenticated Remote Code Execution via file_get_contents() and file_put_contents()
Frigate < 0.16.4 - Remote Command Execution via go2rtc exec Directive
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
Microsoft Windows Defender For Endpoint - Path Traversal
Scramble: Remote code execution via evaluation of user-controlled input in validation rules
KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token
Pix for WooCommerce <=1.5.0 - Arbitrary File Upload
Signal K Server < 2.19.0 - Unauthenticated Remote Code Execution via Backup Validation Endpoint
JetBrains TeamCity < 2024.12 - Incorrect Authorization
Erlang OTP Pre-Auth RCE Scanner and Exploit
FUXA < 1.2.8 - Unauthenticated Authentication Bypass and Remote Code Execution via Referer Header Spoofing
Microsoft Office Word MSDTJS