kaleth4
33 exploits
Active since Sep 2014
Gitea Docker image trusts spoofable reverse-proxy headers by default
CVSS 9.8
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
CVSS 8.1
Microsoft Office Word MSDTJS
CVSS 7.8
TP-Link Tapo C200 Firmware < 1.1.15 - Unauthenticated Remote Code Execution
CVSS 9.8
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
CVSS 9.1
Green Hills INTEGRITY RTOS 5.0.4 - Info Disclosure
CVSS 7.5
GNU inetutils through 2.7 - Buffer Overflow
CVSS 9.8
Linux Kernel - Use-After-Free in proc_readdir_de via Concurrent getdents and unregister_netdevice
CVSS 7.8
Windows HTTP.sys - Privilege Escalation
CVSS 7.8
Traccar <= 6.11.1 - Cross-Site WebSocket Hijacking via Origin Header Misvalidation
CVSS 7.1
Red Hat Enterprise Linux 9 - Out-of-bounds Write via Read Command Input Buffer Overflow
CVSS 6.1
GeographicLib 2.5 - Buffer Overflow
CVSS 7.5
FUXA < 1.2.8 - Unauthenticated Authentication Bypass and Remote Code Execution via Referer Header Spoofing
CVSS 9.8
Windows 10/11, Server 2008 - Authenticated Heap Overflow in CredSSP
CVSS 7.8
ProFTPD < 1.3.10rc1 - Remote Code Execution
CVSS 8.1
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
Log4Shell HTTP Header Injection
CVSS 10.0
OpenClaw < 2026.3.28 - Authorization Bypass in Discord Text Approval Commands
CVSS 8.8
Microsoft Windows TCP/IP - Remote Code Execution
CVSS 8.1
Windows Active Directory Remote Code Execution Vulnerability
CVSS 8.0
Microsoft Defender Elevation of Privilege Vulnerability
CVSS 7.8
Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability
CVSS 9.9
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CVSS 9.8
NetBT Consulting Services Inc. E-Fatura <1.2.15 - Path Traversal
CVSS 7.3
Remote code execution via RPCSEC_GSS packet validation
CVSS 8.8