mbadanoiu
62 exploits
Active since Dec 2014
Crafter CMS 3.1.0-3.1.22 - Authenticated Remote Code Execution via FreeMarker SSTI
CVSS 6.4
Magnolia CMS < 6.2.4 - Formula Injection via CSV/XLS Export
CVSS 7.8
Magnolia CMS <6.2.11 - Code Injection
CVSS 9.8
Magnolia CMS < 6.2.4 - Server-Side Template Injection via Registration and Forgotten Password Forms
CVSS 9.8
Magnolia CMS < 6.2.4 - XML External Entity Injection via XLF File
CVSS 7.8
Magnolia CMS <6.2.3 - CSRF,Open Redirect
CVSS 8.8
Cisco SD-WAN < 20.9 - Authenticated Privilege Escalation via CLI Command Injection
CVSS 7.8
JetBrains YouTrack <2021.4.40426 - SSRF
CVSS 9.8
GeoTools < 24.6 - Authenticated Expression Language Injection via JNDI Lookup
CVSS 8.2
Apache OFBiz < 18.12.06 - Server-Side Template Injection via Ecommerce Contact Us Subject Field
CVSS 7.5
MITRE Caldera < 2.8.1 - Authenticated Command Injection via Startup Requirements
CVSS 8.8
MITRE Caldera < 2.8.1 - Cross-Site Scripting
CVSS 6.1
MITRE Caldera 2.9.0 - XML External Entity Injection via Debrief Plugin SVG Parameter
CVSS 8.8
MITRE Caldera < 2.8.1 - OS Command Injection via Human Plugin Name Parameter
CVSS 8.8
MITRE Caldera < 2.8.1 - Improper Privilege Management
CVSS 8.1
Pulse Secure Desktop Client (Linux) < 9.1R9 - Buffer Overflow
CVSS 7.8
Pulse Secure Desktop Client <9.1R9 - RCE
CVSS 8.8
Pulse Secure Desktop Client (Linux) < 9.1R9 - Privilege Escalation
CVSS 7.8
Pulse Secure Desktop Client (Linux) < 9.1R9 - Privilege Escalation
CVSS 7.8
Roundcube Webmail < 1.4.4 - Stored Cross-Site Scripting via HTML Message CDATA
CVSS 6.1
Roundcube Webmail < 1.3.12 and 1.4.x < 1.4.5 - Stored Cross-Site Scripting via XML Attachment Preview
CVSS 6.1
Apache Solr < 8.6.0 - Unauthenticated Arbitrary File Read and Write via Replication Handler Location Parameter
CVSS 8.8
Roundcube Webmail < 1.4.4 - Remote Code Execution via Shell Metacharacters in Image Configuration
CVSS 9.8
Roundcube Webmail < 1.4.4 - Remote Code Execution via Shell Metacharacters in Image Configuration
CVSS 9.8
Roundcube Webmail <1.4.4 - Path Traversal
CVSS 9.8