msutovsky-r7
23 exploits
Active since Apr 2022
pretalx < 2.3.2 - Path Traversal via HTML Export Feature
CVSS 6.5
Pretalx Limited File Write to Remote Code Execution
CVSS 4.3
dompdf < 1.2.1 - Remote Code Execution via CSS @font-face src:url
CVSS 9.8
NetAlertX 24.7.18-24.10.12 - Unauthenticated Path Traversal and Arbitrary File Read via logs.php
CVSS 8.6
FreePBX endpoint SQLi to RCE
FreePBX endpoint SQLi to RCE
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
CVSS 10.0
FreePBX <16.0.92-17.0.6 - Authenticated File Upload
WonderCMS Remote Code Execution
CVSS 6.1
Monsta FTP < 2.11 - Unauthenticated Arbitrary File Upload
CVSS 9.8
Tatsu Wordpress Plugin RCE
CVSS 8.1
Clinic's Patient Management System 1.0 - RCE
CVSS 9.8
Sitecore XP CVE-2025-34511 Post-Authentication File Upload
CVSS 8.8
Windows Server 2012, 2016, 2019, 2022, 2025 - Unauthenticated RCE via Deserialization
CVSS 9.8
Sitecore XP/XM 10.1-10.1.4, 10.2, 10.3-10.3.3, 10.4-10.4.1 - Unauthenticated RCE via Hardcoded Credentials
CVSS 7.5
LINQPad Deserialization
CVSS 7.3
PivotX CMS 3.0.0 RC 3 - Stored Cross-Site Scripting via Subtitle Field
CVSS 5.4
Skyvern SSTI Remote Code Execution
CVSS 8.5
netdata 1.44.0-60-1.45.0-169 and 1.45.0-1.45.3 - Local Privilege Escalation via PATH Environment Variable Manipulation
CVSS 8.8
Pandora FMS 774-778 - OS Command Injection via Netflow Directory Field
CVSS 9.8
Sudo <1.9.17p1 - Privilege Escalation
CVSS 9.3
eramba 3.19.1 - Remote Code Execution via Path Parameter
CVSS 8.8
Pretalx Limited File Write to Remote Code Execution
CVSS 4.3