nicolaasuni
10 exploits
Active since Sep 2018
TCPDF < 6.2.22 - Remote Code Execution via PHAR Deserialization
CVSS 9.8
TCPDF < 6.7.4 - Cross-Site Scripting via HTML Syntax Mishandling
CVSS 6.1
TCPDF < 6.7.6 - Local File Inclusion via Image Tag
CVSS 6.2
TCPDF < 6.7.4 - Cross-Site Scripting via HTML Syntax Mishandling
CVSS 6.1
TCPDF < 6.8.0 - Cross-Site Scripting via SVG font-family Attribute
CVSS 7.5
tc-lib-pdf-font <2.6.4 - Info Disclosure
CVSS 7.3
tc-lib-pdf-font <2.6.4 - Info Disclosure
CVSS 7.3
TCPDF < 6.8.0 - Improper Certificate Validation via libcurl
CVSS 9.8
TCPDF < 6.8.0 - Type Confusion via Loose Hash Comparison
CVSS 7.5
TCPDF < 6.8.0 - Cross-Site Scripting via Error Function
CVSS 7.5