nikolas-ch

2 exploits Active since Sep 2025
CVE-2025-56267 WRITEUP CRITICAL WRITEUP
Avigilon ACM <7.10.0.20 - Code Injection
A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.
CVSS 9.8
CVE-2025-56265 WRITEUP HIGH WRITEUP
n8n 1.95.3 1.100.1 1.101.1 - Arbitrary File Upload and Remote Code Execution via Chat Trigger Component
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.
CVSS 8.8