nu11secur1ty
118 exploits
Active since Dec 2015
Log4Shell HTTP Header Injection
Linux Kernel 2.x-4.x < 4.8.3 - Local Privilege Escalation via Dirty COW Race Condition
CVSS 7.0
Linux Kernel 2.x-4.x < 4.8.3 - Local Privilege Escalation via Dirty COW Race Condition
CVSS 7.0
Ubuntu Enlightenment Mount Priv Esc
CVSS 7.8
Windows Shell Spoofing Vulnerability
CVSS 4.3
net: skbuff: propagate shared-frag marker through frag-transfer helpers
CVSS 7.8
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
CVSS 7.8
xfrm: esp: avoid in-place decrypt on shared skb frags
CVSS 8.8
xfrm: esp: avoid in-place decrypt on shared skb frags
CVSS 8.8
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
CVSS 7.8
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
solaredge - (CSRF-OOB-Injection)
Windows Snipping Tool Spoofing Vulnerability
CVSS 4.3
Windows 10/11, Server 2016/2019/2022 Hyper-V Authenticated Heap-based Buffer Overflow
CVSS 7.3
Windows 10/11, Server 2016/2019/2022 Hyper-V Authenticated Heap-based Buffer Overflow
CVSS 7.3
Windows 10/11, Server 2016 - Privilege Escalation via Heap Overflow
CVSS 7.8
is-localhost-ip 2.0.0 - SSRF
Google Chrome <145.0.7632.75 - Use After Free
CVSS 8.8
Fortinet FortiWeb unauthenticated RCE
CVSS 9.8
Sourcecodester Online Payment Hub - SQL Injection
CVSS 9.8
Microsoft OneNote - Authentication Bypass by Spoofing
CVSS 6.5
Zippy CRM 6.5.4 - Reflected Cross-Site Scripting via Unvalidated Input Parameters
CVSS 6.1
Kimai 1.30.10 - Sensitive Cookie with Improper SameSite Attribute
CVSS 9.8
Ever Gauzy 0.281.9 - JWT Authentication Bypass via Weak HMAC Secret
CVSS 9.8
Spip 4.1.10 - Stored Cross-Site Scripting via Malicious SVG Upload
CVSS 8.8