r0otk3r
16 exploits
Active since Oct 2021
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
Langflow AI - Unauthenticated Remote Code Execution
FiberHome GPON ONU HG6145F1 RP4423 - Info Disclosure
CVSS 9.8
CrushFTP - Authentication Bypass
CVSS 9.8
Ads Pro Plugin <= 4.89 - Unauthenticated Local File Inclusion
CVSS 8.1
Kubio AI Page Builder <2.5.1 - Local File Inclusion
CVSS 9.8
revpi_status < 2.4.6 - Unauthenticated Authentication Bypass via Incorrect Type Conversion
CVSS 9.8
pgAdmin < 8.12 - OAuth2 Credential Exposure
CVSS 9.9
SPIP porte_plume - Unauthenticated PHP Code Execution
CVSS 9.8
WP Automatic <3.92.0 - Path Traversal
CVSS 9.3
PHP CGI Argument Injection Remote Code Execution
CVSS 9.8
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
CVSS 10.0
LoadMaster 7.2.48.1-7.2.48.9 - Unauthenticated OS Command Injection
CVSS 10.0
D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L - OS Command Injection via group Parameter
CVSS 8.1
F5 BIG-IP iControl RCE via REST Authentication Bypass
CVSS 9.8
Apache 2.4.49/2.4.50 Traversal RCE
CVSS 9.8