r4p3c4
64 exploits
Active since Feb 2024
Windows File Explorer - Exposure of Sensitive Information to an Unauthorized Actor
iPadOS < 17.7.6 - Arbitrary File System Modification
Cacti Graph Template authenticated RCE versions prior to 1.2.29
XWiki Platform - Remote Code Execution
mailcow: dockerized <2025-01a - Info Disclosure
axios < 1.8.2 - Server-Side Request Forgery via Absolute URL Handling
Below < 0.9.0 - Privilege Escalation via World-Writable Log Directory
Apache Camel <4.10.2 - Command Injection
CrushFTP - Authentication Bypass
macOS < 15.5 - Sandbox Escape via Vulnerable Code Removal
Erlang OTP Pre-Auth RCE Scanner and Exploit
PyTorch < 2.6.0 - Remote Code Execution via torch.load with weights_only=True
Sudo <1.9.17p1 - Privilege Escalation
Langflow AI - Unauthenticated Remote Code Execution
Linux Kernel - Time-of-check Time-of-use Race Condition in POSIX CPU Timers
PNETLab 4.2.10 - Path Traversal via HTTP Request File Path Manipulation
2 stars
Python <3.14 - Path Traversal
StoreKeeper <14.4.4 - Unrestricted Upload
Android - Use-After-Free in Chrome Sandbox Escape
DataEase < 2.10.10 - Authentication Bypass via Case Insensitivity
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
Notepad++ <8.8.1 - Privilege Escalation
Redis < 6.2.20, 8.2.1-8.2.2 - Authenticated Use-After-Free via Lua Script Garbage Collector Manipulation
Ollama 0.6.7 - Cross-Domain Token Exposure via WWW-Authenticate Header Realm
JGM Pandoc 3.6.4 - Server-Side Request Forgery via Crafted iframe