rastating
13 exploits
Active since Nov 2014
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass via X-Forwarded-For Header
WordPress < 4.9.2 - Unauthenticated Denial of Service via Repeated JavaScript File Loading
CVSS 7.5
Drupal 7.x < 7.34 and Secure Password Hashes 6.x-2.x < 6.x-2.1 - Denial of Service via Password Hashing API
WordPress Long Password DoS
WPLMS <1.8.4.1 - Privilege Escalation
CVSS 8.8
WP EasyCart 1.1.30-3.0.20 - Unauthenticated Privilege Escalation and RCE via option_name/option_value
CVSS 8.8
Holding Pattern < 0.6 - Unauthenticated Arbitrary File Upload via admin/upload-file.php
Maarch GEC/GED < 1.4 and LetterBox < 2.8 - Unauthenticated Arbitrary File Upload via file_to_index.php
WP Symposium 14.11 - Unauthenticated Arbitrary File Upload via UploadHandler.php
WP EasyCart < 3.0.8 - Authenticated Arbitrary File Upload via Banner Upload Script
Photo Gallery 1.2.5 - Info Disclosure
CVSS 8.8
Ninja Forms <2.9.42.1 - Code Injection
CVSS 9.8
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass via X-Forwarded-For Header
CVSS 9.8