rootxsushant

2 exploits Active since Oct 2023
CVE-2023-5561 NOMISEC MEDIUM WORKING POC
WordPress 4.7-4.7.26 - Unauthenticated Email Address Disclosure via REST API Oracle Attack
WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack
2 stars
CVSS 5.3
CVE-2025-5777 NOMISEC HIGH WORKING POC
Citrix NetScaler ADC/Gateway 12.1-12.1-55.328, 13.1-13.1-37.235, 13.1-13.1-58.32 - Out-of-bounds Read
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVSS 7.5