rvzsec
16 exploits
Active since Aug 2019
Vm2 < 3.9.16 - Injection
angular-base64-upload <v0.1.21 - RCE
ZoneMinder < 1.36.33 - Unauthenticated Remote Code Execution via Snapshot Action
dompdf < 1.2.1 - Remote Code Execution via CSS @font-face src:url
Local Privilege Escalation in polkits pkexec
GNU C Library <2.39 - Buffer Overflow
ISPConfig language_edit.php PHP Code Injection
Below < 0.9.0 - Privilege Escalation via World-Writable Log Directory
Ghost < 5.59.1 - Authenticated Arbitrary File Read via Symlink Upload
request-baskets < 1.2.1 - Server-Side Request Forgery via /api/baskets/{name} Endpoint
crypto: algif_aead - Revert to operating out-of-place
Grafana 11.0.0-11.0.5 - Authenticated Command Injection via DuckDB SQL Expressions
zedna_ebook_download < 1.2 - Path Traversal
React Server Components <19.2.0 - RCE
CVSS 10.0
Rejected
TP-Link Archer A20 v3 1.0.6 Build 20231011 rel.85717(5553) - Cross-Site Scripting via Directory Listing Path
CVSS 4.8