rxerium
40 exploits
Active since Oct 2023
FreePBX endpoint SQLi to RCE
47 stars
n8n Workflow Expression Remote Code Execution
Gogs < 0.13.3 - Local Code Execution via PutContents API Symbolic Link Handling
N-able N-central < 2025.3.1 - Local Code Execution via Untrusted Data Deserialization
Fortra GoAnywhere MFT < 7.6.3 - Deserialization of Untrusted Data via License Servlet
SmarterMail < 100.0.9413 - Unauthenticated Arbitrary File Upload and Remote Code Execution
Roundcube Webmail < 1.5.12 and 1.6 < 1.6.12 - Cross-Site Scripting via SVG Animate Tag
OpenSSH 6.9-9.7 - Machine-in-the-Middle Attack via VerifyHostKeyDNS Error Handling
LiteSpeed Cache < 5.7 - Unauthenticated Stored Cross-Site Scripting
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
Sitecore XM/X <9.0 - Code Injection
SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
OpenSSH - Denial of Service via Ping Packet Memory Exhaustion
Trimble Cityworks < 15.8.9 - Authenticated Remote Code Execution via Deserialization
SonicWall SMA6200/SMA6210/SMA7200/SMA7210/SMA8200v < 12.4.3-03245 Local Privilege Escalation
Exim < 4.97.1 - Improper Encoding or Escaping of Output via Multiline RFC 2231 Header Filename
Citrix NetScaler ADC and Gateway 12.1-13.1 - Remote Code Execution and Denial of Service via Memory Overflow
SolarWinds Web Help Desk < 12.8.6 - Unauthenticated Remote Code Execution via AjaxProxy Deserialization
HPE OneView unauthenticated RCE
Wazuh server remote code execution caused by an unsafe deserialization vulnerability.
FreePBX endpoint SQLi to RCE
1 stars
FreePBX <16.0.92-17.0.6 - Authenticated File Upload
1 stars
FreePBX 15.0-15.0.65 - Unauthenticated Authentication Bypass and Remote Code Execution
VMware Aria Operations and VMware Tools - Local Privilege Escalation via SDMP
InspiryThemes RealHomes <4.3.6 - Privilege Escalation