securekomodo

5 exploits Active since Oct 2022
CVE-2023-3519 NOMISEC CRITICAL SCANNER
Unspecified Product <Version> - RCE
Unauthenticated remote code execution
85 stars
CVSS 9.8
CVE-2025-22457 NOMISEC CRITICAL SCANNER
Ivanti Connect Secure Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
19 stars
CVSS 9.0
CVE-2024-22026 NOMISEC MEDIUM WORKING POC
EPMM <12.1.0.0 - Privilege Escalation
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.
15 stars
CVSS 6.7
CVE-2022-42889 NOMISEC CRITICAL WORKING POC
Apache Commons Text < 1.10.0 - Code Injection
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
8 stars
CVSS 9.8
CVE-2024-22734 NOMISEC MEDIUM WORKING POC
AMCS Group Trux Waste Mgmt <7.19.0018.26912 - Info Disclosure
An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive information via a static, hard-coded AES Key-IV pair in the TxUtilities.dll and TruxUser.cfg components.
2 stars
CVSS 6.2