tucommenceapousser
20 exploits
Active since Oct 2019
WordPress Royal Elementor Addons RCE
Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) - Command Injection
CrushFTP < 10.7.1 - Unauthenticated Server-Side Template Injection
SysAid < 23.3.36 - Path Traversal and Remote Code Execution via Tomcat Webroot File Write
Parks Fiberlink 210 <V2.1.14_X000 - Command Injection
WhatsApp < 2.19.244 - Remote Code Execution via GIF Image Parsing
FreeSWITCH <1.10.1 - Info Disclosure
WhatsApp < 2.19.244 - Remote Code Execution via GIF Image Parsing
SysAid < 23.3.36 - Path Traversal and Remote Code Execution via Tomcat Webroot File Write
CVSS 9.8
EverPress Mailster <4.0.6 - Path Traversal
CVSS 8.1
cPanel < 11.102.0.31 - Cross-Site Scripting via Invalid Webcall ID
CVSS 5.3
cPanel < 11.102.0.31 - Cross-Site Scripting via Invalid Webcall ID
CVSS 5.3
Group-Office 6.6.145 - Reflected Cross-Site Scripting via GO_LANGUAGE Cookie
CVSS 6.1
Chamilo unauthenticated command injection in PowerPoint upload
CVSS 9.8
STAGIL Navigation for Jira <2.0.52 - Path Traversal
CVSS 7.5
raspap 2.8.0-2.8.7 - Unauthenticated Command Injection via cfg_id Parameter
CVSS 9.8
Elementor Website Builder <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting
CVSS 4.7
Elementor Website Builder <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting
CVSS 4.7
Telesquare SDT-CW3B1 1.1.0 - Command Injection
CVSS 9.8
FreeSWITCH <1.10.1 - Info Disclosure
CVSS 9.8