watchtowrlabs
41 exploits
Active since Jun 2022
PHP CGI Argument Injection Remote Code Execution
Juniper Networks Junos OS on EX Series <20.4R3-S9 - PHP External Variable Modification
Fortinet FortiWeb - SQL Injection
Fortinet FortiManager <7.6.0 - RCE
FortiProxy 7.0.0-7.0.19 and 7.2.0-7.2.12 - Authentication Bypass via Node.js Websocket Module
FortiProxy 7.0.0-7.0.19 and 7.2.0-7.2.12 - Authentication Bypass via Node.js Websocket Module
Veeam Backup & Replication 12.0.0.1420 through 12.2.0.334 - Deserialization RCE
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
QNAP QTS and QuTS hero - Remote Code Execution via Stack-based Buffer Overflow
Ivanti Connect Secure <22.7R2.5 - RCE
CrushFTP 10.0.0-10.8.4 and 11.0.0-11.3.3 - Unauthenticated Remote Admin Access via AS2 Validation Bypass
Cleo Harmony, VLTrader, and LexiCom < 5.8.0.21 - Unrestricted File Upload and Remote Code Execution
Palo Alto Networks PAN-OS 10.2 11.0 11.1 11.2 - Unauthenticated Authentication Bypass
Commvault Command Center Innovation Release <11.38.20 - Path Traversal
Mitel MiCollab < 9.8.1.201 - Unauthenticated Path Traversal in NuPoint Unified Messaging
Fortinet FortiSIEM - OS Command Injection
SmarterMail < 100.0.9413 - Unauthenticated Arbitrary File Upload and Remote Code Execution
Rejected
12 stars
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem <= 23.3.40 - XML External Entity
WatchGuard Fireware OS <12.11.3 - RCE
Ivanti Endpoint Manager Mobile <= 12.5.0.0 - Unauthenticated Authentication Bypass via API
FreePBX 15.0-15.0.65 - Unauthenticated Authentication Bypass and Remote Code Execution