watchtowrlabs
41 exploits
Active since Jun 2022
Apache HTTP Server 2.4.0-2.4.53 - HTTP Request Smuggling via mod_proxy_ajp
SolarWinds Web Help Desk < 2026.1 - Unauthenticated Remote Code Execution via Untrusted Data Deserialization
NAKIVO Backup & Replication < 11.0.0.88174 - Absolute Path Traversal via getImageByPath
Ivanti Sentry - Authentication Bypass Using an Alternate Path or Channel
Dell Unity Operating Environment < 5.5.1.0 - Unauthenticated OS Command Injection
OpenAM <14.6.6 - Privilege Escalation
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
Check Point Quantum/Spark Gateways - Unauthenticated VPN Authentication Bypass
BMC FootPrints ITSM 20.20.02-20.24.01.001 - VIEWSTATE Deserialization Code Execution
Ivanti Sentry - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 10.0
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
CVSS 9.8
GNU inetutils through 2.7 - Buffer Overflow
CVSS 9.8
Juniper Junos OS Evolved 25.4-25.4R1-S1-EVO, 25.4R2-EVO - Remote Code Execution via Anomaly Detection
CVSS 9.8
SolarWinds Web Help Desk < 2026.1 - Authentication Bypass
CVSS 9.8
CrushFTP 10.0.0-10.8.4 and 11.0.0-11.3.3 - Unauthenticated Remote Admin Access via AS2 Validation Bypass
CVSS 9.0