wvu
151 exploits
Active since Apr 2014
VMware vRealize Operations Manager < 8.4 - Server-Side Request Forgery via API
CVSS 7.5
Webmin <= 1.920 - OS Command Injection via password_change.cgi Old Parameter
CVSS 9.8
VMware Cloud Foundation 3.0-4.0 and vCenter Server - Arbitrary File Upload via Analytics Service
CVSS 9.8
Lucee Server <5.3.7.47-5.3.6.68-5.3.5.96 - RCE
CVSS 8.6
VMware vCenter Server - Remote Code Execution via Virtual SAN Health Check Plugin
CVSS 9.8
VMware View Planner 4.0-4.5 - Unauthenticated Remote Code Execution via Logupload Arbitrary File Upload
CVSS 9.8
Cisco UCS Director - Auth Bypass/Path Traversal
CVSS 9.8
Cisco HyperFlex HX Data Platform unauthenticated file upload to RCE (CVE-2021-1499)
CVSS 5.3
Nexus Repository Manager Java EL Injection RCE
CVSS 8.8
MobileIron MDM Hessian-Based Java Deserialization RCE
CVSS 9.8
Apache OFBiz SOAP Java Deserialization
CVSS 9.8
F5 iControl REST Unauthenticated SSRF Token Generation RCE
CVSS 9.8
Eir D1000 Modem Firmware - Remote Code Execution via TR-064 Protocol
CVSS 9.8
Cisco HyperFlex HX Data Platform < 4.0(2e) - Unauthenticated OS Command Injection
CVSS 9.8
Axis IP Cameras - OS Command Injection
CVSS 9.8
Pulse Secure <9.0R3.4-5.1R15.1 - Authenticated Command Injection
CVSS 7.2
Apple OS X Rootpipe Privilege Escalation
CVSS 7.8
MyLittleAdmin 3.8 - Unauthenticated Remote Code Execution via Hardcoded MachineKey
CVSS 9.8
Microsoft Windows SMBv1 - Remote Code Execution via Crafted Packets
CVSS 8.1
Morris Worm - sendmail Debug Mode Shell Escape (Metasploit)
Morris Worm - sendmail Debug Mode Shell Escape (Metasploit)
Emacs - movemail Privilege Escalation (Metasploit)
Emacs - movemail Privilege Escalation (Metasploit)
Oracle Solaris 10-11 - Privilege Escalation
CVSS 10.0
macOS X - Remote Command Execution via HTTP Redirect Pipe Character