wvu
151 exploits
Active since Apr 2014
WordPress Plugin InfiniteWP - Client Authentication Bypass (Metasploit)
Blueimp jQuery-File-Upload <=9.22.0 - File Upload
CVSS 9.8
PHPMailer Sendmail Argument Injection
CVSS 9.8
Drupal 7.0.0-7.61.0 8.5.0-8.5.10 8.6.0-8.6.9 - Remote Code Execution via Unsanitized Field Data
CVSS 8.1
Apple OS X Rootpipe Privilege Escalation
CVSS 7.8
Pulse Secure <9.0R3.4-5.1R15.1 - Authenticated Command Injection
CVSS 7.2
ManageEngine Desktop Central < 10.0.479 - Remote Code Execution via Java Deserialization in FileStorage
CVSS 9.8
Apache Struts 2 Namespace Redirect OGNL Injection
CVSS 8.1
ImageMagick <6.9.3-10 & <7.0.1-1 - RCE
CVSS 8.4
HP VAN SDN Controller - Root Command Injection (Metasploit)
ThinkPHP < 3.2.4 - Remote Code Execution via Public Endpoint
CVSS 8.8
OpenSMTPD 6.6 - Remote Code Execution via MAIL FROM Field
CVSS 9.8
Nexus Repository Manager Java EL Injection RCE
CVSS 8.8
Nagios XI Chained - Remote Code Execution (Metasploit)
Axis IP Cameras - Exposed Insecure Interface
CVSS 9.8
OpenSMTPD OOB Read Local Privilege Escalation
CVSS 9.8
Apache Continuum - Arbitrary Command Execution (Metasploit)
Exim <4.86.2 - Privilege Escalation
CVSS 7.0
Artifex Ghostscript <9.24 - Privilege Escalation
CVSS 7.8
Apache Jetspeed Arbitrary File Upload
CVSS 8.8
Oracle Application Testing Suite - Info Disclosure
Liferay Portal <7.2.1 CE GA2 - Code Injection
CVSS 9.8
Pipeline: Declarative Plugin <1.3.3 - RCE
CVSS 8.8
Netgear - 'TelnetEnable' Magic Packet (Metasploit)
Morris Worm - fingerd Stack Buffer Overflow (Metasploit)