xistence
77 exploits
Active since Jul 1997
FreePBX <2.9.0.14, <2.10.1.15, <2.11.0.23, <12.0.1alpha22 - RCE
ISC BIND - Denial of Service via DNS Query Traffic Amplification
Array Networks vAPV/vxAG <8.3.2.17-9.2.0.34 - Privilege Escalation
ProFTPD 1.3.5 - Unauthenticated Arbitrary File Read and Write via mod_copy Site Commands
Western Digital Arkeia <11.0.12 - Command Injection
SkyBlueCanvas CMS <1.1 r248-04 - RCE
ZeroShell <1.0beta11 - Command Injection
Joomla! 3.2-3.4.3 - SQL Injection
ClipBucket < 2.6 - Unauthenticated Arbitrary File Upload and Remote Code Execution via ofc_upload_image.php
CVSS 9.8
ManageEngine EventLog Analyzer < 10.6 - SQL Injection via event/runQuery.do Query Parameter
ZOHO ManageEngine OpManager <11.6 - Auth Bypass
Symantec Endpoint Protection Manager 11.0-11.0.7405.1424 and 12.1-12.1.4023.4080 - Authenticated SQL Injection
AlienVault OSSIM & USM <5.3.2 - XSS
CVSS 6.1
Pandora FMS <= 5.0RC1 - Unauthenticated Remote Command Execution via Anyterm p Parameter
OAstium VoIP PBX astium-confweb-2.1-25399 - Auth Bypass & RCE
Symantec Endpoint Protection Manager < 11.0.7405.1424 and 12.1 < 12.1.4023.4080 - XML External Entity Injection
ManageEngine Security Manager Plus 5.5 build 5505 - Remote SYSTEM SQL Injection (Metasploit)
ManageEngine EventLog Analyzer < 10.6 - SQL Injection via event/runQuery.do Query Parameter
FreePBX <2.9.0.14, <2.10.1.15, <2.11.0.23, <12.0.1alpha22 - RCE
Quantum vmPRO - Backdoor Command (Metasploit)
Quantum DXi V1000 2.2.1 - Static SSH Key
Loadbalancer.org Enterprise VA 7.5.2 - Static SSH Key
Western Digital Arkeia Appliance 10.0.10 - Multiple Vulnerabilities
Pandora Fms 5.0RC1 - Remote Command Injection
ManageEngine SupportCenter Plus < 7.9 - Path Traversal via WorkOrder.do Attach Parameter