Feb 08 - Feb 14, 2025OpenCTI + VulnCheck IntegrationCVE-2023-45498: Vinchin Backup RCECVE-2023-4220: Adds Chamilo File Upload RCE & Chamilo Unification
Feb 01 - Feb 07, 2025CVE-2023-30625: RudderStack rudder_server RCECVE-2024-46506: NetAlertX Unauthenticated RCECVE-2023-25826: OpenTSDB Metric Key Command Injection
Jan 25 - Jan 31, 2025CVE-2024-7097: WSO2 Account CreationCVE-2024-36117: Reposilite Directory TraversalCVE-2024-5082: Nexus Repository 2 RCE
Jan 18 - Jan 24, 2025CVE-2024-57727: SimpleHelp Path TraversalCVE-2025-0107: Palo Alto Networks Expedition Spark Callback RCECVE-2024-55591: FortiOS Websocket Auth Bypass
Jan 11 - Jan 17, 2025CVE-2025-0282: Ivanti Connect Secure IF-T Buffer OverflowCVE-2025-0520: ShowDoc Upload RCECVE-2022-24260 VoIP Monitor GUI SQLi
Dec 21 - Dec 27, 2024CVE-2024-50379: Apache Tomcat TOCTOU Webshell UploadCVE-2018-1160: Netatalk Commands Pointer Buffer Overflow RCECVE-2024-56145: Craft CMS `register_argc_argv` RCE
Dec 14 - Dec 20, 2024Feature UpdateCVE-2024-12856: Four-Faith adjust_sys_time Exploitation in the WildCVE-2023-3722: Avaya Aura Device Service Webshell Upload
Dec 7 - Dec 13, 2024CVE-2024-50623 Rapid ResponseCVE-2023-28879: Exploiting ownCloud through GhostscriptCVE-2024-47533: Cobbler XML-RPC Authentication Bypass
Nov 30 - Dec 6, 2024CVE-2024-41713: Mitel MiCollab File DisclosureCVE-2024-29510: Exploiting ownCloud through GhostscriptCVE-2024-10924: Really Simple Security WordPress Plugin Auth Bypass
Nov 23 - Nov 29, 2024CVE-2024-11680: ProjectSend Authentication Bypass and Webshell UploadCVE-2021-29442: Alibaba Nacos Remote Code ExecutionCVE-2020-8515 Draytek Vigor Remote Code Execution
Nov 18 - Nov 22, 2024CVE-2024-8069: Citrix Session Recording (Virtual Apps and Desktops) .NET DeserializationCVE-2024-0012 PAN-OS Authentication Bypass and CVE-2024-9474 Authenticated Command InjectionCVE-2024-10914: D-Link ShareCenter DNS Command Injection
Nov 9 - Nov 17, 2024STATUS UPDATE: CVE-2024-47575 Fortinet FortiManager fgfmd Missing AuthenticationCVE-2024-20017: Netgear WAX206IP-Intel Update
Nov 2 - Nov 8, 2024CVE-2022-3405: Acronis Cyber Protect and Backup RCECVE-2024-45216: Apache Solr Auth BypassCVE-2024-9014: pgAdmin OAuth2 Information Disclosure
Oct 26 - Nov 1, 2024CVE-2024-38816: Spring WebFlux - Halo CMS Directory Traversal VariantCVE-2024-51378 CybePanel Command InjectionCVE-2023-47207: Delta Electronics InfraSuite Device Master Deserialization
Oct 19 - Oct 25, 2024CVE-2024-9464 + CVE-2024-5910 Palo Alto Network Expedition Exploit ChainCVE-2024-28000: LiteSpeed Cache WordPress Plugin Admin Hash Bruteforce RCECVE-2024-44000: LiteSpeed Cache Debug Log Credential Leak to RCE
Oct 12 - Oct 18, 2024Feature UpdateABB ASPECT CVE-2023-0636 & CVE-2024-6209CVE-2024-2961 + CVE-2024-34102 Exploit Chain (Magento and glibc)
Oct 5 - Oct 11, 2024CVE-2019-12168: Four Faith Industrial RouterCVE-2024-9643: Four Faith Industrial Router (Zero day)CVE-2024-9644: Four Faith Industrial Router (Zero day)
Sept 28 - Oct 4, 2024CVE-2024-9441: Linear eMerge e-Series (Unpatched)CVE-2024-45519: Zimbra SMTP RCPT Injection RCECVE-2023-26469: Jorani Log Poisoning RCE
August 31 - September 6, 2024Traccar Exploit ChainClarification on D-Link "Won't Fix" CVE: CVE-2024-44340 - CVE-2024-44342 and CVE-2024-41622CVE-2024-5932: GiveWP Remote Code Execution
August 24 - August 30, 2024CVE-2024-28987 SolarWinds Web Help DeskCVE-2023-48022 and CVE-2023-6019 Anyscale Ray Remote Code ExecutionsCVE-2023-4911 GLIBC Tunables
August 17 - August 23, 2024CVE-2024-7954: SPIP porte_plume Plugin Arbitrary PHP ExecutionCVE-2024-5276: Fortra FileCatalyst Workflow SQL InjectionCVE-2020-12783: Exim Authentication Bypass
August 10 - August 16, 2024CVE-2024-7593: Ivanti vTM Authentication BypassCVE-2024-26331: ReCrystallize Server authentication bypass to RCECVE-2024-20419: Cisco Smart Software Manager On-Prem Account Takeover
August 3 - August 9, 2024CVE-2024-38077: "MadLicense" Windows RCECVE-2024-38856: Apache OFBiz improper authorization checks RCECVE-2024-4547 and CVE-2024-4548: Delta Electronics DIAEnergie SQLi -> Code Execution
July 27 - August 2, 2024CHANGELOG.md Added to Initial Access RepositoryREADME.md UpdatesCVE-2024-40348 Bazarr Secrets Leak