RESEARCH / EXPLOIT DEVELOPMENT

Exploits

51 research entries include a concrete exploit implementation developed as part of the research work. Payloads, manual reproduction steps, inline validation commands and third-party exploit references alone do not qualify for this category.

51 entriesFilter locally — no external search service
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2026-41679 — Paperclip Unauthenticated Remote Code Execution

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in authenticated mode with default configuration.

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2024-24578 — RaspberryMatic Unauthenticated Remote Code Execution

RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, caused by multiple issues within the Java based HMIPServer.jar component.

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2024-11320 — Pandora FMS LDAP Command Injection

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2022-3405 — Acronis Cyber Protect Agent Code Execution

Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2024-2054 — Artica Proxy PHP Object Injection

The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2023-50445 — GL.iNet Shell Injection

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local attackers to execute arbitrary code via the getsystemlog and…

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2023-30013 — TOTOLINK X5000R Command Injection

TOTOLINK X5000R V9.1.0u.6118B20201102 and V9.1.0u.6369B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2014-6271 — GNU Bash Shellshock Command Injection

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the modcgi and…

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2023-28770 — Zyxel DX5401-B0 Sensitive Information Exposure

The sensitive information exposure vulnerability in the CGI “ExportLog” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2021-39144 — XStream Deserialization Remote Code Execution

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream.

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2022-37061 — FLIR AX8 Remote Command Injection

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint.

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2017-7921 — Hikvision Camera Authentication Bypass

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721…

Read research →
TECHNICAL ANALYSISEXPLOIT DEVELOPMENT

CVE-2022-33891 — Apache Spark Shell Command Injection

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application.

Read research →