Security Research and Discovered CVEs
Real Engagements, Real CVEs. Real skill leaves evidence.
Discovered CVEs
| CVE / NVD | Product Details | Description (Raxis Pentester) |
|---|---|---|
| CVE-2026-36748 - NVD | Rock RMS XSS → privilege escalation to admin | Stored XSS in Rock RMS that lets a standard user escalate to administrator when an admin views the malicious user’s profile page (Jason Taylor) |
| CVE-2022-35739 - NVD | PRTG Network Monitor CSS injection | CSS injection in PRTG Network Monitor via a device’s icon/properties field rendered unescaped inside a style tag (Matt Mathur) |
| CVE-2022-26777 - NVD | ManageEngine Remote Access Plus, Guest IDOR (license details) | IDOR in ManageEngine Remote Access Plus, a Guest user can retrieve license details via the /dcapi/ endpoint (Matt Dunn) |
| CVE-2022-26653 - NVD | ManageEngine Remote Access Plus, Guest IDOR (domain details) | IDOR in ManageEngine Remote Access Plus, a Guest user can retrieve connected domain/controller details (Matt Dunn) |
| CVE-2022-25373 - NVD | ManageEngine Support Center Plus stored XSS | Stored XSS in ManageEngine Support Center Plus (Matt Dunn) |
| CVE-2022-25245 - NVD | ManageEngine Asset Explorer information leakage | Information leakage in ManageEngine Asset Explorer (Matt Dunn) |
| CVE-2022-24681 - NVD | ManageEngine ADSelfService Plus stored XSS (auth screens) | Stored XSS in ManageEngine AD Self Service Plus (Matt Dunn) |
| CVE-2021-38156 - NVD | Nagios XI stored XSS (dashboard edit) | Stored XSS in Nagios XI (Matt Dunn) |
| CVE-2021-31813 - NVD | ManageEngine Applications Manager stored XSS (AD-imported names) | Stored XSS in ManageEngine Applications Manager, via name fields imported from Active Directory (Matt Dunn) |
| CVE-2021-29643 - NVD | PRTG Network Monitor stored XSS | Stored XSS in PRTG Network Monitor (Matt Dunn) |
| CVE-2021-28382 - NVD | ManageEngine Key Manager Plus stored XSS (AD-imported fields) | Stored XSS in ManageEngine Key Manager Plus, via user detail fields imported from Active Directory (Matt Dunn) |
| CVE-2021-27956 - NVD | ManageEngine ADSelfService Plus stored XSS (directory-search email field) | Stored XSS in ManageEngine AD Self Service Plus, in the email field of directory search results (Matt Dunn) |