Raxis Discovered Vulnerabilities

Raxis original discovered vulnerabilities that were identified during real engagement work, validated with the vendor, and assigned a CVE identifier through MITRE.

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines

Articles Categorized as Raxis Discovered Vulnerabilities

  • CVE-2026-36748: XSS in Rock RMS Leads to Privilege Escalation
  • Bypassing a WAF and a CSP with Google Tag Manager: An Attacker’s Perspective and Remediation Advice
  • CVE-2022-35739: PRTG Network Monitor Cascading Style Sheets (CSS) Injection
  • CVE-2022-26653 & CVE-2022-26777: ManageEngine Remote Access Plus Guest User Insecure Direct Object References
  • CVE-2022-25373: ManageEngine Support Center Plus Stored Cross-Site Scripting (XSS)
  • CVE-2022-25245: ManageEngine Asset Explorer Information Leakage