November 13, 2023Travel 1.0 SQL Injection

Travel version 1.0 suffers from a remote SQL injection vulnerability.

November 13, 2023Elementor Website Builder SQL Injection

Elementor Website Builder versions prior to 3.12.2 suffer from a remote SQL injection vulnerability.

November 13, 2023EnBw SENEC Legacy Storage Box Default Credentials

EnBw SENEC Legacy Storage Box versions 1 through 3 suffered from a default credential issue.

November 13, 2023Maxima Max Pro Power 1.0 486A BLE Traffic Replay

Maxima Max Pro Power with firmware version 1.0 486A suffers from a BLE traffic replay vulnerability that allows for arbitrary unauthorized actions.

November 13, 2023WordPress Contact Form To Any API 1.1.2 SQL Injection

WordPress Contact Form to Any API plugin version 1.1.2 suffers from a remote SQL injection vulnerability.

November 13, 2023Penglead 2.0 SQL Injection

Penglead version 2.0 suffers from a remote SQL Injection vulnerability that allows for authentication bypass.

November 13, 2023LOYTEC Electronics Insecure Transit / Insecure Permissions / Unauthenticated Access

Products from LOYTEC electronics such as Loytec LWEB-802, L-INX Automation Servers, L-IOB I/O Controllers, and L-VIS Touch Panels suffer from improper access control and insecure transit vulnerabilities.

October 27, 2023Splunk edit_user Capability Privilege Escalation

Splunk suffers from an issue where a low-privileged user who holds a role that has the edit_user capability assigned to it can escalate their privileges to that of the admin user by providing a specially crafted web request. This is because the edit_user

October 27, 2023phpFox 4.8.13 PHP Object Injection

phpFox versions 4.8.13 and below have an issue where user input passed through the "url" request parameter to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote

October 27, 2023SugarCRM 13.0.1 Shell Upload

SugarCRM versions 13.0.1 and below suffer from a remote shell upload vulnerability in the set_note_attachment SOAP call.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow