September 19, 2023WordPress Essential Blocks 4.2.0 / Essential Blocks Pro 1.1.0 PHP Object Injection

WordPress Essential Blocks plugin versions 4.2.0 and below and Essential Blocks Pro versions 1.1.0 and below suffer from multiple PHP object injection vulnerabilities.

September 19, 2023Taskhub 2.8.7 SQL Injection

Taskhub version 2.8.7 suffers from a remote SQL injection vulnerability.

September 19, 2023Super Store Finder 3.7 Remote Command Execution

Super Store Finder versions 3.7 and below suffer from a remote command execution vulnerability.

September 19, 2023Lamano CMS 2.0 SQL Injection

Lamano CMS version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

September 19, 2023Lacabane 1.0 SQL Injection

Lacabane version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

September 19, 2023Free And Open Source Inventory Management System 1.0 SQL Injection

Free and Open Source Inventory Management System version 1.0 suffers from a remote SQL injection vulnerability.

September 18, 2023Atos Unify OpenScape Code Execution / Missing Authentication

Atos Unify OpenScape Session Border Controller, Atos Unify OpenScape Branch, and Atos Unify OpenScape BCF suffer from remote code execution and missing authentication vulnerabilities. Atos OpenScape SBC versions before 10 R3.3.0, Branch version 10 version

September 18, 2023PTC - Codebeamer Cross Site Scripting

PTC - Codebeamer versions 22.10-SP7 and below, 22.04-SP5 and below, and 21.09-SP13 and below suffer from a cross site scripting vulnerability.

September 18, 2023Ivanti Avalanche MDM Buffer Overflow

This Metasploit module exploits a buffer overflow condition in Ivanti Avalanche MDM versions prior to 6.4.1. An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in arbitrary code execution with the NT/AUT

September 18, 2023Razer Synapse Race Condition / DLL Hijacking

Razer Synapse versions before 3.8.0428.042117 (20230601) suffer from multiple vulnerabilities. Due to an unsafe installation path, improper privilege management, and a time-of-check time-of-use race condition, the associated system service "Razer Synapse

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow