August 31, 2023InterPhoto 2.3.0 Shell Upload

InterPhoto version 2.3.0 suffers from a remote shell upload vulnerability.

August 30, 2023IQ-Medya CMS 2.0 Cross Site Scripting

IQ-Medya CMS version 2.0 suffers from a cross site scripting vulnerability.

August 30, 2023Apache NiFi H2 Connection String Remote Code Execution

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. This exploit will resul

August 29, 2023Grawlix 1.5.1 Cross Site Scripting

Grawlix version 1.5.1 suffers from a cross site scripting vulnerability.

August 29, 2023GOM Player 2.3.90.5360 MITM / Remote Code Execution

GOM Player version 2.3.90.5360 man-in-the-middle proof of concept remote code execution exploit.

August 29, 2023ImgHosting 1.2 Cross Site Scripting

ImgHosting version 1.2 suffers from a cross site scripting vulnerability.

August 29, 2023imax CMS 1.0 SQL Injection

imax CMS version 1.0 suffers from a remote SQL injection vulnerability.

August 29, 2023i-Gallery 3.4 Database Disclosure

i-Gallery version 3.4 suffers from a database disclosure vulnerability.

August 29, 2023iBilling CRM 4.5.0 Add Administrator / Insecure Direct Object Reference

iBilling CRM version 4.5.0 suffers from add administrator and insecure direct object reference vulnerabilities.

August 29, 2023Humhub 1.3.13 Directory Traversal

Humhub version 1.3.13 suffers from a directory traversal vulnerability.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow