August 15, 2023Ekushey Project Manager CRM 3.1 Insecure Settings

Ekushey Project Manager CRM version 3.1 appears to leave default credentials installed after installation.

August 15, 2023E-Journal Homoeo CMS 2.0.3 SQL Injection

E-Journal Homoeo CMS version 2.0.3 suffers from a remote SQL injection vulnerability.

August 15, 2023EI Tube YouTube API 3 SQL Injection

EI Tube YouTube API version 3 suffers from a remote SQL injection vulnerability.

August 15, 2023E-Fun CMS 5.0 XML Injection

E-Fun CMS version 5.0 suffers from an XML external entity injection vulnerability.

August 15, 2023WordPress Core 5.6.2 XPath Injection

WordPress Core version 5.6.2 appears to suffer from an xpath injection vulnerability via the log parameter.

August 15, 2023Education Time Indonesian School CRM 1.7 Directory Traversal

Education Time Indonesian School CRM version 1.7 suffers from a directory traversal vulnerability.

August 15, 2023doorGets CMS 7.0 Shell Upload

doorGets CMS version 7.0 suffers from a remote shell upload vulnerability.

August 15, 2023Datoo Complete Dating Script 1.0 Insecure Settings

Datoo Complete Dating Script version 1.0 suffers from an ignored default credential vulnerability.

August 15, 2023CSC-CMS 1.0.0 Insecure Settings

CSC-CMS version 1.0.0 suffers from an ignored default credential vulnerability.

August 14, 2023Advantech EKI-1524-CE / EKI-1522 / EKI-1521 Cross Site Scripting

Advantech EKI-1524-CE series, EKI-1522 series,and EKI-1521 series versions 1.21 and below and 1.24 and below suffer from cross site scripting vulnerabilities.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow