July 31, 2023Zomplog 3.9 Cross Site Scripting

Zomplog version 3.9 suffers from a persistent cross site scripting vulnerability.

July 31, 2023Zomplog 3.9 Remote Code Execution

Zomplog version 3.9 suffers from a remote code execution vulnerability.

July 31, 2023DBD E-Commerce 2.0.6 SQL Injection

DBD E-Commerce version 2.0.6 suffers from a remote SQL injection vulnerability.

July 31, 2023RosarioSIS 10.8.4 CSV Injection

RosarioSIS version 10.8.4 suffers from a CSV injection vulnerability.

July 31, 2023AMSS++ 5.16 SQL Injection

AMSS++ version 5.16 suffers from a remote SQL injection vulnerability.

July 28, 2023Western Digital MyCloud Unauthenticated Command Injection

This Metasploit module exploits authentication bypass (CVE-2018-17153) and command injection (CVE-2016-10108) vulnerabilities in Western Digital MyCloud before 2.30.196 in order to achieve unauthenticated remote code execution as the root user. The module

July 28, 2023Joomla Solidres 2.13.3 Cross Site Scripting

Joomla Solidres extension version 2.13.3 suffers from a cross site scripting vulnerability.

July 27, 2023XLAgenda 4.4 Cross Site Request Forgery

XLAgenda version 4.4 suffers from a cross site request forgery vulnerability.

July 27, 2023WonderCMS 0.6-Beta Password Disclosure

WonderCMS version 0.6-Beta suffers from a password disclosure vulnerability.

July 27, 2023xForUp Simple File Uploader 1.0 SQL Injection

xForUp Simple File Uploader version 1.0 suffers from a remote SQL injection vulnerability.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow