July 20, 2023CMS porViaX 2.0 SQL Injection

CMS porViaX version 2.0 suffers from a remote SQL injection vulnerability.

July 20, 2023TP-Link TL-WR740N Directory Traversal

TP-Link TL-WR740N suffers from a directory traversal vulnerability.

July 20, 2023Pluck 4.7.18 Remote Shell Upload

Pluck version 4.7.18 appears to suffer from a remote shell upload vulnerability.

July 20, 2023Blackcat CMS 1.4 Shell Upload

Blackcat CMS version 1.4 suffers from a remote shell upload vulnerability.

July 20, 2023Backdrop CMS 1.25.1 Cross Site Scripting

Backdrop CMS version 1.25.1 suffers from a persistent cross site scripting vulnerability.

July 20, 2023Joomla! Booking 2.4.9 Account Enumeration

Joomla! Booking component version 2.4.9 suffers from an information leakage vulnerability that allows for account enumeration.

July 20, 2023CMS EngePlus 2.0.1 Cross Site Scripting

CMS EngePlus version 2.0.1 suffers from a cross site scripting vulnerability.

July 20, 2023PimpMyLog 1.7.14 Improper Access Control

PimpMyLog version 1.7.14 allows an unprivileged user to create an administrative account. In addition, the username is not sanitized and can be leveraged to perform cross site scripting attacks.

July 20, 2023CMS D-Creations 1.0 SQL Injection

CMS D-Creations version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

July 20, 2023CCOM Events CMS 0.1.02 Arbitrary File Upload

CCOM Events CMS version 0.1.02 suffers from an arbitrary file upload vulnerability.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow