July 20, 2023CMS Made Simple 2.2.17 Server-Side Template Injection

CMS Made Simple version 2.2.17 suffers from session hijacking due to a server-side template injection vulnerability.

July 20, 2023CMS Made Simple 2.2.17 Cross Site Scripting

CMS Made Simple version 2.2.17 suffers from a persistent cross site scripting vulnerability.

July 20, 2023CMS Made Simple 2.2.17 Remote Code Execution

CMS Made Simple version 2.2.17 suffers from a remote code execution vulnerability.

July 20, 2023statamic 4.7.0 Cross Site Scripting

statamic version 4.7.0 suffers from a cross site scripting vulnerability via a malicious file upload.

July 20, 2023phpFM 1.7.9 Authentication Bypass / Shell Upload

phpFM version 1.7.9 suffers from authentication bypass and remote shell upload vulnerabilities.

July 20, 2023Blackcat CMS 1.4 Cross Site Scripting

Blackcat CMS version 1.4 suffers from a persistent cross site scripting vulnerability.

July 20, 2023ABB FlowX 4.00 Information Disclosure

ABB FlowX version 4.00 suffers from a sensitive information exposure vulnerability.

July 19, 2023Ciuis CRM 1.0.7 Add Administrator

Ciuis CRM version 1.0.7 suffers from an add administrator vulnerability.

July 19, 2023RWS WorldServer 11.7.3 Session Token Enumeration

RWS WorldServer versions 11.7.3 and below suffer from a session token enumeration vulnerability.

July 19, 2023Openfire Authentication Bypass / Remote Code Execution

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user t

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow