July 13, 2023Bayfront CMS 1.0 SQL Injection

Bayfront CMS version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

July 13, 2023ARTISTRY LIMITED LMS 0.5 SQL Injection

ARTISTRY LIMITED LMS version 0.5 suffers from a remote SQL injection vulnerability.

July 13, 2023Vaidya-Mitra 1.0 SQL Injection

Vaidya-Mitra version 1.0 suffers from a remote SQL injection vulnerability.

July 12, 2023WordPress User Registration 3.0.2 Arbitrary File Upload

The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hard-coded encryption key and missing file type validation on the ur_upload_profile_pic function in versions up to, and including, 3.0.2. This makes it possible fo

July 12, 2023Frappe Framework 13.4.0 Remote Code Execution

Frappe Framework (ERPNext) version 13.4.0 suffers from a remote code execution vulnerability.

July 12, 2023Spring Cloud 3.2.2 Remote Command Execution

Spring Cloud version 3.2.2 suffers from a remote command execution vulnerability.

July 12, 2023Banner RotatorCMS 1.0 Database Disclosure

Banner RotatorCMS version 1.0 suffers from a database disclosure vulnerability.

July 12, 2023Avidi Media 2.0 Insecure Settings

Avidi Media version 2.0 appears to leave default credentials installed after installation.

July 12, 2023AtTestimonials CMS 1.2 Missing Authentication

AtTestimonials CMS version 1.2 suffers from a missing authentication vulnerability.

July 12, 2023Atom CMS 2.0 Directory Traversal

Atom CMS version 2.0 suffers from a directory traversal vulnerability.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow