June 12, 2023Anevia Flamingo XL/XS 3.6.x Default / Hardcoded Credentials

Anevia Flamingo XL/XS versions 3.6.20 and 3.2.9 have a weak set of default and hardcoded administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

June 12, 2023OmniCart 3.4.0 Cross Site Scripting

OmniCart version 3.4.0 suffers from a cross site scripting vulnerability.

June 12, 2023LearnDesk 1.0 Cross Site Scripting

LearnDesk version 1.0 suffers from a cross site scripting vulnerability.

June 12, 2023BB Machine Forum 1.0 Cross Site Scripting

BB Machine Forum version 1.0 suffers from a cross site scripting vulnerability.

June 12, 2023Expert X Jobs Portal And Resume Builder 1.0 Cross Site Scripting

Expert X Jobs Portal And Resume Builder version 1.0 suffers from a cross site scripting vulnerability.

June 12, 2023PhotoSwipe 5.3.7 Arbitrary File Download

PhotoSwipe version 5.3.7 suffers from an arbitrary file download vulnerability.

June 12, 2023PES Pro CMS 1.9.7 Add Administrator

PES Pro CMS version 1.9.7 suffers from an add administrator vulnerability.

June 12, 2023KesionCMS X 9.5 Add Administrator

KesionCMS X version 9.5 suffers from an unauthenticated add administrator vulnerability.

June 12, 2023Pannres-Idence CMS 7.3 Cross Site Request Forgery

Pannres-Idence CMS version 7.3 suffers from a cross site request forgery vulnerability.

June 12, 2023Ormesson-Immobilier CMS 8 SQL Injection

Ormesson-Immobilier CMS version 8 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Archives
Categories
  • All Exploits 4131
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow