August 29, 2024WordPress GiveWP Donation / Fundraising Platform 3.14.1 Code Execution

The GiveWP Donation plugin and Fundraising Platform plugin for WordPress in all versions up to and including 3.14.1 is vulnerable to a PHP object injection (POI) flaw granting an unauthenticated attacker arbitrary code execution.

August 29, 2024vTiger CRM 7.4.0 Cross Site Scripting

vTiger CRM version 7.4.0 suffers from multiple reflective cross site scripting vulnerabilities.

August 29, 2024Microsoft Windows IPv6 CVE-2024-38063 Checker / Denial Of Service

Microsoft Windows IPv6 vulnerability checking proof of concept python script that causes a denial of service. Windows 10 and 11 versions under 10.0.26100.1457 and Server 2016-2019-2022 versions under 10.0.17763.6189 are affected.

August 29, 2024Gitea 1.22.0 Cross Site Scripting

Gitea version 1.22.0 suffers from a cross site scripting vulnerability.

August 29, 2024Notemark 0.13.0 Cross Site Scripting

Notemark versions 0.13.0 and below suffer from a cross site scripting vulnerability.

August 29, 2024Online Graduate Tracer System 1.0.0 Insecure Direct Object Reference

Online Graduate Tracer System version 1.0.0 suffers from an insecure direct object reference vulnerability.

August 29, 2024SPIP 4.2.5 Code Execution

SPIP version 4.2.5 suffers from a code execution vulnerability.

August 29, 2024Online Bus Ticketing 1.0 Insecure Direct Object Reference

Online Bus Ticketing version 1.0 suffers from an insecure direct object reference vulnerability.

August 29, 2024Online Appointment System 1.0 Insecure Settings

Online Appointment System version 1.0 suffers from an ignored default credential vulnerability.

August 29, 2024Multi-Vendor Online Groceries Management System 1.0 Insecure Settings

Multi-Vendor Online Groceries Management System version 1.0 suffers from an ignored default credential vulnerability.

Archives
Categories
  • All Exploits 4087
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow