June 12, 2023osCommerce 4 Local File Inclusion

osCommerce version 4 suffers from a local file inclusion vulnerability.

June 12, 2023WordPress Workreap 2.2.2 Shell Upload

WordPress theme Workreap version 2.2.2 suffers from a remote shell upload vulnerabilities.

June 12, 2023Oracle Weblogic PreAuth Remote Command Execution

Oracle Weblogic versions 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0 prior to the Jan 2023 security update are vulnerable to an unauthenticated remote code execution vulnerability due to a post deserialization vulnerability. This Metasploit module exploits this

June 12, 2023TerraMaster TOS 4.2.15 Remote Code Execution

This Metasploit module is a Terramaster chained exploit that performs session crafting to achieve escalated privileges that allows an attacker to access vulnerable code execution flaws. TOS versions 4.2.15 and below are affected.

June 12, 2023TerraMaster TOS 4.2.06 Remote Code Execution

This Metasploit module exploits an unauthenticated remote code execution vulnerability in TerraMaster TOS versions 4.2.06 and below via shell metacharacters in the Event parameter at vulnerable endpoint include/makecvs.php during CSV creation. Any unauthe

June 9, 2023Movierocket 1.0 Cross Site Scripting

Movierocket version 1.0 suffers from a cross site scripting vulnerability.

June 9, 2023Thruk Monitoring Web Interface 3.06 Path Traversal

Thruk Monitoring Web Interface versions 3.06 and below are affected by a path traversal vulnerability.

June 9, 2023Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution

This Metasploit module exploits a remote unauthenticated command injection vulnerability in the Internet Key Exchange (IKE) packet decoder over UDP port 500 on the WAN interface of several Zyxel devices. The affected devices are as follows: ATP (Firmware

June 9, 2023Codemonkey Multi Vendor Digital Product Mart 1.0 Cross Site Scripting

Codemonkey Multi Vendor Digital Product Mart version 1.0 suffers from a cross site scripting vulnerability.

June 9, 2023Scriptio 1.4 Cross Site Scripting

Scriptio version 1.4 suffers from a cross site scripting vulnerability.

Archives
Categories
  • All Exploits 4131
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow