May 30, 2023PrinterLogic Build 1.0.757 XSS / SQL Injection / Authentication Bypass

PrinterLogic build version 1.0.757 suffers from authentication bypass, cross site request forgery, cross site scripting, session fixation, insufficient checks, impersonation, remote SQL injection, and various other vulnerabilities.

May 30, 2023Argon Dashboard 2 SQL Injection

Argon Dashboard version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

May 30, 2023Thai Auto Web 1.2 Missing Authentication

Thai Auto Web version 1.2 appears to be missing authentication on the administrative interface.

May 30, 2023Code-Bakers 1.0 Missing Authentication

Code-Bakers version 1.0 appears to be missing authentication on the administrative interface.

May 30, 2023Wekan 6.74 Cross Site Scripting

Wekan versions 6.74 and below suffer from a persistent cross site scripting vulnerability.

May 30, 2023Serenity / StartSharp Software File Upload / XSS / User Enumeration / Reusable Tokens

Serenity and StartSharp Software versions prior to 6.7.1 suffer from file upload to cross site scripting, user enumeration, and reusable password reset token vulnerabilities.

May 30, 2023Pydio Cells 4.1.2 Server-Side Request Forgery

Pydio Cells versions 4.1.2 and below suffer from a server-side request forgery vulnerability.

May 30, 2023Pydio Cells 4.1.2 Cross Site Scripting

Pydio Cells versions 4.1.2 and below implement the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaScript. The secrets used to sign these URLs are hardcoded and exposed through the JavaScript files of the web ap

May 29, 2023New MVC Shop 1.0 SQL Injection / Missing Attributes

New MVC Shop version 1.0 suffers from remote SQL injection and missing attribute vulnerabilities.

May 29, 2023Simple Customer Relationship Management CRM 2023 1.0 SQL Injection

Simple Customer Relationship Management CRM 2023 version 1.0 suffers from a remote SQL injection vulnerability.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow