May 24, 20231Two Ecommerce 1.0 Missing Authentication

1Two Ecommerce version 1.0 appears to be missing authentication on the administrative interface.

May 24, 2023e107 2.3.2 Cross Site Scripting

e107 version 2.3.2 suffers from a cross site scripting vulnerability.

May 24, 2023Apache Superset 2.0.0 Authentication Bypass

Apache Superset version 2.0.0 suffers from an authentication bypass vulnerability.

May 24, 2023Cameleon CMS 2.7.4 Cross Site Scripting

Cameleon CMS version 2.7.4 suffers from a persistent cross site scripting vulnerability.

May 24, 2023Prestashop 8.0.4 CSV Injection

Prestashop version 8.0.4 suffers from a CSV injection vulnerability.

May 24, 2023Hubstaff 1.6.14-61e5e22e DLL Hijacking

Hubstaff version 1.6.14-61e5e22e suffers from a DLL hijacking vulnerability.

May 24, 2023WordPress Backup Migration 1.2.8 Backup Disclosure

WordPress Backup Migration plugin version 1.2.8 suffers from a database disclosure vulnerability.

May 23, 2023Sudoedit Extra Arguments Privilege Escalation

This exploit takes advantage of a vulnerability in sudoedit, part of the sudo package. The sudoedit (aka sudo -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local atta

May 23, 2023WBiz Desk 1.2 Cross Site Scripting

WBiz Desk version 1.2 suffers from a cross site scripting vulnerability.

May 23, 2023Affiliate Me 5.0.1 SQL Injection

Affiliate Me version 5.0.1 suffers from a remote SQL injection vulnerability.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow