May 22, 2023W3 Eden Download Manager 3.2.70 Cross Site Scripting

W3 Eden Download Manager versions 3.2.70 and below suffer from a persistent cross site scripting vulnerability via ShortCode.

May 22, 2023eBankIT 6 Arbitrary OTP Generation

In eBankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any email address or phone number without validation.

May 22, 2023WBiz Desk 1.2 SQL Injection

WBiz Desk version 1.2 suffers from a remote SQL injection vulnerability.

May 22, 2023hyiplab 2.1 Default Credentials

hyiplab version 2.1 leaves a default set of administrative credentials installed post installation.

May 22, 2023Esg 2.5 SQL Injection

Esg version 2.5 suffers from a remote SQL injection vulnerability.

May 22, 2023Code Bakers 1.0 SQL Injection

Code Bakers version 1.0 suffers from a remote SQL injection vulnerability.

May 19, 2023CiviCRM 5.59.alpha1 Cross Site Scripting

CiviCRM version 5.59.alpha1 suffers from a persistent cross site scripting vulnerability.

May 19, 2023ChurchCRM 4.5.4 Cross Site Scripting

ChurchCRM version 4.5.4 suffers from a cross site scripting vulnerability. Related CVE number: CVE-2023-31699.

May 19, 2023MobileTrans 4.0.11 Weak Service Permissions

MobileTrans version 4.0.11 suffers from having a weak service permission vulnerability.

May 19, 2023Filmora 12 Build 1.0.0.7 Unquoted Service Path

Filmora version 12 Build 1.0.0.7 suffers from an unquoted service path vulnerability.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow