April 14, 2023Microsoft Word Remote Code Execution

Microsoft Word appears to suffer from a remote code execution vulnerability when a user load a malicious file that reaches out to an attacker-controller server to get a hostile payload.

April 13, 2023File Replication Pro 7.5.0 Insecure Permissions / Privilege Escalation

File Replication Pro version 7.5.0 suffers from having insecure directory permissions that can allow a local attacker the ability to escalate privileges.

April 12, 2023Sielco Analog FM Transmitter 2.12 Cross Site Request Forgery

Sielco Analog FM Transmitter version 2.12 suffers from a cross site request forgery vulnerability.

April 12, 2023Sielco Analog FM Transmitter 2.12 Cookie Brute Force

Sielco Analog FM Transmitter version 2.12 suffers from a cookie brute forcing vulnerability that can allow for session hijacking.

April 12, 2023Google Chrome Browser 111.0.5563.64 AXPlatformNodeCocoa Denial Of Service

Google Chrome Browser version 111.0.5563.64 suffers from an AXPlatformNodeCocoa fatal out-of-memory denial of service vulnerability on macOS.

April 12, 2023WordPress WP Data Access 5.3.7 Privilege Escalation

WordPress WP Data Access plugin versions 5.3.7 and below suffer from a privilege escalation vulnerability.

April 12, 2023WordPress Limit Login Attempts 1.7.1 Cross Site Scripting

WordPress Limit Login Attempts plugin versions 1.7.1 and below suffer from a persistent cross site scripting vulnerability.

April 12, 2023InnovaStudio WYSIWYG Editor Asset Manager 5.4 Shell Upload

InnovaStudio WYSIWYG Editor Asset Manager versions 5.4 and below suffer from a remote shell upload vulnerability.

April 12, 2023Sielco PolyEco Digital FM Transmitter 2.0.6 Default Credentials

Sielco PolyEco Digital FM Transmitter version 2.0.6 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks to gain full control of the system.

April 12, 2023Sielco PolyEco Digital FM Transmitter 2.0.6 Cookie Brute Force

Sielco PolyEco Digital FM Transmitter version 2.0.6 suffers from a cookie brute forcing vulnerability that can allow for session hijacking.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow