February 3, 2023Oracle Database 12.1.0.2 Spatial Component Privilege Escalation

Oracle Database version 12.1.0.2 suffers from a privilege escalation vulnerability that achieves DBA access via the Spatial component.

February 1, 2023io_uring Same Type Object Reuse Privilege Escalation

This Metasploit module exploits a bug in io_uring leading to an additional put_cred() that can be exploited to hijack credentials of other processes. This exploit will spawn SUID programs to get the freed cred object reallocated by a privileged process an

February 1, 2023vmwgfx Driver File Descriptor Handling Privilege Escalation

If the vmwgfx driver fails to copy the fence_rep object to userland, it tries to recover by deallocating the (already populated) file descriptor. This is wrong, as the fd gets released via put_unused_fd() which shouldn't be used, as the fd table slot was

February 1, 2023eCommerce Marketplace Platform CMS 1.7 SQL Injection

eCommerce Marketplace Platform CMS version 1.7 suffers from a remote SQL injection vulnerability.

February 1, 2023eCommerce Marketplace Platform CMS 1.7 Cross Site Scripting

eCommerce Marketplace Platform CMS version 1.7 suffers from a cross site scripting vulnerability.

February 1, 2023Online Eyewear Shop 1.0 SQL Injection

Online Eyewear Shop version 1.0 suffers from a remote SQL injection vulnerability.

January 31, 2023Control Web Panel Unauthenticated Remote Command Execution

Control Web Panel versions prior to 0.9.8.1147 are vulnerable to unauthenticated OS command injection. Successful exploitation results in code execution as the root user. The results of the command are not contained within the HTTP response and the reques

January 31, 2023PHPJabbers Business Directory Script 3.2 Cross Site Scripting

PHPJabbers Business Directory Script version 3.2 suffers from a cross site scripting vulnerability.

January 31, 2023PHPJabbers Auto Classifieds Script 3.2 Cross Site Scripting

PHPJabbers Auto Classifieds Script version 3.2 suffers from a cross site scripting vulnerability.

January 31, 2023mRemoteNG 1.76.20 Privilege Escalation

mRemoteNG version 1.76.20 suffers from a weak permission privilege escalation vulnerability.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow