December 9, 2022Delta Electronics DVW-W02W2-E2 2.42 Command Injection

Delta Electronics DVW-W02W2-E2 version 2.42 suffers from an authenticated command injection vulnerability.

December 9, 2022Delta Electronics DX-2100-L1-CN 1.5.0.10 Command Injection / XSS

Delta Electronics DX-2100-L1-CN version 1.5.0.10 suffers from command injection and cross site scripting vulnerabilities.

December 7, 2022SentinelOne sentinelagent 22.3.2.5 Privilege Escalation

SentinelOne sentinelagent version 22.3.2.5 on Linux suffers from a privilege escalation vulnerability due to not use a fully qualified path when calling grep.

December 7, 2022py7zr 0.20.0 Directory Traversal

A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr versions 0.20.0 and earlier allows attackers to read arbitrary files on the local machine via a malicious 7z file extraction.

December 6, 2022VMware vCenter vScalation Privilege Escalation

This Metasploit module exploits a privilege escalation in vSphere/vCenter due to improper permissions on the /usr/lib/vmware-vmon/java-wrapper-vmon file. It is possible for anyone in the cis group to write to the file, which will execute as root on vmware

December 6, 2022Senayan Library Management System 9.5.1 SQL Injection

Senayan Library Management System version 9.5.1 suffers from a remote SQL injection vulnerability.

December 5, 2022Drupal H5P Module 2.0.0 Zip Slip Traversal

Drupal H5P Module versions 2.0.0 and below suffer from a traversal vulnerability when handling a zipped filename on windows.

December 5, 2022Automotive Shop Management System 1.0 SQL Injection

Automotive Shop Management System version 1.0 suffers from a remote SQL injection vulnerability.

December 5, 2022Zillya Total Security 3.0.2367.0 / 3.0.2368.0 Local Privilege Escalation

Zillya Total Security versions 3.0.2367.0 and 3.0.2368.0 suffer from a local privilege escalation vulnerability via a symlink vulnerability when using the quarantine module.

December 2, 2022Backdoor.Win32.Delf.gj MVID-2022-0663 Information Disclosure

Backdoor.Win32.Delf.gj malware suffers from an information leakage vulnerability.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow