September 16, 2022SAP SAProuter Improper Access Control

SAP SAProuter suffers from an improper access control vulnerability where permitting loopback traffic can lead to unexpected behavior.

September 16, 2022Social Share Button 2.2.3 SQL Injection

Social Share Buttons version 2.2.3 suffers from a remote SQL injection vulnerability.

September 16, 2022Rocket LMS 1.6 SQL Injection

Rocket LMS version 1.6 suffers from a remote SQL injection vulnerability.

September 15, 2022News247 News Magazine 1.0 Cross Site Scripting

News247 News Magazine version 1.0 suffers from a persistent cross site scripting vulnerability.

September 15, 2022Gitea 1.16.6 Remote Code Execution

This Metasploit module exploits the Git fetch command in Gitea repository migration process that leads to a remote command execution on the system. This vulnerability affects Gitea versions prior to 1.16.7.

September 14, 2022WordPress WPGateway 3.5 Privilege Escalation

WordPress WPGateway plugin versions 3.5 and below suffer from an unauthenticated privilege escalation vulnerability.

September 13, 2022TIBCO JasperReports Server 8.0.2 Community Edition Code Execution

Due to JMX/RMI services in TIBCO JasperReports Server version 8.0.2 Community Edition performing unsafe deserialization, it is possible to execute arbitrary code and system commands on the server system.

September 13, 2022Academy Learning Management System 5.7 Shell Upload

Academy Learning Management System version 5.7 suffers from a remote shell upload vulnerability.

September 13, 2022Rocket LMS 1.6 Cross Site Scripting

Rocket LMS version 1.6 suffers from a cross site scripting vulnerability.

September 13, 2022Rocket LMS 1.6 Shell Upload

Rocket LMS version 1.6 suffers from a remote shell upload vulnerability.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow