August 4, 2022WordPress Duplicator 1.4.7 Unauthenticated Backup Download

WordPress Duplicator plugin version 1.4.7 suffers from a backup disclosure vulnerability.

August 4, 2022VMware Workspace ONE Access Privilege Escalation

VMware Workspace ONE Access contains a vulnerability whereby the horizon user can escalate their privileges to those of the root user by modifying a file and then restarting the vmware-certproxy service which invokes it. The service control is permitted v

August 3, 2022Zoho Password Manager Pro XML-RPC Java Deserialization

This Metasploit module exploits a Java deserialization vulnerability in Zoho ManageEngine Pro before 12101 and PAM360 before 5510. Unauthenticated attackers can send a crafted XML-RPC request containing malicious serialized data to /xmlrpc to gain remote

August 3, 2022MobileIron Log4Shell Remote Command Execution

MobileIron Core is affected by the Log4Shell vulnerability whereby a JNDI string sent to the server will cause it to connect to the attacker and deserialize a malicious Java object. This results in OS command execution in the context of the tomcat user. T

August 3, 2022Multi-Language Hotel Management 2022 1.0 SQL Injection

Multi-Language Hotel Management 2022 version 1.0 suffers from a remote SQL injection vulnerability.

August 3, 2022IObit Malware Fighter 9.2 Tampering / Privilege Escalation

IObit Malware Fighter version 9.2 fails to provide sufficient anti-tampering protection and that shortcoming can be leveraged to escalate to SYSTEM privileges.

August 2, 2022uftpd 2.10 Directory Traversal

uftpd versions 2.7 through 2.10 suffer from an authenticated directory traversal vulnerability.

August 1, 2022Backdoor.Win32.Destrukor.20 MVID-2022-0627 Remote Command Execution

Backdoor.Win32.Destrukor.20 malware suffers from an unauthenticated remote command execution vulnerability.

August 1, 2022Omnia MPX 1.5.0+r1 Path Traversal

Omnia MPX version 1.5.0+r1 suffers from a path traversal vulnerability.

August 1, 2022NanoCMS 0.4 Remote Code Execution

NanoCMS version 0.4 suffers from an authenticated remote code execution vulnerability.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow