July 4, 2022Ransom Lockbit 3.0 MVID-2022-0620 Buffer Overflow

Lockbit ransomware version 3.0 apparently now requires a password to execute as noted by "@vxunderground", but does not properly check bounds for both the -pass and -k arguments. Supplying a long string of characters for either flag will trigger a unicode

July 4, 2022DouPHP 1.2 Release 20141027 SQL Injection

DouPHP version 1.2 Release 20141027 suffers from a remote SQL injection vulnerability.

July 4, 2022Paymoney 3.3 Cross Site Scripting

Paymoney version 3.3 suffers from a cross site scripting vulnerability.

July 4, 2022Stock Management System 2020 SQL Injection

Stock Management System 2020 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

July 1, 2022Carel pCOWeb HVAC BACnet Gateway 2.1.0 Unauthenticated Directory Traversal

Carel pCOWeb HVAC BACnet Gateway version 2.1.0 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the file GET parameter through the logdownload.cgi bash script is not properly verified before being used to downl

July 1, 2022PHP Library Remote Code Execution

Several PHP compatibility libraries contain a potential remote code execution flaw in their json_decode() function based on having copy pasted existing vulnerable code. Affected components include the WassUp Realtime analytics WordPress plugin, AjaXplorer

July 1, 2022BigBlueButton 2.3 / 2.4.7 Cross Site Scripting

BigBlueButton versions 2.3, prior to 2.4.8, and prior to 2.5.0 suffer from a persistent cross site scripting vulnerability.

July 1, 2022Classified Listing 2.2.9 Cross Site Scripting

Classified Listing version 2.2.9 suffers from a cross site scripting vulnerability.

July 1, 2022TypeORM SQL Injection

TypeORM versions prior to 0.3.0 suffer from a remote SQL injection vulnerability in the findOne function.

June 30, 2022Backdoor.Win32.Coredoor.10.a MVID-2022-0618 Authentication Bypass

Backdoor.Win32.Coredoor.10.a malware suffers from an authentication bypass vulnerability.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow