June 3, 2022Microweber CMS 1.2.15 Account Takeover

Microweber CMS versions 1.2.15 and below suffer from an account takeover vulnerability.

June 3, 2022Zyxel USG FLEX 5.21 Command Injection

Zyxel USG FLEX version 5.21 suffers from a command injection vulnerability.

June 2, 2022libMeshb Buffer Overflow

libMeshb suffers from a buffer overflow vulnerability. Version 7.62 has been released to address this issue.

June 2, 2022Product Show Room Site 1.0 Cross Site Scripting

Product Show Room Site version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.

June 2, 2022dotCMS Shell Upload

When files are uploaded into dotCMS via the content API, but before they become content, dotCMS writes the file down in a temporary directory. In the case of this vulnerability, dotCMS does not sanitize the filename passed in via the multipart request hea

June 1, 2022GtkRadiant 1.6.6 Buffer Overflow

GtkRadiant version 1.6.6 suffers from a buffer overflow vulnerability.

June 1, 2022libxml2 xmlBufAdd Heap Buffer Overflow

libxml2 is vulnerable to a heap buffer overflow when xmlBufAdd is called on a very large buffer.

June 1, 2022Avantune Genialcloud ProJ 10 Cross Site Scripting

Avantune Genialcloud ProJ version 10 suffers from a cross site scripting vulnerability.

May 31, 2022MyBB Admin Control Remote Code Execution

This Metasploit module exploits an improper input validation vulnerability in MyBB versions prior to 1.8.30 to execute arbitrary code in the context of the user running the application. The MyBB Admin Control setting page calls the PHP eval function with

May 31, 2022Microsoft Office MSDT Follina Proof Of Concept

Proof of concept for the remote code execution vulnerability in MSDT known as Follina.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow