May 2, 2022WordPress Stafflist 3.1.2 Cross Site Request Forgery

WordPress Stafflist plugin version 3.1.2 suffers from a cross site request forgery vulnerability.

May 2, 2022WordPress Stafflist 3.1.2 SQL Injection

WordPress Stafflist plugin version 3.1.2 suffers from a remote SQL injection vulnerability.

May 2, 2022Strapi 3.6.8 Password Disclosure / Insecure Handling

Strap versions prior to 3.6.9 and 4.1.5 disclose a user's password due to simply base64 encoding it and sticking it in a cookie.

May 2, 2022Ransom.LockBit DLL Hijacking

Ransom.LockBit malware suffers from a dll hijacking vulnerability.

May 2, 2022Covid 19 Travel Pass Management System 1.0 SQL Injection

Covid 19 Travel Pass Management System version 1.0 suffers from a remote SQL injection vulnerability.

May 2, 2022Toll Tax Management System 1.0 SQL Injection

Toll Tax Management System version 1.0 suffers from a remote SQL injection vulnerability.

May 2, 2022Ransom.LockBit Code Execution

Ransom.LockBit malware suffers from a code execution vulnerability that can be leveraged via dll hijacking.

April 28, 2022Home Clean Service System 1.0 SQL Injection

Home Clean Service System version 1.0 suffers from a remote SQL injection vulnerability.

April 27, 2022Redis Lua Sandbox Escape

This Metasploit module exploits CVE-2022-0543, a Lua-based Redis sandbox escape. The vulnerability was introduced by Debian and Ubuntu Redis packages that insufficiently sanitized the Lua environment. The maintainers failed to disable the package interfac

April 27, 2022Zepp 6.1.4-play User Account Enumeration

Zepp version 6.1.4-play suffers from a user account enumeration flaw in the password reset function.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow