April 27, 2022Prime95 30.7 Build 9 Buffer Overflow

Prime95 version 30.7 build 9 suffers from a buffer overflow vulnerability.

April 27, 2022WordPress Curtain 1.0.2 Cross Site Scripting

WordPress Curtain plugin version 1.0.2 suffers from a persistent cross site scripting vulnerability.

April 26, 2022WordPress Coru LFMember 1.0.2 Cross Site Scripting

WordPress Coru LFMember plugin version 1.0.2 suffers from a persistent cross site scripting vulnerability.

April 26, 2022Gitlab 14.9 Cross Site Scripting

Gitlab versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.7 prior to 14.7.7 suffer from a persistent cross site scripting vulnerability.

April 26, 2022Gitlab 14.9 Authentication Bypass

Gitlab versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.7 prior to 14.7.7 suffer from a bypass vulnerability due to having set a hardcoded password for accounts registered using an OmniAuth provider.

April 26, 2022WordPress WP-Invoice 4.3.1 Cross Site Scripting

WordPress WP-Invoice plugin version 4.3.1 suffers from a persistent cross site scripting vulnerability.

April 25, 2022Joomla Sexy Polling 2.1.7 SQL Injection

Joomla Sexy Polling extension versions 2.1.7 and below suffer from a remote SQL injection vulnerability.

April 25, 2022WordPress ScrollReveal.js Effects 1.1.1 Cross Site Scripting

WordPress ScrollReveal.js Effects plugin version 1.1.1 suffers from a persistent cross site scripting vulnerability.

April 21, 2022ManageEngine ADSelfService Plus Custom Script Execution

This Metasploit module exploits the "custom script" feature of ADSelfService Plus. The feature was removed in build 6122 as part of the patch for CVE-2022-28810. For purposes of this module, a "custom script" is arbitrary operating system command executio

April 21, 2022Watch Queue Out-Of-Bounds Write

This Metasploit module exploits a vulnerability in the Linux Kernel's watch_queue event notification system. It relies on a heap out-of-bounds write in kernel memory. The exploit may fail on the first attempt so multiple attempts may be needed. Note that

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow