August 1, 2024Oracle Database 12c Release 1 Unquoted Service Path

Oracle Database version 12c Release 1 suffers from an unquoted service path vulnerability.

August 1, 2024SolarWinds Kiwi Syslog Server 9.6.7.1 Unquoted Service Path

SolarWinds Kiwi Syslog Server version 9.6.7.1 suffers from an unquoted service path vulnerability.

August 1, 2024Babaji E-Commerce 1.0 Insecure Settings

Babaji E-Commerce version 1.0 suffers from an ignored default credential vulnerability.

July 31, 2024OpenMediaVault rpc.php Authenticated Cron Remote Code Execution

OpenMediaVault allows an authenticated user to create cron jobs as root on the system. An attacker can abuse this by sending a POST request via rpc.php to schedule and execute a cron entry that runs arbitrary commands as root on the system. All OpenMediaV

July 31, 2024Readymade Real Estate Script SQL Injection / Cross Site Scripting

Readymade Real Estate Script suffers from remote blind SQL injection and cross site scripting vulnerabilities.

July 31, 2024AMPLE BILLS 1.0 Cross Site Scripting

AMPLE BILLS version 1.0 suffers from a cross site scripting vulnerability.

July 31, 2024Aero CMS 0.0.1 Cross Site Request Forgery

Aero CMS version 0.0.1 suffers from a cross site request forgery vulnerability.

July 31, 2024SchoolPlus LMS 1.0 SQL Injection

SchoolPlus LMS version 1.0 suffers from a remote SQL injection vulnerability.

July 31, 2024AccPack Khanepani 1.0 Insecure Direct Object Reference

AccPack Khanepani version 1.0 suffers from an insecure direct object reference vulnerability.

July 31, 2024AccPack Cop 1.0 SQL Injection

AccPack Cop version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow