June 6, 2024Trojan.Win32.DarkGateLoader MVID-2024-0685 Code Execution

Multiple variants of Trojan.Win32.DarkGateLoader malware suffer from a code execution vulnerability.

June 6, 2024Small CRM 1.0 SQL Injection

Small CRM version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

June 6, 2024Small CRM 1.0 Cross Site Scripting

Small CRM version 1.0 suffers from a cross site scripting vulnerability.

June 6, 2024Northwind Demo 1.0 Cross Site Scripting

Northwind Demo version 1.0 suffers from persistent cross site scripting vulnerability.

June 6, 2024WordPress Hash Form 1.1.0 Remote Code Execution

The Hash Form Drag and Drop Form Builder plugin for WordPress suffers from a critical vulnerability due to missing file type validation in the file_upload_action function. This vulnerability exists in all versions up to and including 1.1.0. Unauthenticate

June 3, 2024Employee And Visitor Gate Pass Logging System 1.0 SQL Injection

Employee and Visitor Gate Pass Logging System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

June 3, 2024FreePBX 16 Remote Code Execution

FreePBX suffers from a remote code execution vulnerability. Versions 14, 15, and 16 are all affected.

June 3, 2024Sitefinity 15.0 Cross Site Scripting

Sitefinity version 15.0 suffers from a persistent cross site scripting vulnerability.

June 3, 2024appRain CMF 4.0.5 Shell Upload

appRain CMF version 4.0.5 suffers from a remote shell upload vulnerability.

June 3, 2024CMSimple 5.15 Remote Shell Upload

CMSimple version 5.15 suffers from a remote shell upload vulnerability.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow