May 20, 2024WordPress XStore Theme 9.3.8 SQL Injection

WordPress XStore theme version 9.3.8 suffers from a remote SQL injection vulnerability.

May 20, 2024Apache OFBiz 18.12.12 Directory Traversal

Apache OFBiz versions 18.12.12 and below suffer from a directory traversal vulnerability.

May 20, 2024Backdrop CMS 1.27.1 Remote Command Execution

Backdrop CMS version 1.27.1 suffers from a remote command execution vulnerability.

May 20, 2024Rocket LMS 1.9 Cross Site Scripting

Rocket LMS version 1.9 suffers from a persistent cross site scripting vulnerability.

May 15, 2024Cacti 1.2.26 Remote Code Execution

Cacti versions 1.2.26 and below suffer from a remote code execution execution vulnerability in import.php.

May 15, 2024SAP Cloud Connector 2.16.1 Missing Validation

SAP Cloud Connector versions 2.15.0 through 2.16.1 were found to happily accept self-signed TLS certificates between SCC and SAP BTP.

May 15, 2024Zope 5.9 Command Injection

Zope version 5.9 suffers from a command injection vulnerability in /utilities/mkwsgiinstance.py.

May 14, 2024CrushFTP Directory Traversal

CrushFTP versions prior to 11.1.0 suffers from a directory traversal vulnerability.

May 14, 2024TrojanSpy.Win64.EMOTET.A MVID-2024-0684 Code Execution

TrojanSpy.Win64.EMOTET.A malware suffers from a code execution vulnerability.

May 14, 2024Plantronics Hub 3.25.1 Arbitrary File Read

Plantronics Hub version 3.25.1 suffers from an arbitrary file read vulnerability.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow