FreshRSS

๐Ÿ”’
โŒ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayExploit-DB Updates

[webapps] Employee Management System v1 - 'email' SQL Injection

Employee Management System v1 - 'email' SQL Injection
  • February 19th 2024 at 00:00

[local] Microsoft Windows Defender - VBScript Detection Bypass

Microsoft Windows Defender - VBScript Detection Bypass
  • February 19th 2024 at 00:00

[webapps] Wondercms 4.3.2 - XSS to RCE

Wondercms 4.3.2 - XSS to RCE
  • February 19th 2024 at 00:00

[dos] XAMPP - Buffer Overflow POC

XAMPP - Buffer Overflow POC
  • February 19th 2024 at 00:00

[local] Microsoft Windows Defender Bypass - Detection Mitigation Bypass

Microsoft Windows Defender Bypass - Detection Mitigation Bypass
  • February 19th 2024 at 00:00

[webapps] Metabase 0.46.6 - Pre-Auth Remote Code Execution

Metabase 0.46.6 - Pre-Auth Remote Code Execution
  • February 15th 2024 at 00:00

[local] DS Wireless Communication - Remote Code Execution

DS Wireless Communication - Remote Code Execution
  • February 15th 2024 at 00:00

[webapps] SISQUALWFM 7.1.319.103 - Host Header Injection

SISQUALWFM 7.1.319.103 - Host Header Injection
  • February 15th 2024 at 00:00

[webapps] Splunk 9.0.4 - Information Disclosure

Splunk 9.0.4 - Information Disclosure
  • February 13th 2024 at 00:00

[webapps] Lost and Found Information System v1.0 - ( IDOR ) leads to Account Take over

Lost and Found Information System v1.0 - ( IDOR ) leads to Account Take over
  • February 13th 2024 at 00:00

[dos] VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service

VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service
  • February 13th 2024 at 00:00

[webapps] Wordpress Seotheme - Remote Code Execution Unauthenticated

Wordpress Seotheme - Remote Code Execution Unauthenticated
  • February 9th 2024 at 00:00

[webapps] Wordpress Augmented-Reality - Remote Code Execution Unauthenticated

Wordpress Augmented-Reality - Remote Code Execution Unauthenticated
  • February 9th 2024 at 00:00

[dos] Elasticsearch - StackOverflow DoS

Elasticsearch - StackOverflow DoS
  • February 9th 2024 at 00:00

[webapps] Online Nurse Hiring System 1.0 - Time-Based SQL Injection

Online Nurse Hiring System 1.0 - Time-Based SQL Injection
  • February 9th 2024 at 00:00

[remote] Zyxel zysh - Format string

Zyxel zysh - Format string
  • February 9th 2024 at 00:00

[webapps] Rail Pass Management System 1.0 - Time-Based SQL Injection

Rail Pass Management System 1.0 - Time-Based SQL Injection
  • February 9th 2024 at 00:00

[webapps] Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)

Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)
  • February 9th 2024 at 00:00
  • February 5th 2024 at 00:00

[webapps] Curfew e-Pass Management System 1.0 - FromDate SQL Injection

Curfew e-Pass Management System 1.0 - FromDate SQL Injection
  • February 5th 2024 at 00:00

[webapps] GYM MS - GYM Management System - Cross Site Scripting (Stored)

GYM MS - GYM Management System - Cross Site Scripting (Stored)
  • February 5th 2024 at 00:00

[webapps] TASKHUB-2.8.8 - XSS-Reflected

TASKHUB-2.8.8 - XSS-Reflected
  • February 5th 2024 at 00:00

[webapps] WhatsUp Gold 2022 (22.1.0 Build 39) - XSS

WhatsUp Gold 2022 (22.1.0 Build 39) - XSS
  • February 5th 2024 at 00:00

[webapps] MISP 2.4.171 - Stored XSS

MISP 2.4.171 - Stored XSS
  • February 5th 2024 at 00:00

[webapps] Clinic's Patient Management System 1.0 - Unauthenticated RCE

Clinic's Patient Management System 1.0 - Unauthenticated RCE
  • February 5th 2024 at 00:00

[webapps] Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution

Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution
  • February 2nd 2024 at 00:00

[webapps] Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass

Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass
  • February 2nd 2024 at 00:00

[webapps] TP-Link TL-WR740N - UnAuthenticated Directory Transversal

TP-Link TL-WR740N - UnAuthenticated Directory Transversal
  • February 2nd 2024 at 00:00

[webapps] TP-LINK TL-WR740N - Multiple HTML Injection

TP-LINK TL-WR740N - Multiple HTML Injection
  • February 2nd 2024 at 00:00

[webapps] mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page

mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page
  • February 2nd 2024 at 00:00

[remote] PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow

PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow
  • February 2nd 2024 at 00:00

[webapps] Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure

Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
  • February 2nd 2024 at 00:00

[dos] Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS

Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS
  • February 2nd 2024 at 00:00

[webapps] Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)

Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)
  • February 2nd 2024 at 00:00

[webapps] Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure

Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure
  • February 2nd 2024 at 00:00

[remote] WebCatalog 48.4 - Arbitrary Protocol Execution

WebCatalog 48.4 - Arbitrary Protocol Execution
  • February 2nd 2024 at 00:00

[webapps] Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal

Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal
  • February 2nd 2024 at 00:00

[webapps] GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities

GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
  • January 31st 2024 at 00:00

[remote] RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC

RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC
  • January 31st 2024 at 00:00

[remote] Proxmox VE - TOTP Brute Force

Proxmox VE - TOTP Brute Force
  • January 31st 2024 at 00:00

[webapps] 101 News 1.0 - Multiple-SQLi

101 News 1.0 - Multiple-SQLi
  • January 31st 2024 at 00:00

[webapps] Academy LMS 6.2 - SQL Injection

Academy LMS 6.2 - SQL Injection
  • January 31st 2024 at 00:00

[webapps] Academy LMS 6.2 - Reflected XSS

Academy LMS 6.2 - Reflected XSS
  • January 31st 2024 at 00:00
  • January 31st 2024 at 00:00

[remote] Equipment Rental Script-1.0 - SQLi

Equipment Rental Script-1.0 - SQLi
  • January 29th 2024 at 00:00

[remote] Ricoh Printer - Directory and File Exposure

Ricoh Printer - Directory and File Exposure
  • January 29th 2024 at 00:00

[remote] Blood Bank & Donor Management System using v2.2 - Stored XSS

Blood Bank & Donor Management System using v2.2 - Stored XSS
  • January 29th 2024 at 00:00

[webapps] Fundraising Script 1.0 - SQLi

Fundraising Script 1.0 - SQLi
  • January 29th 2024 at 00:00

[webapps] PHP Shopping Cart 4.2 - Multiple-SQLi

PHP Shopping Cart 4.2 - Multiple-SQLi
  • January 29th 2024 at 00:00

[local] Typora v1.7.4 - OS Command Injection

Typora v1.7.4 - OS Command Injection
  • January 29th 2024 at 00:00

[local] 7 Sticky Notes v1.9 - OS Command Injection

7 Sticky Notes v1.9 - OS Command Injection
  • January 29th 2024 at 00:00

[webapps] Bank Locker Management System - SQL Injection

Bank Locker Management System - SQL Injection
  • January 29th 2024 at 00:00

[remote] Atcom 2.7.x.x - Authenticated Command Injection

Atcom 2.7.x.x - Authenticated Command Injection
  • October 9th 2023 at 00:00

[webapps] Shuttle-Booking-Software v1.0 - Multiple-SQLi

Shuttle-Booking-Software v1.0 - Multiple-SQLi
  • October 9th 2023 at 00:00

[webapps] Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation

Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
  • October 9th 2023 at 00:00

[webapps] GLPI GZIP(Py3) 9.4.5 - RCE

GLPI GZIP(Py3) 9.4.5 - RCE
  • October 9th 2023 at 00:00

[webapps] Wordpress Sonaar Music Plugin 4.7 - Stored XSS

Wordpress Sonaar Music Plugin 4.7 - Stored XSS
  • October 9th 2023 at 00:00
โŒ