FreshRSS

๐Ÿ”’
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)

April 3rd 2023 at 00:00
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Art Gallery Management System Project v1.0 - SQL Injection (sqli) authenticated

April 3rd 2023 at 00:00
Art Gallery Management System Project v1.0 - SQL Injection (sqli) authenticated
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin

April 3rd 2023 at 00:00
GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] HotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path

April 3rd 2023 at 00:00
HotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] sleuthkit 4.11.1 - Command Injection

April 3rd 2023 at 00:00
sleuthkit 4.11.1 - Command Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] ChiKoi v1.0 - SQL Injection

April 3rd 2023 at 00:00
ChiKoi v1.0 - SQL Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] Grand Theft Auto III/Vice City Skin File v1.1 - Buffer Overflow

April 3rd 2023 at 00:00
Grand Theft Auto III/Vice City Skin File v1.1 - Buffer Overflow
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] Windows 11 10.0.22000 - Backup service Privilege Escalation

April 3rd 2023 at 00:00
Windows 11 10.0.22000 - Backup service Privilege Escalation
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Active eCommerce CMS 6.5.0 - Stored Cross-Site Scripting (XSS)

April 3rd 2023 at 00:00
Active eCommerce CMS 6.5.0 - Stored Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)

April 3rd 2023 at 00:00
GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion

April 3rd 2023 at 00:00
GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] sudo 1.8.0 to 1.9.12p1 - Privilege Escalation

April 3rd 2023 at 00:00
sudo 1.8.0 to 1.9.12p1 - Privilege Escalation
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration)

April 3rd 2023 at 00:00
GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] AmazCart CMS 3.4 - Cross-Site-Scripting (XSS)

April 3rd 2023 at 00:00
AmazCart CMS 3.4 - Cross-Site-Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] MyBB 1.8.32 - Remote Code Execution (RCE) (Authenticated)

April 3rd 2023 at 00:00
MyBB 1.8.32 - Remote Code Execution (RCE) (Authenticated)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] Solaris 10 libXm - Buffer overflow Local privilege escalation

April 3rd 2023 at 00:00
Solaris 10 libXm - Buffer overflow Local privilege escalation
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquoted Service Path

April 3rd 2023 at 00:00
Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquoted Service Path
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] SQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS)

April 3rd 2023 at 00:00
SQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin

April 3rd 2023 at 00:00
GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Roxy WI v6.1.0.0 - Improper Authentication Control

April 3rd 2023 at 00:00
Roxy WI v6.1.0.0 - Improper Authentication Control
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)

April 3rd 2023 at 00:00
Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload

April 3rd 2023 at 00:00
Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE

April 3rd 2023 at 00:00
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Nacos 2.0.3 - Access Control vulnerability

April 3rd 2023 at 00:00
Nacos 2.0.3 - Access Control vulnerability
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] ManageEngin AMP 4.3.0 - File-path-traversal

April 3rd 2023 at 00:00
ManageEngin AMP 4.3.0 - File-path-traversal
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)

April 3rd 2023 at 00:00
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] pimCore v5.4.18-skeleton - Sensitive Cookie with Improper SameSite Attribute

April 3rd 2023 at 00:00
pimCore v5.4.18-skeleton - Sensitive Cookie with Improper SameSite Attribute
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] ERPGo SaaS 3.9 - CSV Injection

April 3rd 2023 at 00:00
ERPGo SaaS 3.9 - CSV Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GLPI v10.0.1 - Unauthenticated Sensitive Data Exposure

April 3rd 2023 at 00:00
GLPI v10.0.1 - Unauthenticated Sensitive Data Exposure
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Art Gallery Management System Project v1.0 - SQL Injection (sqli) Unauthenticated

April 3rd 2023 at 00:00
Art Gallery Management System Project v1.0 - SQL Injection (sqli) Unauthenticated
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] perfSONAR v4.4.5 - Partial Blind CSRF

April 1st 2023 at 00:00
perfSONAR v4.4.5 - Partial Blind CSRF
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] NetIQ/Microfocus Performance Endpoint v5.1 - remote root/SYSTEM exploit

April 1st 2023 at 00:00
NetIQ/Microfocus Performance Endpoint v5.1 - remote root/SYSTEM exploit
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Hughes Satellite Router HX200 v8.3.1.14 - Remote File Inclusion

April 1st 2023 at 00:00
Hughes Satellite Router HX200 v8.3.1.14 - Remote File Inclusion
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)

April 1st 2023 at 00:00
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] AD Manager Plus 7122 - Remote Code Execution (RCE)

April 1st 2023 at 00:00
AD Manager Plus 7122 - Remote Code Execution (RCE)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] TP-Link TL-WR902AC firmware 210730 (V3) - Remote Code Execution (RCE) (Authenticated)

April 1st 2023 at 00:00
TP-Link TL-WR902AC firmware 210730 (V3) - Remote Code Execution (RCE) (Authenticated)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[dos] AimOne Video Converter V2.04 Build 103 - Buffer Overflow (DoS)

April 1st 2023 at 00:00
AimOne Video Converter V2.04 Build 103 - Buffer Overflow (DoS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] SugarCRM 12.2.0 - Remote Code Execution (RCE)

April 1st 2023 at 00:00
SugarCRM 12.2.0 - Remote Code Execution (RCE)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Nexxt Router Firmware 42.103.1.5095 - Remote Code Execution (RCE) (Authenticated)

April 1st 2023 at 00:00
Nexxt Router Firmware 42.103.1.5095 - Remote Code Execution (RCE) (Authenticated)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] XCMS v1.83 - Remote Command Execution (RCE)

April 1st 2023 at 00:00
XCMS v1.83 - Remote Command Execution (RCE)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)

April 1st 2023 at 00:00
Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Apache 2.4.x - Buffer Overflow

April 1st 2023 at 00:00
Apache 2.4.x - Buffer Overflow
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] Splashtop 8.71.12001.0 - Unquoted Service Path

April 1st 2023 at 00:00
Splashtop 8.71.12001.0 - Unquoted Service Path
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Prizm Content Connect v10.5.1030.8315 - XXE

April 1st 2023 at 00:00
Prizm Content Connect v10.5.1030.8315 - XXE
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)

April 1st 2023 at 00:00
Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] ELSI Smart Floor V3.3.3 - Stored Cross-Site Scripting (XSS)

April 1st 2023 at 00:00
ELSI Smart Floor V3.3.3 - Stored Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Ecommerse v1.0 - Cross-Site Scripting (XSS)

March 30th 2023 at 00:00
Ecommerse v1.0 - Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] ClicShopping v3.402 - Cross-Site Scripting (XSS)

March 30th 2023 at 00:00
ClicShopping v3.402 - Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Virtual Reception v1.0 - Web Server Directory Traversal

March 30th 2023 at 00:00
Virtual Reception v1.0 - Web Server Directory Traversal
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] WPForms 1.7.8 - Cross-Site Scripting (XSS)

March 30th 2023 at 00:00
WPForms 1.7.8 - Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Shoplazza 1.1 - Stored Cross-Site Scripting (XSS)

March 30th 2023 at 00:00
Shoplazza 1.1 - Stored Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] CrowdStrike Falcon AGENT 6.44.15806 - Uninstall without Installation Token

March 30th 2023 at 00:00
CrowdStrike Falcon AGENT 6.44.15806 - Uninstall without Installation Token
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Dreamer CMS v4.0.0 - SQL Injection

March 30th 2023 at 00:00
Dreamer CMS v4.0.0 - SQL Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] LISTSERV 17 - Insecure Direct Object Reference (IDOR)

March 30th 2023 at 00:00
LISTSERV 17 - Insecure Direct Object Reference (IDOR)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] Lavasoft web companion 4.1.0.409 - 'DCIservice' Unquoted Service Path

March 30th 2023 at 00:00
Lavasoft web companion 4.1.0.409 - 'DCIservice' Unquoted Service Path
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Eve-ng 5.0.1-13 - Stored Cross-Site Scripting (XSS)

March 30th 2023 at 00:00
Eve-ng 5.0.1-13 - Stored Cross-Site Scripting (XSS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] 4images 1.9 - Remote Command Execution (RCE)

March 30th 2023 at 00:00
4images 1.9 - Remote Command Execution (RCE)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Concrete5 CME v9.1.3 - Xpath injection

March 30th 2023 at 00:00
Concrete5 CME v9.1.3 - Xpath injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[dos] Router ZTE-H108NS - Stack Buffer Overflow (DoS)

March 30th 2023 at 00:00
Router ZTE-H108NS - Stack Buffer Overflow (DoS)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Router ZTE-H108NS - Authentication Bypass

March 30th 2023 at 00:00
Router ZTE-H108NS - Authentication Bypass
โŒ