FreshRSS

๐Ÿ”’
โŒ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayExploit-DB Updates

[webapps] Flowise 1.6.5 - Authentication Bypass

Flowise 1.6.5 - Authentication Bypass
  • April 21st 2024 at 00:00

[webapps] SofaWiki 3.9.2 - Remote Command Execution (RCE) (Authenticated)

SofaWiki 3.9.2 - Remote Command Execution (RCE) (Authenticated)
  • April 21st 2024 at 00:00

[webapps] Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution

Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution
  • April 21st 2024 at 00:00

[webapps] FlatPress v1.3 - Remote Command Execution

FlatPress v1.3 - Remote Command Execution
  • April 21st 2024 at 00:00

[webapps] Laravel Framework 11 - Credential Leakage

Laravel Framework 11 - Credential Leakage
  • April 21st 2024 at 00:00

[webapps] djangorestframework-simplejwt 5.3.1 - Information Disclosure

djangorestframework-simplejwt 5.3.1 - Information Disclosure
  • April 15th 2024 at 00:00

[webapps] OpenClinic GA 5.247.01 - Path Traversal (Authenticated)

OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
  • April 15th 2024 at 00:00

[webapps] OpenClinic GA 5.247.01 - Information Disclosure

OpenClinic GA 5.247.01 - Information Disclosure
  • April 15th 2024 at 00:00

[webapps] Jenkins 2.441 - Local File Inclusion

Jenkins 2.441 - Local File Inclusion
  • April 15th 2024 at 00:00

[webapps] Savsoft Quiz v6.0 Enterprise - Stored XSS

Savsoft Quiz v6.0 Enterprise - Stored XSS
  • April 13th 2024 at 00:00

[webapps] Stock Management System v1.0 - Unauthenticated SQL Injection

Stock Management System v1.0 - Unauthenticated SQL Injection
  • April 13th 2024 at 00:00

[webapps] Online Fire Reporting System OFRS - SQL Injection Authentication Bypass

Online Fire Reporting System OFRS - SQL Injection Authentication Bypass
  • April 13th 2024 at 00:00

[webapps] BMC Compuware iStrobe Web - 20.13 - Pre-auth RCE

BMC Compuware iStrobe Web - 20.13 - Pre-auth RCE
  • April 13th 2024 at 00:00

[webapps] Moodle 3.10.1 - Authenticated Blind Time-Based SQL Injection - "sort" parameter

Moodle 3.10.1 - Authenticated Blind Time-Based SQL Injection - "sort" parameter
  • April 12th 2024 at 00:00

[local] Terratec dmx_6fire USB - Unquoted Service Path

Terratec dmx_6fire USB - Unquoted Service Path
  • April 12th 2024 at 00:00

[local] PrusaSlicer 2.6.1 - Arbitrary code execution

PrusaSlicer 2.6.1 - Arbitrary code execution
  • April 12th 2024 at 00:00

[webapps] Wordpress Plugin Playlist for Youtube 1.32 - Stored Cross-Site Scripting (XSS)

Wordpress Plugin Playlist for Youtube 1.32 - Stored Cross-Site Scripting (XSS)
  • April 12th 2024 at 00:00

[webapps] PopojiCMS Version 2.0.1 - Remote Command Execution

PopojiCMS Version 2.0.1 - Remote Command Execution
  • April 12th 2024 at 00:00

[webapps] Wordpress Plugin WP Video Playlist 1.1.1 - Stored Cross-Site Scripting (XSS)

Wordpress Plugin WP Video Playlist 1.1.1 - Stored Cross-Site Scripting (XSS)
  • April 12th 2024 at 00:00

[webapps] Ray OS v2.6.3 - Command Injection RCE(Unauthorized)

Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
  • April 12th 2024 at 00:00

[webapps] HTMLy Version v2.9.6 - Stored XSS

HTMLy Version v2.9.6 - Stored XSS
  • April 12th 2024 at 00:00

[webapps] WBCE 1.6.0 - Unauthenticated SQL injection

WBCE 1.6.0 - Unauthenticated SQL injection
  • April 12th 2024 at 00:00

[webapps] WBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)

WBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)
  • April 12th 2024 at 00:00

[webapps] GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload

GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
  • April 12th 2024 at 00:00

[webapps] Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload

Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload
  • April 8th 2024 at 00:00

[webapps] Daily Expense Manager 1.0 - 'term' SQLi

Daily Expense Manager 1.0 - 'term' SQLi
  • April 8th 2024 at 00:00

[webapps] Human Resource Management System v1.0 - Multiple SQLi

Human Resource Management System v1.0 - Multiple SQLi
  • April 8th 2024 at 00:00

[webapps] Best Student Result Management System v1.0 - Multiple SQLi

Best Student Result Management System v1.0 - Multiple SQLi
  • April 8th 2024 at 00:00

[remote] Positron Broadcast Signal Processor TRA7005 v1.20 - Authentication Bypass

Positron Broadcast Signal Processor TRA7005 v1.20 - Authentication Bypass
  • April 8th 2024 at 00:00

[webapps] Open Source Medicine Ordering System v1.0 - SQLi

Open Source Medicine Ordering System v1.0 - SQLi
  • April 8th 2024 at 00:00

[local] AnyDesk 7.0.15 - Unquoted Service Path

AnyDesk 7.0.15 - Unquoted Service Path
  • April 8th 2024 at 00:00

[webapps] Quick CMS v6.7 en 2023 - 'password' SQLi

Quick CMS v6.7 en 2023 - 'password' SQLi
  • April 3rd 2024 at 00:00

[webapps] Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XSS)

Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XSS)
  • April 3rd 2024 at 00:00

[webapps] Computer Laboratory Management System v1.0 - Multiple-SQLi

Computer Laboratory Management System v1.0 - Multiple-SQLi
  • April 3rd 2024 at 00:00

[local] ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path

ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path
  • April 3rd 2024 at 00:00

[webapps] Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)

Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
  • April 2nd 2024 at 00:00

[webapps] Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)

Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)
  • April 2nd 2024 at 00:00

[webapps] Online Hotel Booking In PHP 1.0 - Blind SQL Injection (Unauthenticated)

Online Hotel Booking In PHP 1.0 - Blind SQL Injection (Unauthenticated)
  • April 2nd 2024 at 00:00

[webapps] CE Phoenix v1.0.8.20 - Remote Code Execution

CE Phoenix v1.0.8.20 - Remote Code Execution
  • April 2nd 2024 at 00:00

[webapps] Simple Backup Plugin Python Exploit 2.7.10 - Path Traversal

Simple Backup Plugin Python Exploit 2.7.10 - Path Traversal
  • April 2nd 2024 at 00:00

[webapps] FoF Pretty Mail 1.1.2 - Local File Inclusion (LFI)

FoF Pretty Mail 1.1.2 - Local File Inclusion (LFI)
  • April 2nd 2024 at 00:00

[webapps] Hospital Management System v1.0 - Stored Cross Site Scripting (XSS)

Hospital Management System v1.0 - Stored Cross Site Scripting (XSS)
  • April 2nd 2024 at 00:00

[webapps] E-INSUARANCE v1.0 - Stored Cross Site Scripting (XSS)

E-INSUARANCE v1.0 - Stored Cross Site Scripting (XSS)
  • April 2nd 2024 at 00:00

[webapps] Gibbon LMS v26.0.00 - SSTI vulnerability

Gibbon LMS v26.0.00 - SSTI vulnerability
  • April 2nd 2024 at 00:00

[webapps] Smart School 6.4.1 - SQL Injection

Smart School 6.4.1 - SQL Injection
  • April 2nd 2024 at 00:00

[webapps] Employee Management System 1.0 - `txtfullname` and `txtphone` SQL Injection

Employee Management System 1.0 - `txtfullname` and `txtphone` SQL Injection
  • April 2nd 2024 at 00:00

[webapps] Daily Habit Tracker 1.0 - SQL Injection

Daily Habit Tracker 1.0 - SQL Injection
  • April 2nd 2024 at 00:00

[local] ASUS Control Center Express 01.06.15 - Unquoted Service Path

ASUS Control Center Express 01.06.15 - Unquoted Service Path
  • April 2nd 2024 at 00:00

[webapps] Blood Bank v1.0 - Stored Cross Site Scripting (XSS)

Blood Bank v1.0 - Stored Cross Site Scripting (XSS)
  • April 2nd 2024 at 00:00

[webapps] OpenCart Core 4.0.2.3 - 'search' SQLi

OpenCart Core 4.0.2.3 - 'search' SQLi
  • April 2nd 2024 at 00:00

[webapps] FoF Pretty Mail 1.1.2 - Server Side Template Injection (SSTI)

FoF Pretty Mail 1.1.2 - Server Side Template Injection (SSTI)
  • April 2nd 2024 at 00:00

[local] Microsoft Windows Defender - Detection Mitigation Bypass TrojanWin32Powessere.G

Microsoft Windows Defender - Detection Mitigation Bypass TrojanWin32Powessere.G
  • April 2nd 2024 at 00:00

[local] Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation

Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation
  • April 2nd 2024 at 00:00

[local] Rapid7 nexpose - 'nexposeconsole' Unquoted Service Path

Rapid7 nexpose - 'nexposeconsole' Unquoted Service Path
  • April 2nd 2024 at 00:00

[webapps] Employee Management System 1.0 - `txtusername` and `txtpassword` SQL Injection (Admin Login)

Employee Management System 1.0 - `txtusername` and `txtpassword` SQL Injection (Admin Login)
  • April 2nd 2024 at 00:00
โŒ