Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:212770

📄 dotCMS 24.04.24 Vulnerability Scanner_PACKETSTORM:212770

dotCMS version 24.04.24 advanced exploitation python scanning script that looks for local file inclusion, data exposure, SQL injection, and more...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:212774

📄 Eramba GRC 3.19.1 Command Injection_PACKETSTORM:212774

Eramba GRC platform version 3.19.1 proof of concept command injection exploit...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:212772

📄 EduplusCampus Student Portal 3.0.1 Insecure Direct Object Reference_PACKETSTORM:212772

EduplusCampus Student Portal version 3.0.1 suffers from an insecure direct object reference vulnerability...

N/A N/A PACKETSTORM
MEDIUM 5.3 PACKETSTORM:212771

📄 Drupal 11.x-dev Information Disclosure_PACKETSTORM:212771

Proof of concept script demonstrating a full path disclosure issue in Drupal version 11.x-dev...

N/A N/A PACKETSTORM
CRITICAL 9.6 PACKETSTORM:212777

📄 Grav CMS Twig SSTI Authenticated Sandbox Bypass Remote Code Execution_PACKETSTORM:212777

This Metasploit module exploits a Server-Side Template Injection SSTI vulnerability CVE-2025-66294 in Grav CMS that allows bypassing the Twig sandb...

N/A N/A PACKETSTORM
NONE PACKETSTORM:212775

📄 FlatPress 1.3 Shell Upload_PACKETSTORM:212775

FlatPress version 1.3 remote shell upload proof of concept exploit that leverages a cross site request forgery vulnerability...

N/A N/A PACKETSTORM
HIGH 7.2 PACKETSTORM:212773

📄 Elementor Website Builder SQL Injection_PACKETSTORM:212773

Proof of concept exploit that demonstrates a remote SQL injection vulnerability in Elementor Website Builder versions prior 3.12.2...

N/A N/A PACKETSTORM
CRITICAL 9.1 PACKETSTORM:212729

📄 Magento SessionReaper Remote Code Execution_PACKETSTORM:212729

This Metasploit module exploits CVE-2025-54236 SessionReaper, a critical vulnerability in Magento/Adobe Commerce that allows unauthenticated remote...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:212722

📄 Casdoor 2.95.0 Directory Traversal_PACKETSTORM:212722

Casdoor version 2.95.0 directory traversal proof of concept exploit...

N/A N/A PACKETSTORM
HIGH 10 PACKETSTORM:212721

📄 Broadcom Wi-Fi Firmware Out-Of-Bounds Write_PACKETSTORM:212721

Broadcom Wi-Fi firmware remote code execution exploit via an out-of-bounds write in the RRM Neighbor Report Handler...

N/A N/A PACKETSTORM