Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.4 PACKETSTORM:212540

📄 YOURLS 1.8.2 CSRF / IDOR / Missing Authorization_PACKETSTORM:212540

YOURLS version 1.8.2 AJAX endpoint scanner that checks for cross site request forgery, insecure direct object reference, missing authorization, and...

N/A N/A PACKETSTORM
NONE PACKETSTORM:212532

📄 Coohom SaaS Cross Site Scripting_PACKETSTORM:212532

Coohoom SaaS is susceptible to a persistent cross site scripting vulnerability...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:212535

📄 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535

Cinnamon kotaemon version 0.11.0 zip bomb proof of concept denial of service exploit...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:212534

📄 Cacti 1.2.29 Remote Command Execution_PACKETSTORM:212534

Proof of concept exploit that demonstrates how authenticated users with access to Graph Templates in Cacti can abuse RRD invocation parameters to w...

N/A N/A PACKETSTORM
CRITICAL 10 PACKETSTORM:212501

📄 Flask 3.0.0 Remote Code Execution_PACKETSTORM:212501

Flask version 3.0.0 suffers from multiple remote code execution vulnerabilities...

N/A N/A PACKETSTORM
CRITICAL 9.1 PACKETSTORM:212499

📄 WordPress AI Buddy 1.8.5 Shell Upload_PACKETSTORM:212499

WordPress AI Buddy plugin versions 1.8.5 and below remote shell upload exploit that leverages the REST API attachment functionality...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:212497

📄 Microsoft Windows File Explorer NTLM Hash Disclosure_PACKETSTORM:212497

Microsoft Windows File Explorer in Windows 10 and 11 contains a critical NTLM hash disclosure vulnerability that allows attackers to capture user a...

N/A N/A PACKETSTORM
HIGH 7.8 PACKETSTORM:212502

📄 Visual Studio 1.39.0 Remote Debugger_PACKETSTORM:212502

Visual Studio versions 1.30.0 through 1.39.0 had a remote debugger enabled by default that could cause multiple security issues. Code included to s...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:212503

📄 Apache bRPC Stack Overflow_PACKETSTORM:212503

A critical stack overflow vulnerability in Apache bRPC's JSON parser allows remote attackers to crash servers via specially crafted deep recursive ...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:212378

📄 phpMyAdmin 5.0.0 SQL Injection_PACKETSTORM:212378

phpMyAdmin version 5.0.0 suffers from a remote SQL injection vulnerability...

N/A N/A PACKETSTORM