Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:214907

πŸ“„ mPDF 8.1.0 Server-Side Request Forgery / Local File Disclosure / DoS_PACKETSTORM:214907

mPDF version 8.1.0 is vulnerable to multiple security issues related to unsafe handling of external resources, file paths, and image content during...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:214948

πŸ“„ Blesta 5.13.1 2Checkout PHP Object Injection_PACKETSTORM:214948

Blesta versions 3.0.0 through 5.13.1 suffer from a 2Checkout PHP object injection vulnerability. The vulnerabilities exist because user input passe...

N/A N/A PACKETSTORM
NONE PACKETSTORM:214888

πŸ“„ Microsoft Windows 11 Build 10.0.27898.1000 Advanced Admin Protection Bypass_PACKETSTORM:214888

This enhanced proof of concept demonstrates an advanced method for bypassing Windows Administrator Protection by manipulating registry hives using ...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:214808

πŸ“„ Chromium Memory Corruption Trigger Simulation_PACKETSTORM:214808

This is a theoretical trigger simulation for a Chromium-class vulnerability associated with memory corruption scenarios commonly affecting the V8 J...

N/A N/A PACKETSTORM
HIGH 9 PACKETSTORM:214834

πŸ“„ LimeSurvey 5.2.4 Remote Code Execution_PACKETSTORM:214834

Proof of concept exploit for LimeSurvey version 5.2.4 that loads a malicious PHP plugin and executes a reverse shell...

N/A N/A PACKETSTORM
NONE PACKETSTORM:214818

πŸ“„ Flask-Uploads 0.2.1 Path Traversal / Arbitrary File Write_PACKETSTORM:214818

Flask-Uploads versions 0.2.1 and below Metasploit module that exploits a path traversal vulnerability to achieve an arbitrary file write...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:214849

πŸ“„ Casdoor 2.283.0 Cross Site Request Forgery_PACKETSTORM:214849

Casdoor version 2.283.0 suffers from a cross site request forgery vulnerability. Related CVE number: CVE-2023-34927...

N/A N/A PACKETSTORM
NONE PACKETSTORM:214803

πŸ“„ Podinfo 6.10.0 Cross Site Scripting_PACKETSTORM:214803

Podinfo versions 6.10.0 and below suffer from a cross site scripting vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:214762

πŸ“„ Gibbon 14.0.01 Frame Injection_PACKETSTORM:214762

Frame injection vulnerabilities exist in Gibbon version 14.0.01. These vulnerabilities allow remote attackers to inject arbitrary HTML frames into ...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:214780

πŸ“„ Mailpit 1.28.1 Cross Site WebSocket Hijacking_PACKETSTORM:214780

A cross site websocket hijacking vulnerability exists in Mailpit versions 1.28.1 and below. The vulnerability allows remote attackers to intercept ...

N/A N/A PACKETSTORM