Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 PACKETSTORM:214602

πŸ“„ FreePBX Endpoint SQL Injection / Remote Code Execution_PACKETSTORM:214602

FreePBX is an open-source IP PBX management tool that provides a modern phone system for businesses that use VoIP to make and receive phone calls. ...

N/A N/A PACKETSTORM
MEDIUM 6.1 PACKETSTORM:214584

πŸ“„ MaNGOSWeb 4.0.6 SQL Injection_PACKETSTORM:214584

MaNGOSWeb version 4.0.6 remote SQL injection proof of concept exploit...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:214567

πŸ“„ Samsung libimagecodec.quram.so Buffer Overflow / Denial of Service_PACKETSTORM:214567

This proof of concept demonstrates a denial of service vulnerability in Samsung's libimagecodec.quram.so JPEG decoder. By crafting a structurally v...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:214573

πŸ“„ OpenSSL 3.x ASN.1 AES‑GCM Nonce Stack Corruption_PACKETSTORM:214573

This Metasploit auxiliary module generates a specially crafted CMS file encoded in DER format to test a stack-based buffer overflow vulnerability i...

N/A N/A PACKETSTORM
CRITICAL 9.3 PACKETSTORM:214537

πŸ“„ FreePBX Firmware Shell Upload_PACKETSTORM:214537

FreePBX versions prior to 16.0.44,16.0.92 and 17.0.6,17.0.23 are vulnerable to multiple CVEs, specifically CVE-2025-66039 and CVE-2025-61678, in th...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:214538

πŸ“„ Papermark 0.20.0 Path Traversal_PACKETSTORM:214538

Papermark version 0.20.0 suffers from an authenticated path traversal vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:214469

πŸ“„ AVideo 14.3.1 Cross Site Scripting_PACKETSTORM:214469

AVideo version 14.3.1 suffers from a cross site scripting vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:214487

πŸ“„ FreeBSD 15.x rtsold DNSSL Command Injection_PACKETSTORM:214487

This Metasploit module targets a command injection vulnerability in the FreeBSD rtsold daemon related to the handling of DNSSL DNS Search List opti...

N/A N/A PACKETSTORM
MEDIUM 5.5 PACKETSTORM:214496

πŸ“„ Qualcomm CVP Kernel Pointer Leak_PACKETSTORM:214496

The Qualcomm CVP driver exposes kernel pointers to userland by returning a hashed session ID derived from a kernel pointer using hash32ptr. This fu...

N/A N/A PACKETSTORM
NONE PACKETSTORM:214484

πŸ“„ Django Summernote 0.8.20.0 Unrestricted File Upload Scanner_PACKETSTORM:214484

This Metasploit Auxiliary Scanner module detects unrestricted file upload vulnerabilities in django-summernote. It targets misconfigurations where ...

N/A N/A PACKETSTORM