Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 PACKETSTORM:219933

📄 Microsoft Windows TBroker Registry Symlink Information Disclosure_PACKETSTORM:219933

This code demonstrates a proof of concept attack targeting Windows ATBroker Assistive Technology Broker to achieve sensitive information disclosure...

N/A N/A PACKETSTORM
HIGH 7.8 PACKETSTORM:219937

📄 Microsoft WinLogon Registry Deletion / Privilege Escalation_PACKETSTORM:219937

This code represents a highly destructive proof of concept targeting Windows WinLogon and Registry access control mechanisms to achieve privilege e...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219846

📄 OWASP CRS 3.3.9 / 4.25.x LTS / 4.8.x File Upload Bypass_PACKETSTORM:219846

This proof of concept demonstrating a weakness in some web applications protected by OWASP Core Rule Set CRS or similar filters, where file upload ...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219822

📄 node-tesseract-ocr 2.2.1 Command Injection_PACKETSTORM:219822

In node-tesseract-ocr version 2.2.1, a security vulnerability allows OS command injection when attacker-controlled image paths are passed to the OC...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219904

📄 SolarEdge 3.0-2021 Cross Site Request Forgery / OOB Injection_PACKETSTORM:219904

SolarEdge version 3.0-2021 suffers from a cross site request forgery vulnerability in the /solaredge-web/p/initClient that can lead to a remote com...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219847

📄 pdf-image 2.0.0 Command Injection_PACKETSTORM:219847

In pdf-image version 2.0.0, a security issue allows OS command injection when untrusted input is passed to the PDFImage constructor and later proce...

N/A N/A PACKETSTORM
HIGH 7.8 PACKETSTORM:219845

📄 OSK Registry-Based Privilege Escalation / Symlink Attack_PACKETSTORM:219845

The provided code is a conceptual Windows privilege escalation exploit targeting the On-Screen Keyboard osk.exe and Accessibility AT registry infra...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219895

📄 WebADM 2.4.17-1 Password Hash Disclosure_PACKETSTORM:219895

WebADM version 2.4.17-1 contains an authenticated information disclosure vulnerability in the LDAP search functionality. The display parameter in s...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219878

📄 Windows Cloud Files Tiering Engine Local Privilege Escalation_PACKETSTORM:219878

his Metasploit local exploit module models a Windows privilege escalation scenario involving Cloud Files, NTFS reparse points, named pipes, and ser...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219864

📄 thumbler 1.1.2 Command Injection_PACKETSTORM:219864

The thumbler package through version 1.1.2 contains a critical command injection vulnerability in the thumbnail function. User-supplied input param...

N/A N/A PACKETSTORM