Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:219754

📄 LuaJIT 2.1.1774638290 FFI Remote Code Execution / Lua Injection_PACKETSTORM:219754

This script is a LuaJIT exploitation tool that attempts to abuse the LuaJIT FFI Foreign Function Interface to execute system commands or arbitrary ...

N/A N/A PACKETSTORM
CRITICAL 9.9 PACKETSTORM:219776

📄 NocoBase 2.0.27 Sandbox Escape / Remote Code Execution_PACKETSTORM:219776

This code is a Metasploit Auxiliary module designed to exploit a remote code execution vulnerability in NocoBase versions 2.0.27 and below. It targ...

N/A N/A PACKETSTORM
HIGH 7 PACKETSTORM:219768

📄 Microsoft MMC (.MSC) File Execution Abuse Leading / Admin Creation_PACKETSTORM:219768

This Metasploit local Windows exploit module abuses the way Microsoft Management Console MMC processes specially crafted .msc files to achieve arbi...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219759

📄 MetInfo CMS 8.1 Shell Upload Mass Exploiter_PACKETSTORM:219759

This Python module is a mass exploitation framework designed to automate the testing and exploitation of multiple MetInfo CMS targets potentially a...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219760

📄 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760

This Python script is a full remote code execution exploit suite targeting a vulnerability in MetInfo CMS versions 8.1 and below. The flaw resides ...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:219769

📄 Microsoft SQL Server 2022/2025 Privilege Escalation_PACKETSTORM:219769

This Python script demonstrates a privilege escalation technique targeting Microsoft SQL Server, associated with CVE-2025-24999. The exploit abuses...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219709

📄 Langflow Remote Code Execution_PACKETSTORM:219709

The CSV Agent node in Langflow hardcodes allowdangerouscode=True, which automatically exposes the LangChains Python REPL tool pythonreplast. As a r...

N/A N/A PACKETSTORM
HIGH 8.5 PACKETSTORM:219704

📄 SocialEngine 7.8.0 Server-Side Request Forgery_PACKETSTORM:219704

SocialEngine versions 7.8.0 and below suffer from a blind server-side request forgery vulnerability. User input passed through the uri request para...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219705

📄 SocialEngine 7.8.0 SQL Injection_PACKETSTORM:219705

SocialEngine versions 7.8.0 and below suffer from a remote SQL injection vulnerability. User input passed through the text request parameter to the...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:219697

📄 Langflow 1.8.4 Traversal / Remote Code Execution_PACKETSTORM:219697

This Metasploit module targets a path traversal vulnerability in Langflow versions 1.8.4 and below that allows attackers to write arbitrary files o...

N/A N/A PACKETSTORM