Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.4 PACKETSTORM:218667

πŸ“„ WordPress Contact List 3.0.17 Cross Site Scripting_PACKETSTORM:218667

WordPress Contact List plugin versions 3.0.17 and below suffer from a persistent cross site scripting vulnerability...

N/A N/A PACKETSTORM
HIGH 8.1 PACKETSTORM:218672

πŸ“„ WordPress Tutor LMS 3.9.5 Insecure Direct Object Reference_PACKETSTORM:218672

WordPress Tutor LMS plugin versions 3.9.5 and below suffer from broken access control and insecure direct object reference vulnerabilities...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218663

πŸ“„ XiboCMS 3.3.4 Traversal / Code Execution_PACKETSTORM:218663

XiboCMS version 3.3.4 zip slip exploit that leverages path traversal and arbitrary file upload vulnerabilities to achieve code execution...

N/A N/A PACKETSTORM
HIGH 7.3 PACKETSTORM:218685

πŸ“„ NetBT e-Fatura 2024 Unquoted Service Path_PACKETSTORM:218685

NetBT e-Fatura 2024 suffers from an unquoted service path vulnerability...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:218678

πŸ“„ MyRewards 5.6.0 Missing Authorization_PACKETSTORM:218678

MyRewards – Loyalty Points and Rewards for WooCommerce versions 5.6.0 and below suffer from a missing authorization vulnerability that allows for p...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:218680

πŸ“„ SQLite 3.50.1 Heap Overflow_PACKETSTORM:218680

SQLite version 3.50.1 proof of concept that triggers a heap overflow in winsqlite3.dll via excessive aggregate functions...

N/A N/A PACKETSTORM
HIGH 7.6 PACKETSTORM:218681

πŸ“„ RomM Cross Site Scripting / File Upload_PACKETSTORM:218681

RomM versions prior to 4.4.1 chained vulnerabilities exploit that leverages file upload to achieve cross site scripting that then leverages csrf to...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218708

πŸ“„ Authentic 8 User Profile Insecure Direct Object Reference_PACKETSTORM:218708

Proof of concept exploit that demonstrates user data exposure via an insecure direct object reference and missing access control vulnerabilities in...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215963

πŸ“„ Soosyze CMS 2.0 Rate Limit Scanner_PACKETSTORM:215963

Soosyze CMS 2.0 suffers from a missing authentication rate‑limiting vulnerability CWE‑307 on the /user/login endpoint. The application allows unlim...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215967

πŸ“„ wlc SSL Certification Validation Bypass_PACKETSTORM:215967

This proof of concept demonstrates a security issue in wlc versions earlier than 1.17.0, where SSL/TLS certificate validation can be bypassed. By a...

N/A N/A PACKETSTORM