Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 PACKETSTORM:221085

📄 Dolibarr ERP/CRM Authenticated Code Injection_PACKETSTORM:221085

Dolibarr ERP/CRM versions prior to 17.0.1 allow remote code execution by an authenticated user who has access to the Website module...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:221084

📄 GestioIP 3.5.7 Remote Command Execution_PACKETSTORM:221084

This Metasploit module exploits a command execution via file upload. If GestioIP is configured to use no authentication for admin account, no passw...

N/A N/A PACKETSTORM
NONE PACKETSTORM:221083

📄 Apache HertzBeat 1.8.0 Remote Command Execution_PACKETSTORM:221083

Apache HertzBeat version 1.8.0 suffers from a remote command execution vulnerability via the scriptCommand parameter in a monitoring template defin...

N/A N/A PACKETSTORM
NONE PACKETSTORM:220989

📄 Espanso 2.3.0 Shell Extension Arbitrary Command Execution_PACKETSTORM:220989

The Shell extension in Espanso version 2.3.0 allows arbitrary command execution. An attacker who can modify the match configuration file can inject...

N/A N/A PACKETSTORM
HIGH 7.8 PACKETSTORM:220960

📄 Glances 4.5.2 Command Injection_PACKETSTORM:220960

Glances version 4.5.2 suffers from a command injection vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:220962

📄 Event Booking Calendar 5.0 Cross Site Scripting_PACKETSTORM:220962

Event Booking Calendar version 5.0 suffers from a cross site scripting vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:220990

📄 Espanso 2.3.0 Shell and Script Extension Arbitrary Command Execution_PACKETSTORM:220990

The Shell and Script extensions in Espanso version 2.3.0 allow arbitrary command execution. No restart required. Config changes take effect immedia...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:220959

📄 Flowise Missing Authentication_PACKETSTORM:220959

Proof of concept for Flowise versions prior to 3.0.5 that suffer from a missing authentication vulnerability...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:220896

📄 WordPress Ninja Forms – File Uploads 3.3.26 Shell Upload / Traversal_PACKETSTORM:220896

WordPress Ninja Forms - File Uploads plugin versions 3.3.26 and below arbitrary file upload exploit...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:220776

📄 WordPress Madera 2.2.2 Local File Inclusion_PACKETSTORM:220776

This Python script exploits a local file inclusion vulnerability in the WordPress Madara theme. It interacts with the admin-ajax.php endpoint to lo...

N/A N/A PACKETSTORM