Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 PACKETSTORM:223728

📄 Grav CMS Remote Code Execution_PACKETSTORM:223728

This Python exploit targets a vulnerability in Grav CMS versions prior to 2.0.0-beta.2 by abusing the administrative Direct Install plugin feature ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:223751

📄 NTLM Relay to Self (HTTP to LDAP) Post Exploitation_PACKETSTORM:223751

This Metasploit module performs an NTLM relay-to-self privilege escalation attack. It starts an HTTP-to-LDAP relay server on the compromised host, ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:223627

📄 CMSsiam 2 SQL Injection_PACKETSTORM:223627

CMSsiam version 2 suffers from a remote SQL injection vulnerability that allows for login bypass...

N/A N/A PACKETSTORM
HIGH 8.6 PACKETSTORM:223698

📄 Discuz! X5.0 Local File Inclusion_PACKETSTORM:223698

This is a Metasploit auxiliary module targeting a local file inclusion vulnerability in Discuz! X5.0...

N/A N/A PACKETSTORM
NONE PACKETSTORM:223619

📄 CMS SINDEHOTÉIS 1.2.4 Cross Site Request Forgery_PACKETSTORM:223619

CMS SINDEHOT�IS version 1.2.4 suffers from a cross site request forgery vulnerability...

N/A N/A PACKETSTORM
CRITICAL 9.4 PACKETSTORM:223657

📄 dedoc/scramble 0.13.2 Remote Code Execution_PACKETSTORM:223657

This is a Metasploit exploit module for CVE-2026-44262, an unauthenticated remote code execution vulnerability in the Laravel-based tool dedoc/scra...

N/A N/A PACKETSTORM
HIGH 8.6 PACKETSTORM:223682

📄 Discuz! X5.0 Chained Remote Code Execution_PACKETSTORM:223682

This Metasploit module uses race condition and local file inclusion vulnerabilities in Discuz! X5.0 in order to achieve remote code execution...

N/A N/A PACKETSTORM
NONE PACKETSTORM:223562

📄 Bloodbank CMS 1.0 SQL Injection_PACKETSTORM:223562

Bloodbank CMS version 1.0 suffers from a remote SQL injection vulnerability...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:223516

📄 Apache Flink Kubernetes Operator 1.14.0 Server-Side Request Forgery_PACKETSTORM:223516

This is a Metasploit auxiliary module to demonstrate a service-side request forgery vulnerability in Apache Flink Kubernetes Operator version 1.14....

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:223514

📄 Apache 2.4.66 HTTP/2 mod_http2 Double-Free Denial of Service_PACKETSTORM:223514

This script is a multi-mode security tool that triggers a denial of service against Apache HTTP Server version 2.4.66 related to a double-free cond...

N/A N/A PACKETSTORM