Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:219772

📄 MISP 2.5.27 Workflow Engine Cross Site Scripting_PACKETSTORM:219772

This Metasploit auxiliary module targets a potential stored cross site scripting vulnerability in the MISP Workflow Engine. It is designed to inter...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219754

📄 LuaJIT 2.1.1774638290 FFI Remote Code Execution / Lua Injection_PACKETSTORM:219754

This script is a LuaJIT exploitation tool that attempts to abuse the LuaJIT FFI Foreign Function Interface to execute system commands or arbitrary ...

N/A N/A PACKETSTORM
CRITICAL 9.9 PACKETSTORM:219776

📄 NocoBase 2.0.27 Sandbox Escape / Remote Code Execution_PACKETSTORM:219776

This code is a Metasploit Auxiliary module designed to exploit a remote code execution vulnerability in NocoBase versions 2.0.27 and below. It targ...

N/A N/A PACKETSTORM
HIGH 7 PACKETSTORM:219768

📄 Microsoft MMC (.MSC) File Execution Abuse Leading / Admin Creation_PACKETSTORM:219768

This Metasploit local Windows exploit module abuses the way Microsoft Management Console MMC processes specially crafted .msc files to achieve arbi...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219759

📄 MetInfo CMS 8.1 Shell Upload Mass Exploiter_PACKETSTORM:219759

This Python module is a mass exploitation framework designed to automate the testing and exploitation of multiple MetInfo CMS targets potentially a...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219760

📄 MetInfo CMS 8.1 PHP Code Injection_PACKETSTORM:219760

This Python script is a full remote code execution exploit suite targeting a vulnerability in MetInfo CMS versions 8.1 and below. The flaw resides ...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:219769

📄 Microsoft SQL Server 2022/2025 Privilege Escalation_PACKETSTORM:219769

This Python script demonstrates a privilege escalation technique targeting Microsoft SQL Server, associated with CVE-2025-24999. The exploit abuses...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219709

📄 Langflow Remote Code Execution_PACKETSTORM:219709

The CSV Agent node in Langflow hardcodes allowdangerouscode=True, which automatically exposes the LangChains Python REPL tool pythonreplast. As a r...

N/A N/A PACKETSTORM
HIGH 8.5 PACKETSTORM:219704

📄 SocialEngine 7.8.0 Server-Side Request Forgery_PACKETSTORM:219704

SocialEngine versions 7.8.0 and below suffer from a blind server-side request forgery vulnerability. User input passed through the uri request para...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219705

📄 SocialEngine 7.8.0 SQL Injection_PACKETSTORM:219705

SocialEngine versions 7.8.0 and below suffer from a remote SQL injection vulnerability. User input passed through the text request parameter to the...

N/A N/A PACKETSTORM