Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 PACKETSTORM:219769

📄 Microsoft SQL Server 2022/2025 Privilege Escalation_PACKETSTORM:219769

This Python script demonstrates a privilege escalation technique targeting Microsoft SQL Server, associated with CVE-2025-24999. The exploit abuses...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219709

📄 Langflow Remote Code Execution_PACKETSTORM:219709

The CSV Agent node in Langflow hardcodes allowdangerouscode=True, which automatically exposes the LangChains Python REPL tool pythonreplast. As a r...

N/A N/A PACKETSTORM
HIGH 8.5 PACKETSTORM:219704

📄 SocialEngine 7.8.0 Server-Side Request Forgery_PACKETSTORM:219704

SocialEngine versions 7.8.0 and below suffer from a blind server-side request forgery vulnerability. User input passed through the uri request para...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219705

📄 SocialEngine 7.8.0 SQL Injection_PACKETSTORM:219705

SocialEngine versions 7.8.0 and below suffer from a remote SQL injection vulnerability. User input passed through the text request parameter to the...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:219697

📄 Langflow 1.8.4 Traversal / Remote Code Execution_PACKETSTORM:219697

This Metasploit module targets a path traversal vulnerability in Langflow versions 1.8.4 and below that allows attackers to write arbitrary files o...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:219691

📄 Keras 3.13.0 Malicious ML Model Server HDF5 Shape Bomb_PACKETSTORM:219691

This script is a Flask-based web server that distributes .keras machine learning model files, but it is designed in a malicious way for security re...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:219685

📄 Keras 3.13.0 HDF5 Shape Bomb Denial of Service_PACKETSTORM:219685

This script is a security research tool demonstrating a denial of service vulnerability in Keras model loading through malicious HDF5 shape bombs. ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219679

📄 Grav CMS 1.7.49.5 Shell Upload_PACKETSTORM:219679

This script targets a Grav CMS administrative panel by first authenticating, then checking version information to estimate vulnerability exposure. ...

N/A N/A PACKETSTORM
CRITICAL 9.4 PACKETSTORM:219677

📄 Ghost CMS 6.19.0 SQL Injection_PACKETSTORM:219677

This is a Metasploit auxiliary module targeting a blind, unauthenticated SQL injection vulnerability in the Ghost CMS Content API that affects vers...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219682

📄 Hoverfly 1.11.3 Remote Command Execution_PACKETSTORM:219682

This Python script is an exploitation tool targeting a vulnerable Hoverfly API endpoint, specifically the /api/v2/hoverfly/middleware functionality...

N/A N/A PACKETSTORM