Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:220076

📄 Pizzafy Ecommerce System 1.0 SQL Injection_PACKETSTORM:220076

The admin/vieworder.php endpoint in Pizzafy Ecommerce System version 1.0 fails to properly sanitize the id GET parameter before passing it to a MyS...

N/A N/A PACKETSTORM
NONE PACKETSTORM:220040

📄 OpenNebula 6.10.0.1 Cross Site Scripting_PACKETSTORM:220040

OpenNebula version 6.10.0.1 suffers from multiple persistent cross site scripting vulnerabilities...

N/A N/A PACKETSTORM
NONE PACKETSTORM:220045

📄 ESP-RFID-Tool V2 PRO Traversal / XSS / Bypass / Enumeration_PACKETSTORM:220045

ESP-RFID-Tool V2 PRO suffers from bypass, cross site request forgery, cross site scripting, information leakage, path traversal, and multiple other...

N/A N/A PACKETSTORM
NONE PACKETSTORM:220075

📄 Pizzafy Ecommerce System 1.0 Shell Upload_PACKETSTORM:220075

The savemenu function in Pizzafy Ecommerce System version 1.0 handles image uploads for menu items without performing any file type validation. The...

N/A N/A PACKETSTORM
MEDIUM 5.1 PACKETSTORM:220047

📄 Coaching Management System 1.0 Cross Site Scripting_PACKETSTORM:220047

Coaching Management System version 1.0 suffers from a persistent cross site scripting vulnerability...

N/A N/A PACKETSTORM
MEDIUM 5.5 PACKETSTORM:219933

📄 Microsoft Windows TBroker Registry Symlink Information Disclosure_PACKETSTORM:219933

This code demonstrates a proof of concept attack targeting Windows ATBroker Assistive Technology Broker to achieve sensitive information disclosure...

N/A N/A PACKETSTORM
HIGH 7.8 PACKETSTORM:219937

📄 Microsoft WinLogon Registry Deletion / Privilege Escalation_PACKETSTORM:219937

This code represents a highly destructive proof of concept targeting Windows WinLogon and Registry access control mechanisms to achieve privilege e...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219846

📄 OWASP CRS 3.3.9 / 4.25.x LTS / 4.8.x File Upload Bypass_PACKETSTORM:219846

This proof of concept demonstrating a weakness in some web applications protected by OWASP Core Rule Set CRS or similar filters, where file upload ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219904

📄 SolarEdge 3.0-2021 Cross Site Request Forgery / OOB Injection_PACKETSTORM:219904

SolarEdge version 3.0-2021 suffers from a cross site request forgery vulnerability in the /solaredge-web/p/initClient that can lead to a remote com...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219847

📄 pdf-image 2.0.0 Command Injection_PACKETSTORM:219847

In pdf-image version 2.0.0, a security issue allows OS command injection when untrusted input is passed to the PDFImage constructor and later proce...

N/A N/A PACKETSTORM