Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 PACKETSTORM:215529

📄 OpenSSL 3.x PKCS#12 PBMAC1 KeyLength Buffer Overflow_PACKETSTORM:215529

This proof of concept demonstrates a buffer overflow vulnerability in OpenSSL versions 3.4 to 3.6 related to improper handling of the PBMAC1 keyLen...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215528

📄 Online Grievance Redressal Software 2.6 Cross Site Scripting_PACKETSTORM:215528

Online Grievance Redressal Software version 2.6 suffers from a cross site scripting vulnerability...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:215533

📄 Oracle Database Server 9.2.0.5 SQL Injection_PACKETSTORM:215533

Oracle Database Server version 9.2.0.5 proof of concept remote SQL injection exploit that leverages SYS.DBMSCDCSUBSCRIBE.ACTIVATESUBSCRIPTION and m...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215589

📄 Xerte Online Toolkits 3.14 Upload Image Shell Upload_PACKETSTORM:215589

This Metasploit module exploits the user template file import functions unrestricted file upload in Xerte Online Toolkits versions 3.14 and earlier...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215591

📄 FreeBSD rtsold/rtsol DNSSL Command Injection_PACKETSTORM:215591

This Metasploit module exploits a command injection vulnerability CVE-2025-14558 in FreeBSD's rtsol8 and rtsold8 programs. These programs do not va...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:215525

📄 PandoraFMS Netflow 7.0.777.10 Command Injection_PACKETSTORM:215525

PandoraFMS versions 7.0.774 through 7.0.777.10 contain an authenticated command injection vulnerability in the Netflow configuration component. An ...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:215578

📄 SolarWinds Web Help Desk Unauthenticated Remote Code Execution_PACKETSTORM:215578

This Metasploit module exploits an access control bypass vulnerability CVE-2025-40536 and an unsafe deserialization vulnerability CVE-2025-40551 to...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215590

📄 Xerte Online Toolkits 3.14 Template Import Shell Upload_PACKETSTORM:215590

This Metasploit module exploits an authentication bypass allowing arbitrary file upload in Xerte Online Toolkits versions 3.14 and earlier to uploa...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215521

📄 JUNG Smart Visu Server 1.1.1050 Remote Server Shutdown_PACKETSTORM:215521

JUNG Smart Visu Server version 1.1.1050 suffers from a denial of service vulnerability. An unauthenticated attacker can reboot or shutdown the serv...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:215519

📄 GNU Inetutils Telnet Authentication Bypass_PACKETSTORM:215519

A Metasploit module has been released that exploit telnetd. The telnetd service from GNU InetUtils is vulnerable to authentication bypass, tracked ...

N/A N/A PACKETSTORM