Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 PACKETSTORM:221269

📄 CPanel/WHM CRLF Injection / Authentication Bypass / Remote Code Execution_PACKETSTORM:221269

This Metasploit module exploits CVE-2026-41940, a CRLF injection in cPanel/WHMs cpsrvd daemon that allows unauthenticated remote code execution as ...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:221161

📄 HUSTOJ Zip Slip / Remote Code Execution_PACKETSTORM:221161

This Metasploit module demonstrates a remote code execution vulnerability in HUSTOJ. A user with administrative privileges can abuse the problemimp...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:221082

📄 WordPress Supsystic Contact Form 1.7.36 Server-Side Template Injection_PACKETSTORM:221082

Proof of concept code execution exploit for a server-side template injection vulnerability in WordPress Supsystic Contact Form plugin versions 1.7....

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:221081

📄 ePati Antikor NGFW 2.0.1301 Authentication Bypass_PACKETSTORM:221081

ePati Antikor NGFW version 2.0.1301 suffers from an authentication bypass vulnerability...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:221080

📄 PJPROJECT 2.16 Buffer Overflow_PACKETSTORM:221080

PJPROJECT versions 2.16 and below suffer from a heap buffer overflow vulnerability...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:221085

📄 Dolibarr ERP/CRM Authenticated Code Injection_PACKETSTORM:221085

Dolibarr ERP/CRM versions prior to 17.0.1 allow remote code execution by an authenticated user who has access to the Website module...

N/A N/A PACKETSTORM
NONE PACKETSTORM:221083

📄 Apache HertzBeat 1.8.0 Remote Command Execution_PACKETSTORM:221083

Apache HertzBeat version 1.8.0 suffers from a remote command execution vulnerability via the scriptCommand parameter in a monitoring template defin...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:221084

📄 GestioIP 3.5.7 Remote Command Execution_PACKETSTORM:221084

This Metasploit module exploits a command execution via file upload. If GestioIP is configured to use no authentication for admin account, no passw...

N/A N/A PACKETSTORM
NONE PACKETSTORM:220989

📄 Espanso 2.3.0 Shell Extension Arbitrary Command Execution_PACKETSTORM:220989

The Shell extension in Espanso version 2.3.0 allows arbitrary command execution. An attacker who can modify the match configuration file can inject...

N/A N/A PACKETSTORM
HIGH 7.8 PACKETSTORM:220960

📄 Glances 4.5.2 Command Injection_PACKETSTORM:220960

Glances version 4.5.2 suffers from a command injection vulnerability...

N/A N/A PACKETSTORM