Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 PACKETSTORM:218663

πŸ“„ XiboCMS 3.3.4 Traversal / Code Execution_PACKETSTORM:218663

XiboCMS version 3.3.4 zip slip exploit that leverages path traversal and arbitrary file upload vulnerabilities to achieve code execution...

N/A N/A PACKETSTORM
HIGH 7.3 PACKETSTORM:218685

πŸ“„ NetBT e-Fatura 2024 Unquoted Service Path_PACKETSTORM:218685

NetBT e-Fatura 2024 suffers from an unquoted service path vulnerability...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:218678

πŸ“„ MyRewards 5.6.0 Missing Authorization_PACKETSTORM:218678

MyRewards – Loyalty Points and Rewards for WooCommerce versions 5.6.0 and below suffer from a missing authorization vulnerability that allows for p...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:218680

πŸ“„ SQLite 3.50.1 Heap Overflow_PACKETSTORM:218680

SQLite version 3.50.1 proof of concept that triggers a heap overflow in winsqlite3.dll via excessive aggregate functions...

N/A N/A PACKETSTORM
HIGH 7.6 PACKETSTORM:218681

πŸ“„ RomM Cross Site Scripting / File Upload_PACKETSTORM:218681

RomM versions prior to 4.4.1 chained vulnerabilities exploit that leverages file upload to achieve cross site scripting that then leverages csrf to...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218708

πŸ“„ Authentic 8 User Profile Insecure Direct Object Reference_PACKETSTORM:218708

Proof of concept exploit that demonstrates user data exposure via an insecure direct object reference and missing access control vulnerabilities in...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215963

πŸ“„ Soosyze CMS 2.0 Rate Limit Scanner_PACKETSTORM:215963

Soosyze CMS 2.0 suffers from a missing authentication rate‑limiting vulnerability CWE‑307 on the /user/login endpoint. The application allows unlim...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215967

πŸ“„ wlc SSL Certification Validation Bypass_PACKETSTORM:215967

This proof of concept demonstrates a security issue in wlc versions earlier than 1.17.0, where SSL/TLS certificate validation can be bypassed. By a...

N/A N/A PACKETSTORM
MEDIUM 5 PACKETSTORM:215965

πŸ“„ Sophos Web Virtual Appliance 3.7.0 Directory Traversal_PACKETSTORM:215965

Proof of concept exploit for an older vulnerability from 2013 where Sophos Web Virtual Appliance version 3.7.0 suffered from a directory traversal ...

N/A N/A PACKETSTORM
MEDIUM 5.3 PACKETSTORM:215956

πŸ“„ GnuTLS X.509 Name Constraints Denial of Service_PACKETSTORM:215956

This program is a multi-threaded test application created to analyze the impact of excessive X.509 Name Constraints processing in vulnerable versio...

N/A N/A PACKETSTORM