Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 PACKETSTORM:219847

📄 pdf-image 2.0.0 Command Injection_PACKETSTORM:219847

In pdf-image version 2.0.0, a security issue allows OS command injection when untrusted input is passed to the PDFImage constructor and later proce...

N/A N/A PACKETSTORM
HIGH 7.8 PACKETSTORM:219845

📄 OSK Registry-Based Privilege Escalation / Symlink Attack_PACKETSTORM:219845

The provided code is a conceptual Windows privilege escalation exploit targeting the On-Screen Keyboard osk.exe and Accessibility AT registry infra...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219895

📄 WebADM 2.4.17-1 Password Hash Disclosure_PACKETSTORM:219895

WebADM version 2.4.17-1 contains an authenticated information disclosure vulnerability in the LDAP search functionality. The display parameter in s...

N/A N/A PACKETSTORM
NONE PACKETSTORM:219878

📄 Windows Cloud Files Tiering Engine Local Privilege Escalation_PACKETSTORM:219878

his Metasploit local exploit module models a Windows privilege escalation scenario involving Cloud Files, NTFS reparse points, named pipes, and ser...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219864

📄 thumbler 1.1.2 Command Injection_PACKETSTORM:219864

The thumbler package through version 1.1.2 contains a critical command injection vulnerability in the thumbnail function. User-supplied input param...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219850

📄 SQLite 3.50.1 winsqlite3.dll Heap Overflow_PACKETSTORM:219850

This Metasploit local exploit module targets a heap overflow vulnerability in winsqlite3.dll in SQLite versions prior to 3.50.2 on Windows systems....

N/A N/A PACKETSTORM
NONE PACKETSTORM:219875

📄 V8 BigInt String Conversion Stress Test Conceptual Sandbox_PACKETSTORM:219875

This is a V8 Sandbox Escape vulnerability in BigInt::Allocate where buffers are shuffled outside the sandbox. The vulnerability allows for writes o...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:219858

📄 textract 2.5.0 Command Injection_PACKETSTORM:219858

In textract version 2.5.0, a security vulnerability allows OS command injection when untrusted file paths are processed by the library...

N/A N/A PACKETSTORM
High 7.5 PACKETSTORM:219872

📄 Sequelize 6.37.7 SQL Injection_PACKETSTORM:219872

A remote SQL injection vulnerability exists Sequelize versions 6.37.7 and below in the JSON/JSONB where clause processing. When Sequelize parses a ...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:219877

📄 Vienna Assistant 1.2.542 macOS Privilege Escalation_PACKETSTORM:219877

A macOS helper service interface implemented via NSXPC was observed exposing methods that may allow privileged operations such as file writing and ...

N/A N/A PACKETSTORM