Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:213135

📄 Lepton CMS 7.4.0 Cross Site Scripting / Code Execution_PACKETSTORM:213135

Lepton CMS version 7.4.0 has a vulnerability which allows for a persistent cross site scripting payload to escalate into PHP execution through the ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213132

📄 Institute Admission Software 2.5 Shell Upload_PACKETSTORM:213132

Institute Admission Software version 2.5 fails to properly validate and restrict uploaded files in the gallery upload functionality within the admi...

N/A N/A PACKETSTORM
MEDIUM 6.8 PACKETSTORM:213134

📄 Dahua TPC-AEBF5201 P2P Camera ToolsComplete Security Analysis Suite_PACKETSTORM:213134

This PHP proof-of-concept provides defensive tooling to analyze DH-P2P / Easy4IP behaviors observed during DFIR activities. It includes routines to...

N/A N/A PACKETSTORM
CRITICAL 10 PACKETSTORM:213133

📄 Cisco ISE API 3.2 Command Injection_PACKETSTORM:213133

Proof of concept exploit for a command injection vulnerability in Cisco ISE API version 3.2...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:213022

📄 Kubio AI Page Builder 2.5.1 PHP LFI Extractor Scanner_PACKETSTORM:213022

A local file inclusion vulnerability exists in the function kubiohybridthemeloadtemplate of the Kubio AI Page Builder plugin for WordPress versions...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213051

📄 Headlamp 0.38.0 Credential Reuse_PACKETSTORM:213051

A security issue was discovered in the in-cluster version of Headlamp where unauthenticated users may be able to reuse cached credentials to access...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:213002

📄 Kalmia CMS 0.2.0 User Enumeration_PACKETSTORM:213002

Proof of concept exploit that demonstrates a user enumeration vulnerability via the JWT authentication API on Kalmia CMS version 0.2.0...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:213032

📄 Laravel Pulse 1.3.1 Arbitrary Code Injection_PACKETSTORM:213032

Proof of concept exploit written in PHP for Laravel Pulse version 1.3.1. This version of Laravel Pulse suffers from an arbitrary code injection vul...

N/A N/A PACKETSTORM
HIGH 10 PACKETSTORM:213043

📄 Xiongmai XM530 IP Camera Hardcoded RTSP Credential Exposure_PACKETSTORM:213043

The GetStreamUri ONVIF endpoint in Xiongmai XM530-series IP cameras exposes RTSP URIs containing hardcoded credentials, enabling direct unauthorize...

N/A N/A PACKETSTORM
HIGH 10 PACKETSTORM:213001

📄 Juniper ScreenOS 6.2.0r15 Backdoor Scanner_PACKETSTORM:213001

Juniper ScreenOS version 6.2.0r15 SSH backdoor scanner written in PHP...

N/A N/A PACKETSTORM