Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 PACKETSTORM:222805

📄 Lyrion Music Server 9.2.0 metadata Persistent Cross Site Scripting_PACKETSTORM:222805

Lyrion Music Server version 9.2.0 stores media file metadata tags such as GENRE, ARTIST, and ALBUM exactly as written in the file and later renders...

N/A N/A PACKETSTORM
MEDIUM 6.1 PACKETSTORM:222802

📄 Lyrion Music Server 9.2.0 server.log Reflected Cross Site Scripting_PACKETSTORM:222802

Lyrion Music Server version 9.2.0 suffers from an unauthenticated reflected cross site scripting vulnerability through server.log endpoint abusing ...

N/A N/A PACKETSTORM
HIGH 7.3 PACKETSTORM:222760

📄 Craft CMS 5.9.5 Missing Authorization / Denial of Service_PACKETSTORM:222760

Craft CMS versions 5.9.5 and below suffer from a missing authorization vulnerability that can trigger an unwanted migration...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:222745

📄 WordPress Contest Gallery 28.1.4 SQL Injection_PACKETSTORM:222745

WordPress Contest Gallery plugin versions 28.1.4 and below suffer from a remote SQL injection vulnerability...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:222633

📄 WordPress ARMember Premium 7.3.1 Insecure Password Reset_PACKETSTORM:222633

WordPress ARMember Premium plugin versions 7.3.1 and below suffer from an insecure password reset mechanism that allows for administrative account ...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:222614

📄 MCPJam Inspector 1.4.2 Command Injection_PACKETSTORM:222614

This is an advanced Python proof of concept for CVE-2026-23744 demonstrating command injection through a vulnerable MCP API endpoint, leading to re...

N/A N/A PACKETSTORM
NONE PACKETSTORM:222620

📄 Gogs Git Rebase Argument Injection / Remote Code Execution_PACKETSTORM:222620

This Metasploit module exploits an argument injection vulnerability in the pull request merge flow of Gogs versions less than or equal to 0.14.2 an...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:222473

📄 WordPress OrderConvo 13.5 Path Traversal_PACKETSTORM:222473

Proof of concept exploit that demonstrates a path traversal vulnerability in WordPress OrderConvo plugin version 13.5...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:222477

📄 Samba SMB Printer Queue Command Injection / Remote Task Delivery_PACKETSTORM:222477

This Python script is a structured exploitation framework targeting Samba print services exposed over SMB port 445. It focuses on printer-share int...

N/A N/A PACKETSTORM
NONE PACKETSTORM:222526

📄 WebRemoteControl Unauthenticated Remote Filesystem Access_PACKETSTORM:222526

Proof of concept tool that demonstrates how WebRemoteControl suffers from unauthenticated remote filesystem access and potential remote code execut...

N/A N/A PACKETSTORM