Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 PACKETSTORM:218979

📄 Kiuwan SAST 2.8.2412.0 Improper Enforcement_PACKETSTORM:218979

It was found out that a user is still able to login at the Kiuwan WebUI via SSO, even if the Kiuwan mapped account has been disabled in the user se...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218892

📄 CMS Sense 2.0 Cross Site Scripting_PACKETSTORM:218892

CMS Sense version 2.0 suffers from a cross site scripting vulnerability...

N/A N/A PACKETSTORM
MEDIUM 4.9 PACKETSTORM:218881

📄 Twig Sandbox Bypass / XXE / Remote Code Execution / LFI_PACKETSTORM:218881

Research describing a critical vulnerability that exists in the October CMS Twig sandbox Safe Mode that allows authenticated users with template ed...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218912

📄 WebRemoteControl Unauthenticated Remote Filesystem Access_PACKETSTORM:218912

WebRemoteControl suffers from an unauthenticated remote filesystem access vulnerability. This proof of concept exploit lets you browse directory co...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218911

📄 WebRemoteControl Unauthenticated Remote Code Execution_PACKETSTORM:218911

WebRemoteControl suffers from an unauthenticated remote code execution vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218909

📄 Selenium Grid/Selenoid Unauthenticated Remote Code Execution_PACKETSTORM:218909

Selenium Grid and Selenoid expose a WebDriver API that allows creating browser sessions with arbitrary capabilities. When deployed without authenti...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218859

📄 Pachno 1.0.6 Privilege Escalation_PACKETSTORM:218859

The authorization check in the runSwitchUser action in Pachno version 1.0.6 evaluates the expression !canSaveConfiguration && !hasCookie'originalus...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218861

📄 Pachno 1.0.6 FileCache Deserialization Remote Code Execution_PACKETSTORM:218861

Pachno version 1.0.6 uses the unserialize function on the contents of cache files stored under PACHNOPATH/cache/ during the framework bootstrap seq...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218854

📄 Pachno 1.0.6 Cross Site Scripting_PACKETSTORM:218854

Pachno version 1.0.6 suffers from persistent cross site scripting vulnerabilities...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218855

📄 Pachno 1.0.6 Open Redirection_PACKETSTORM:218855

Pachno version 1.0.6 suffers from an open redirection vulnerability. Input passed via the returnto GET/POST parameter to the login endpoint is not ...

N/A N/A PACKETSTORM