Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 PACKETSTORM:215719

📄 Extensis Portfolio Manager 4.0.1 Shell Upload_PACKETSTORM:215719

This Metasploit module exploits multiple vulnerabilities in Extensis Portfolio Server to achieve remote code execution. It leverages CVE-2022-24251...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215641

📄 PopojiCMS 2.0.1 Code Injection_PACKETSTORM:215641

PopojiCMS version 2.0.1 remote PHP code injection proof of concept exploit...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:215642

📄 PPOM for WooCommerce 33.0.15 SQL Injection / Code Execution_PACKETSTORM:215642

This is an extensive exploit that leverages a remote SQL injection vulnerability in PPOM for WooCommerce version 33.0.15 to also achieve remote cod...

N/A N/A PACKETSTORM
CRITICAL 10 PACKETSTORM:215704

📄 ChurchCRM 6.8.0 Unauthenticated Remote Code Execution_PACKETSTORM:215704

This Metasploit module exploits an unauthenticated remote code execution vulnerability in the installation process of ChurchCRM versions 6.8.0 and ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215645

📄 Netgate pfSense Community Edition 2.7.2 / 2.8.0 Remote Code Execution_PACKETSTORM:215645

Netgate pfSense Community Edition versions 2.7.2 and 2.8.0 appear to suffer from multiple authenticated remote code execution vulnerabilities that ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215702

📄 eNet SMART HOME Server 2.3.1 Account Takeover_PACKETSTORM:215702

The eNet Smart Home system contains an authorization flaw in the resetUserPassword functionality that allows any authenticated low-privileged user ...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:215692

📄 mailcow: Dockerized Host Header Password Reset Poisoning_PACKETSTORM:215692

mailcow: dockerized versions prior to 2025-01a are vulnerable to Host header poisoning in the password reset workflow. The application incorrectly ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215699

📄 eNet SMART HOME Server 2.3.1 Default Credentials_PACKETSTORM:215699

The eNet Smart Home system ships with default credentials that remain active after installation and commissioning without enforcing a mandatory pas...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215644

📄 Precurio Intranet Portal 4.4 Cross Site Request Forgery / Shell Upload_PACKETSTORM:215644

Precurio Intranet Portal version 4.4 proof of concept cross site request forgery and remote shell upload exploit...

N/A N/A PACKETSTORM
NONE PACKETSTORM:215700

📄 eNet SMART HOME Server 2.3.1 Arbitrary User Deletion_PACKETSTORM:215700

The eNet Smart Home system contains an authorization weakness in the deleteUserAccount JSON-RPC method that permits any authenticated low-privilege...

N/A N/A PACKETSTORM