Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 PACKETSTORM:213984

📄 AVideo Notify.ffmpeg.json.php Unauthenticated Remote Code Execution_PACKETSTORM:213984

This Metasploit module exploits an unauthenticated remote code execution vulnerability in the AVideos notify.ffmpeg.json.php endpoint. The vulnerab...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213897

📄 Control Web Panel 0.9.8.1208 Remote Code Execution_PACKETSTORM:213897

Control Web Panel CWP versions less than or equal to 0.9.8.1208 are vulnerable to unauthenticated OS command injection. User input passed via the "...

N/A N/A PACKETSTORM
CRITICAL 9.9 PACKETSTORM:213896

📄 n8n Workflow Expression Remote Code Execution_PACKETSTORM:213896

This Metasploit module exploits a critical remote code execution vulnerability CVE-2025-68613 in the n8n workflow automation platform. The vulnerab...

N/A N/A PACKETSTORM
CRITICAL 9.3 PACKETSTORM:213735

📄 Web-Check Screenshot API Command Injection_PACKETSTORM:213735

This Metasploit module exploits a command injection vulnerability in Web-Check's /api/screenshot endpoint. The directChromiumScreenshot function us...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213714

📄 LibreChat MCP Remote Command Execution_PACKETSTORM:213714

LibreChat's Model Context Protocol MCP implementation contained a remote command execution vulnerability that allowed any authenticated user to exe...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213675

📄 Eptura Archibus Directory Traversal_PACKETSTORM:213675

In Eptura Archibus versions before version 2025.01, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to...

N/A N/A PACKETSTORM
HIGH 8.6 PACKETSTORM:213677

📄 Hustle Plugin 7.8.3 Hardcoded Credentials_PACKETSTORM:213677

Hustle plugin versions 7.8.3 and below contain hardcoded HubSpot API credentials in inc/providers/hubspot/hustle-hubspot-api.php...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:213630

📄 Prison Management System 1.0 Shell Upload_PACKETSTORM:213630

This Metasploit module exploits an unrestricted file upload vulnerability in Prison Management System version 1.0. An authenticated user can upload...

N/A N/A PACKETSTORM
CRITICAL 9 PACKETSTORM:213594

📄 Taiga Tribe_gig Authenticated Unserialize Remote Code Execution_PACKETSTORM:213594

This Metasploit module exploits an unserialization flaw by creating a userstory in a project...

N/A N/A PACKETSTORM
HIGH 7.5 PACKETSTORM:213574

📄 WordPress Quiz Maker 6.7.0.56 SQL Injection_PACKETSTORM:213574

WordPress Quiz Maker plugin versions 6.7.0.56 and below suffer from a remote SQL injection vulnerability...

N/A N/A PACKETSTORM