Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 PACKETSTORM:213208

📄 Pi-hole 5.18.3 Remote Code Execution_PACKETSTORM:213208

This PHP script is an authenticated remote code execution exploit targeting Pi-hole's web admin interface. It requires valid administrator credenti...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213212

📄 HEUR.Backdoor.Win32.Poison.gen MVID-2025-0701 DLL Hijacking_PACKETSTORM:213212

HEUR.Backdoor.Win32.Poison.gen malware looks for and executes a x32-bit "WININET.dll" PE file in its current directory. Therefore, we can hijack th...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:213137

📄 libtransmission 2.93 Integer Overflow_PACKETSTORM:213137

libtransmission versions 2.93 and below suffer from multiple integer overflows. A remote attacker could create a specially crafted .torrent file wh...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:213140

📄 WordPress ACF 0.9.1.1 Remote Code Execution_PACKETSTORM:213140

This Metasploit module exploits an unauthenticated remote code execution vulnerability in the Advanced Custom Fields: Extended ACF Extended WordPre...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213136

📄 LibreNMS 24.9.1 Code Injection_PACKETSTORM:213136

LibreNMS version 24.9.1 suffers from a remote command execution vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213135

📄 Lepton CMS 7.4.0 Cross Site Scripting / Code Execution_PACKETSTORM:213135

Lepton CMS version 7.4.0 has a vulnerability which allows for a persistent cross site scripting payload to escalate into PHP execution through the ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213132

📄 Institute Admission Software 2.5 Shell Upload_PACKETSTORM:213132

Institute Admission Software version 2.5 fails to properly validate and restrict uploaded files in the gallery upload functionality within the admi...

N/A N/A PACKETSTORM
MEDIUM 6.8 PACKETSTORM:213134

📄 Dahua TPC-AEBF5201 P2P Camera ToolsComplete Security Analysis Suite_PACKETSTORM:213134

This PHP proof-of-concept provides defensive tooling to analyze DH-P2P / Easy4IP behaviors observed during DFIR activities. It includes routines to...

N/A N/A PACKETSTORM
CRITICAL 10 PACKETSTORM:213133

📄 Cisco ISE API 3.2 Command Injection_PACKETSTORM:213133

Proof of concept exploit for a command injection vulnerability in Cisco ISE API version 3.2...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:213022

📄 Kubio AI Page Builder 2.5.1 PHP LFI Extractor Scanner_PACKETSTORM:213022

A local file inclusion vulnerability exists in the function kubiohybridthemeloadtemplate of the Kubio AI Page Builder plugin for WordPress versions...

N/A N/A PACKETSTORM