Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:213051

📄 Headlamp 0.38.0 Credential Reuse_PACKETSTORM:213051

A security issue was discovered in the in-cluster version of Headlamp where unauthenticated users may be able to reuse cached credentials to access...

N/A N/A PACKETSTORM
MEDIUM 6.5 PACKETSTORM:213002

📄 Kalmia CMS 0.2.0 User Enumeration_PACKETSTORM:213002

Proof of concept exploit that demonstrates a user enumeration vulnerability via the JWT authentication API on Kalmia CMS version 0.2.0...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:213032

📄 Laravel Pulse 1.3.1 Arbitrary Code Injection_PACKETSTORM:213032

Proof of concept exploit written in PHP for Laravel Pulse version 1.3.1. This version of Laravel Pulse suffers from an arbitrary code injection vul...

N/A N/A PACKETSTORM
HIGH 10 PACKETSTORM:213043

📄 Xiongmai XM530 IP Camera Hardcoded RTSP Credential Exposure_PACKETSTORM:213043

The GetStreamUri ONVIF endpoint in Xiongmai XM530-series IP cameras exposes RTSP URIs containing hardcoded credentials, enabling direct unauthorize...

N/A N/A PACKETSTORM
HIGH 10 PACKETSTORM:213001

📄 Juniper ScreenOS 6.2.0r15 Backdoor Scanner_PACKETSTORM:213001

Juniper ScreenOS version 6.2.0r15 SSH backdoor scanner written in PHP...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:213036

📄 Mantis Bug Tracker 2.3.0 Remote Code Execution_PACKETSTORM:213036

Mantis Bug Tracker version 2.3.0 unauthenticated remote code execution exploit that chains together two vulnerabilities. The exploit resets the adm...

N/A N/A PACKETSTORM
HIGH 10 PACKETSTORM:213044

📄 Xiongmai XM530 IP Camera ONVIF Complete Authentication Bypass_PACKETSTORM:213044

There is a complete authentication bypass in the ONVIF implementation of Xiongmai XM530-series IP cameras that allows unauthenticated remote access...

N/A N/A PACKETSTORM
NONE PACKETSTORM:213025

📄 AVAST Antivirus 25.11 Unquoted Service Path_PACKETSTORM:213025

AVAST Antivirus version 25.11 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code wi...

N/A N/A PACKETSTORM
MEDIUM 4.8 PACKETSTORM:213014

📄 Keras 2.15 Insecure Deserialization_PACKETSTORM:213014

Keras version 2.15 insecure deserialization proof of concept exploit. A security issue in certain versions of Keras allows attackers to craft a mal...

N/A N/A PACKETSTORM
CRITICAL 9.8 PACKETSTORM:213029

📄 Langflow 1.3.0 Remote Code Execution_PACKETSTORM:213029

A critical remote code execution vulnerability exists in Langflow that allows unauthenticated attackers to execute arbitrary system commands via th...

N/A N/A PACKETSTORM