Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 PACKETSTORM:212924

πŸ“„ FastAPI‑Based Delivery Server Proof of Concept_PACKETSTORM:212924

This proof of concept demonstrates how legacy ActiveX objects in Internet Explorer can be invoked automatically when a crafted HTML payload is deli...

N/A N/A PACKETSTORM
NONE PACKETSTORM:212925

πŸ“„ HighPortal 12.x SQL Injection_PACKETSTORM:212925

HighPortal version 12.x remote SQL injection proof of concept exploit...

N/A N/A PACKETSTORM
NONE PACKETSTORM:212933

πŸ“„ Institute Admission Software 2.5 Insecure Direct Object Reference_PACKETSTORM:212933

Institute Admission Software version 2.5 suffers from an insecure direct object reference vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:212936

πŸ“„ ionCube Loader Wizard 14.4.0 Scanner_PACKETSTORM:212936

ionCube Loader Wizard version 2.34 scanner that look for the installation file and displays PHP info to gather more information about the target...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:212935

πŸ“„ Invoice Ninja 5.8.22 PHP Code Injection_PACKETSTORM:212935

Invoice Ninja version 5.8.22 remote proof of concept exploit for a PHP code injection vulnerability...

N/A N/A PACKETSTORM
CRITICAL 10 PACKETSTORM:212928

πŸ“„ WordPress GiveWP Donation 3.14.1 PHP Object Injection_PACKETSTORM:212928

WordPress GiveWP Donation Fundraising Platform version 3.14.1 suffers from a PHP code injection vulnerability. This script exploits a different vec...

N/A N/A PACKETSTORM
CRITICAL 9.6 PACKETSTORM:212868

πŸ“„ Grav CMS 1.7.49.5 Sandbox Bypass_PACKETSTORM:212868

This code is a standalone PHP proof of concept exploit targeting Grav CMS version 1.7.49.5 that demonstrates an authenticated remote code execution...

N/A N/A PACKETSTORM
NONE PACKETSTORM:212863

πŸ“„ WIX.com Cross Site Scripting_PACKETSTORM:212863

WIX.com appears to suffer from a cross site scripting vulnerability. The researcher contacted them months ago and they have ignored his report, so ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:212895

πŸ“„ Control Web Panel 0.9.8.1208 Command Injection_PACKETSTORM:212895

Control Web Panel versions 0.9.8.1208 and below suffer from an issue where user input passed via the key GET parameter to /admin/index.php when the...

N/A N/A PACKETSTORM
NONE PACKETSTORM:212893

πŸ“„ Bitrix24 25.100.300 Remote Code Execution_PACKETSTORM:212893

Bitrix24 versions 25.100.300 and below have a vulnerability that is located within the Translate Module, which allows users to upload and extract a...

N/A N/A PACKETSTORM