docPrint Pro 8.0 - SEH Buffer Overflow
|
|
2019-09-16
|
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
|
|
2019-09-16
|
AppXSvc - Privilege Escalation
|
|
2019-09-16
|
Inteno IOPSYS Gateway - Improper Access Restrictions
|
|
2019-09-16
|
Windows NTFS - Privileged File Access Enumeration
|
|
2019-09-16
|
College-Management-System 1.2 - Authentication Bypass
|
|
2019-09-14
|
Ticket-Booking 1.4 - Authentication Bypass
|
|
2019-09-14
|
LimeSurvey 3.17.13 - Cross-Site Scripting
|
|
2019-09-13
|
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
|
|
2019-09-13
|
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
|
|
2019-09-13
|
Folder Lock 7.7.9 - Denial of Service
|
|
2019-09-13
|
Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processing TTF Fonts
|
|
2019-09-12
|
Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
|
|
2019-09-12
|
eWON Flexy - Authentication Bypass
|
|
2019-09-11
|
AVCON6 systems management platform - OGNL Remote Command Execution
|
|
2019-09-11
|
Windows 10 - UAC Protection Bypass Via Windows Store (WSReset.exe) and Registry (Metasploit)
|
|
2019-09-10
|
Windows 10 - UAC Protection Bypass Via Windows Store (WSReset.exe) (Metasploit)
|
|
2019-09-10
|
October CMS - Upload Protection Bypass Code Execution (Metasploit)
|
|
2019-09-10
|
LibreNMS - Collectd Command Injection (Metasploit)
|
|
2019-09-10
|
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
|
|
2019-09-10
|
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
|
|
2019-09-10
|
WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
|
|
2019-09-10
|
Dolibarr ERP-CRM 10.0.1 - SQL Injection
|
|
2019-09-09
|
WordPress Plugin Sell Downloads 1.0.86 - Cross-Site Scripting
|
|
2019-09-09
|
Rifatron Intelligent Digital Security System - 'animate.cgi' Stream Disclosure
|
|
2019-09-09
|
Online Appointment - SQL Injection
|
|
2019-09-09
|
Enigma NMS 65.0.0 - SQL Injection
|
|
2019-09-09
|
Enigma NMS 65.0.0 - OS Command Injection
|
|
2019-09-09
|
Enigma NMS 65.0.0 - Cross-Site Request Forgery
|
|
2019-09-09
|
Dolibarr ERP-CRM 10.0.1 - 'elemid' SQL Injection
|
|
2019-09-09
|
Wordpress 5.2.3 - Cross-Site Host Modification
|
|
2019-09-09
|
FusionPBX 4.4.8 - Remote Code Execution
|
|
2019-09-06
|
Inventory Webapp - 'itemquery' SQL injection
|
|
2019-09-06
|
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Remote Code Execution
|
|
2019-09-06
|
AwindInc SNMP Service - Command Injection (Metasploit)
|
|
2019-09-05
|
Linux/x86 - TCP Reverse Shell 127.0.0.1 Nullbyte Free Shellcode
|
|
2019-09-05
|
DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
|
|
2019-09-04
|
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
|
|
2019-09-04
|
FileThingie 2.5.7 - Arbitrary File Upload
|
|
2019-09-03
|
Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command Execution (Metasploit)
|
|
2019-09-03
|
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
|
|
2019-09-03
|
Cisco UCS Director - default scpuser password (Metasploit)
|
|
2019-09-03
|
ptrace - Sudo Token Privilege Escalation (Metasploit)
|
|
2019-09-03
|
ktsuss 1.4 - suid Privilege Escalation (Metasploit)
|
|
2019-09-03
|
Craft CMS 2.7.9/3.2.5 - Information Disclosure
|
|
2019-09-02
|
Kaseya VSA agent 9.5 - Privilege Escalation
|
|
2019-09-02
|
Alkacon OpenCMS 10.5.x - Local File inclusion
|
|
2019-09-02
|
Alkacon OpenCMS 10.5.x - Cross-Site Scripting (2)
|
|
2019-09-02
|
Alkacon OpenCMS 10.5.x - Cross-Site Scripting
|
|
2019-09-02
|
IntelBras TELEFONE IP TIP200/200 LITE 60.61.75.15 - Arbitrary File Read
|
|
2019-09-02
|
Wordpress Plugin Event Tickets 4.10.7.1 - CSV Injection
|
|
2019-09-02
|
ChaosPro 3.1 - SEH Buffer Overflow
|
|
2019-09-02
|
ChaosPro 2.1 - SEH Buffer Overflow
|
|
2019-09-02
|
ChaosPro 2.0 - SEH Buffer Overflow
|
|
2019-09-02
|
Opencart 3.x - Cross-Site Scripting
|
|
2019-09-02
|
Cisco Email Security Appliance (IronPort) C160 - 'Host' Header Injection
|
|
2019-09-02
|
VX Search Enterprise 10.4.16 - 'User-Agent' Denial of Service
|
|
2019-08-30
|
WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting
|
|
2019-08-30
|
YouPHPTube 7.4 - Remote Code Execution
|
|
2019-08-30
|
DomainMod 4.13 - Cross-Site Scripting
|
|
2019-08-30
|
Sentrifugo 3.2 - Persistent Cross-Site Scripting
|
|
2019-08-30
|
Sentrifugo 3.2 - File Upload Restriction Bypass
|
|
2019-08-30
|
Asus Precision TouchPad 11.0.0.25 - Denial of Service
|
|
2019-08-30
|
Canon PRINT 2.5.5 - Information Disclosure
|
|
2019-08-30
|
QEMU - Denial of Service
|
|
2019-08-30
|
Easy MP3 Downloader 4.7.8.8 - 'Unlock Code' Denial of Service
|
|
2019-08-30
|
SQL Server Password Changer 1.90 - Denial of Service
|
|
2019-08-30
|
Sony PlayStation Vita (PS Vita) - How to find savedata exploits
|
|
2019-08-30
|
Webkit JSC: JIT - Uninitialized Variable Access in ArgumentsEliminationPhase::transform
|
|
2019-08-29
|
PilusCart 1.4.1 - Local File Disclosure
|
|
2019-08-29
|
Jobberbase 2.0 - 'subscribe' SQL Injection
|
|
2019-08-29
|
Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities
|
|
2019-08-28
|
WordPress Plugin GoURL.io < 1.4.14 - File Upload
|
|
2019-08-28
|
Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
|
|
2019-08-28
|
SQLiteManager 1.2.0 / 1.2.4 - Blind SQL Injection
|
|
2019-08-28
|
Outlook Password Recovery 2.10 - Denial of Service
|
|
2019-08-28
|
Windows 10 - SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
|
|
2019-08-27
|
Tableau - XML External Entity
|
|
2019-08-27
|
Exim 4.87 / 4.91 - Local Privilege Escalation (Metasploit)
|
|
2019-08-26
|
openITCOCKPIT 3.6.1-2 - Cross-Site Request Forgery
|
|
2019-08-26
|
WordPress Plugin UserPro 4.9.32 - Cross-Site Scripting
|
|
2019-08-26
|
WordPress Plugin Import Export WordPress Users 1.3.1 - CSV Injection
|
|
2019-08-26
|
LSoft ListServ < 16.5-2018a - Cross-Site Scripting
|
|
2019-08-26
|
Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal
|
|
2019-08-23
|
LibreOffice < 6.2 Macro - Python Code Execution (Metasploit)
|
|
2019-08-21
|
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure (metasploit)
|
|
2019-08-21
|
SilverSHielD 6.x - Local Privilege Escalation
|
|
2019-08-20
|
Linux/MIPS64 - Reverse Shell Shellcode (157 bytes)
|
|
2019-08-20
|
WordPress Plugin 2.2.1 - Cross-Site Request Forgery
|
|
2019-08-20
|
YouPHPTube 7.2 - 'userCreate.json.php' SQL Injection
|
|
2019-08-19
|
Webmin 1.920 - Remote Code Execution
|
|
2019-08-19
|
Linux/x86_64 - AVX2 XOR Decoder + execve("/bin/sh") Shellcode (62 bytes)
|
|
2019-08-19
|
Linux/x86_64 - Reverse Shell (/bin/sh) with Configurable Password Shellcode (120 bytes)
|
|
2019-08-19
|
Linux/x86_64 - Bind Shell (/bin/sh) with Configurable Password Shellcode (129 bytes)
|
|
2019-08-19
|
Neo Billing 3.5 - Persistent Cross-Site Scripting
|
|
2019-08-19
|
FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure
|
|
2019-08-19
|
FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit)
|
|
2019-08-19
|
Kimai 2 - Persistent Cross-Site Scripting
|
|
2019-08-19
|
RAR Password Recovery 1.80 - 'User Name and Registration Code' Denial of Service
|
|
2019-08-19
|
Web Wiz Forums 12.01 - 'PF' SQL Injection
|
|
2019-08-16
|
Integria IMS 5.0.86 - Arbitrary File Upload
|
|
2019-08-16
|
GetGo Download Manager 6.2.2.3300 - Denial of Service
|
|
2019-08-16
|
Joomla! component com_jsjobs 1.2.6 - Arbitrary File Deletion
|
|
2019-08-16
|
EyesOfNetwork 5.1 - Authenticated Remote Command Execution
|
|
2019-08-16
|
Adobe Acrobat Reader DC for Windows - Double Free due to Malformed JP2 Stream
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - free() of Uninitialized Pointer due to Malformed JBIG2Globals Stream
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed JP2 Stream
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - Heap-Based Memory Corruption due to Malformed TTF Font
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow in CoolType.dll
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed Font Stream
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - Static Buffer Overflow due to Malformed Font Stream
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow While Processing Malformed PDF
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Stream
|
|
2019-08-15
|
Adobe Acrobat Reader DC for Windows - Heap-Based Out-of-Bounds read due to Malformed JP2 Stream
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in FixSbitSubTableFormat1
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Heap Corruption in MakeFormat12MergedGlyphList
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in WriteTableFromStructure
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Heap Corruption in ReadAllocFormat12CharGlyphMapList
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Heap Corruption in FixSbitSubTables
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Double Free in MergeFormat12Cmap / MakeFormat12MergedGlyphList
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in GetGlyphIdx
|
|
2019-08-15
|
Microsoft Font Subsetting - DLL Returning a Dangling Pointer via MergeFontPackage
|
|
2019-08-15
|
Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FDArray in Type 1 Fonts
|
|
2019-08-15
|
Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Font load/store Operators
|
|
2019-08-15
|
Microsoft Windows Text Services Framework MSCTF - Multiple Vulnerabilities
|
|
2019-08-15
|
NSKeyedUnarchiver - Info Leak in Decoding SGBigUTF8String
|
|
2019-08-15
|
Agent Tesla Botnet - Arbitrary Code Execution (Metasploit)
|
|
2019-08-15
|
ManageEngine opManager 12.3.150 - Authenticated Code Execution
|
|
2019-08-15
|
ABC2MTEX 1.6.1 - Command Line Stack Overflow
|
|
2019-08-15
|
Microsoft Windows 10 AppXSvc Deployment Service - Arbitrary File Deletion
|
|
2019-08-15
|
TortoiseSVN 1.12.1 - Remote Code Execution
|
|
2019-08-15
|
WordPress Plugin Download Manager 2.5 - Cross-Site Request Forgery
|
|
2019-08-15
|
D-Link DIR-600M - Authentication Bypass (Metasploit)
|
|
2019-08-15
|
Joomla! Component JS Jobs (com_jsjobs) 1.2.5 - 'customfields.php' SQL Injection
|
|
2019-08-15
|
Windows PowerShell - Unsanitized Filename Command Execution
|
|
2019-08-15
|
SugarCRM Enterprise 9.0.0 - Cross-Site Scripting
|
|
2019-08-15
|
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated OS Command Injection Bind Shell
|
|
2019-08-15
|
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated Configuration Download
|
|
2019-08-15
|
Sony PlayStation Vita - The First F00D Exploit
|
|
2019-08-13
|
Azorult Botnet - SQL Injection
|
|
2019-08-13
|
Agent Tesla Botnet - Arbitrary Code Execution
|
|
2019-08-13
|
Linux/x86 - Multiple In-Memory Modules (Prompt + Privilege Restore + Break Chroot Jail + Backdoor) + Signature Evasion Shellcode
|
|
2019-08-13
|
Linux/x86 - execve("/bin/sh") + tolower() Shellcode
|
|
2019-08-13
|
Linux/Tru64 alpha - execve(/bin/sh) Shellcode (108 bytes)
|
|
2019-08-13
|
Steam Windows Client - Local Privilege Escalation
|
|
2019-08-13
|
WebKit - UXSS via XSLT and Nested Document Replacements
|
|
2019-08-12
|
Linux - Use-After-Free Reads in show_numa_stats()
|
|
2019-08-12
|
VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow
|
|
2019-08-12
|
Joomla! Component JS Jobs (com_jsjobs) 1.2.5 - 'cities.php' SQL Injection
|
|
2019-08-12
|
Ghidra (Linux) 9.0.4 - .gar Arbitrary Code Execution
|
|
2019-08-12
|
Webmin 1.920 - Unauthenticated Remote Code Execution (Metasploit)
|
|
2019-08-12
|
ManageEngine OpManager 12.4x - Unauthenticated Remote Command Execution (Metasploit)
|
|
2019-08-12
|
ManageEngine Application Manager 14.2 - Privilege Escalation / Remote Command Execution (Metasploit)
|
|
2019-08-12
|
ManageEngine OpManager 12.4x - Privilege Escalation / Remote Command Execution (Metasploit)
|
|
2019-08-12
|
osTicket 1.12 - Persistent Cross-Site Scripting
|
|
2019-08-12
|
osTicket 1.12 - Formula Injection
|
|
2019-08-12
|
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
|
|
2019-08-12
|
Joomla! Component JS Support Ticket (com_jssupportticket) 1.1.6 - 'ticket.php' Arbitrary File Deletion
|
|
2019-08-12
|
Joomla! Component JS Support Ticket (com_jssupportticket) 1.1.6 - 'ticketreply.php' SQL Injection
|
|
2019-08-12
|
UNA 10.0.0 RC1 - 'polyglot.php' Persistent Cross-Site Scripting
|
|
2019-08-12
|
Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
|
|
2019-08-12
|
BSI Advance Hotel Booking System 2.0 - 'booking_details.php Persistent Cross-Site Scripting
|
|
2019-08-12
|
Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 - SQL Injection
|
|
2019-08-08
|
Adive Framework 2.0.7 - Cross-Site Request Forgery
|
|
2019-08-08
|
Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 - Arbitrary File Download
|
|
2019-08-08
|
Baldr Botnet Panel - Arbitrary Code Execution (Metasploit)
|
|
2019-08-08
|
Aptana Jaxer 1.0.3.4547 - Local File inclusion
|
|
2019-08-08
|
Daily Expense Manager 1.0 - Cross-Site Request Forgery (Delete Income)
|
|
2019-08-08
|
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
|
|
2019-08-08
|
Google Chrome 74.0.3729.0 / 76.0.3789.0 - Heap Use-After-Free in blink::PresentationAvailabilityState::UpdateAvailability
|
|
2019-08-07
|
WordPress Plugin JoomSport 3.3 - SQL Injection
|
|
2019-08-07
|
ARMBot Botnet - Arbitrary Code Execution
|
|
2019-08-05
|
Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
|
|
2019-08-05
|
macOS iMessage - Heap Overflow when Deserializing
|
|
2019-08-05
|
1CRM On-Premise Software 8.5.7 - Persistent Cross-Site Scripting
|
|
2019-08-02
|
Rest - Cafe and Restaurant Website CMS - 'slug' SQL Injection
|
|
2019-08-02
|
Sar2HTML 3.2.1 - Remote Command Execution
|
|
2019-08-02
|
Cisco Catalyst 3850 Series Device Manager - Cross-Site Request Forgery
|
|
2019-08-02
|
Linux/x86 - Force Reboot Shellcode (51 bytes)
|
|
2019-08-02
|
Linux/x86 - ASLR Disable Polymorphic Shellcode (107 bytes)
|
|
2019-08-02
|
Linux/x86 - chmod(/etc/shadow, 0666) Polymorphic Shellcode (53 bytes)
|
|
2019-08-02
|
WebIncorp ERP - SQL injection
|
|
2019-08-02
|
Ultimate Loan Manager 2.0 - Cross-Site Scripting
|
|
2019-08-02
|
Oracle Hyperion Planning 11.1.2.3 - XML External Entity
|
|
2019-07-31
|
Redis 4.x / 5.x - Unauthenticated Code Execution (Metasploit)
|
|
2019-07-31
|
iMessage - NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
|
|
2019-07-31
|
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
|
|
2019-07-31
|
iMessage - NSArray Deserialization can Invoke Subclass that does not Retain References
|
|
2019-07-31
|
macOS / iOS JavaScriptCore - JSValue Use-After-Free in ValueProfiles
|
|
2019-07-31
|
macOS / iOS JavaScriptCore - Loop-Invariant Code Motion (LICM) Leaves Object Property Access Unguarded
|
|
2019-07-31
|
macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances
|
|
2019-07-31
|
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
|
|
2019-07-31
|
phpMyFAQ 2.9.8 - Cross-Site Scripting (2)
|
|
2019-07-30
|
Trend Micro InterScan Messaging Security (Virtual Appliance) - 'Proxy.php' Remote Code Execution (Metasploit)
|
|
2019-07-30
|
Linux/x64 - Reverse (192.168.1.45:4444/TCP) Shell Shellcode (84 bytes)
|
|
2019-07-30
|
WP Database Backup < 5.2 - Remote Code Execution (Metasploit)
|
|
2019-07-29
|
Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Metasploit)
|
|
2019-07-29
|
GigToDo 1.3 - Cross-Site Scripting
|
|
2019-07-29
|
WordPress Theme Real Estate 2.8.9 - Cross-Site Scripting
|
|
2019-07-29
|
Linux/x86 - NOT +SHIFT-N+ XOR-N Encoded /bin/sh Shellcode
|
|
2019-07-29
|
WordPress Plugin Simple Membership < 3.8.5 - Cross-Site Request Forgery
|
|
2019-07-29
|
Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection
|
|
2019-07-26
|
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution (Metasploit)
|
|
2019-07-26
|
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution
|
|
2019-07-26
|
pdfresurrect 0.15 - Buffer Overflow
|
|
2019-07-26
|
Moodle Filepicker 3.5.2 - Server Side Request Forgery
|
|
2019-07-26
|
Microsoft Windows 7 build 7601 (x86) - Local Privilege Escalation
|
|
2019-07-26
|
Deepin Linux 15 - 'lastore-daemon' Local Privilege Escalation
|
|
2019-07-26
|
ASAN/SUID - Local Privilege Escalation
|
|
2019-07-26
|
Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (2)
|
|
2019-07-26
|
S-nail < 14.8.16 - Local Privilege Escalation
|
|
2019-07-26
|
VMware Workstation/Player < 12.5.5 - Local Privilege Escalation
|
|
2019-07-26
|
Linux Kernel 4.4.0-21 < 4.4.0-51 (Ubuntu 14.04/16.04 x86-64) - 'AF_PACKET' Race Condition Privilege Escalation
|
|
2019-07-26
|
Linux Kernel < 4.4.0/ < 4.8.0 (Ubuntu 14.04/16.04 / Linux Mint 17/18 / Zorin) - Local Privilege Escalation (KASLR / SMEP)
|
|
2019-07-26
|
Linux Kernel 4.8.0-34 < 4.8.0-45 (Ubuntu / Linux Mint) - Packet Socket Local Privilege Escalation
|
|
2019-07-26
|
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (polkit Method)
|
|
2019-07-26
|
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
|
|
2019-07-26
|
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (dbus Method)
|
|
2019-07-26
|
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
|
|
2019-07-26
|
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation
|
|
2019-07-26
|
WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
|
|
2019-07-25
|
Ovidentia 8.4.3 - SQL Injection
|
|
2019-07-25
|
Ovidentia 8.4.3 - Cross-Site Scripting
|
|
2019-07-25
|
Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
|
|
2019-07-24
|
Trend Micro Deep Discovery Inspector IDS - Security Bypass
|
|
2019-07-24
|
WordPress Plugin Hybrid Composer 1.4.6 - Improper Access Restrictions
|
|
2019-07-24
|
Cisco Wireless Controller 3.6.10E - Cross-Site Request Forgery
|
|
2019-07-24
|
NoviSmart CMS - SQL injection
|
|
2019-07-24
|
Linux/x86_64 - Wget Linux Enumeration Script Shellcode (155 Bytes)
|
|
2019-07-23
|
Axway SecureTransport 5 - Unauthenticated XML Injection
|
|
2019-07-22
|
Comtrend-AR-5310 - Restricted Shell Escape
|
|
2019-07-22
|
BACnet Stack 0.8.6 - Denial of Service
|
|
2019-07-22
|
Docker - Container Escape
|
|
2019-07-22
|
REDCap < 9.1.2 - Cross-Site Scripting
|
|
2019-07-19
|
Web Ofisi Firma 13 - 'oz' SQL Injection
|
|
2019-07-19
|
Web Ofisi Rent a Car 3 - 'klima' SQL Injection
|
|
2019-07-19
|
Web Ofisi Firma Rehberi 1 - 'il' SQL Injection
|
|
2019-07-19
|
Web Ofisi Emlak 3 - 'emlak_durumu' SQL Injection
|
|
2019-07-19
|
Web Ofisi Emlak 2 - 'ara' SQL Injection
|
|
2019-07-19
|
Web Ofisi Platinum E-Ticaret 5 - 'q' SQL Injection
|
|
2019-07-19
|
Web Ofisi E-Ticaret 3 - 'a' SQL Injection
|
|
2019-07-19
|
fuelCMS 1.4.1 - Remote Code Execution
|
|
2019-07-19
|
MAPLE Computer WBT SNMP Administrator 2.0.195.15 - Remote Buffer Overflow (EggHunter)
|
|
2019-07-19
|
WordPress Plugin OneSignal 1.17.5 - 'subdomain' Persistent Cross-Site Scripting
|
|
2019-07-18
|
Microsoft Windows 10 1903/1809 - RPCSS Activation Kernel Security Callback Privilege Escalation
|
|
2019-07-18
|
Windows - NtUserSetWindowFNID Win32k User Callback Privilege Escalation (Metasploit)
|
|
2019-07-17
|
Linux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME
|
|
2019-07-17
|
Oracle Siebel CRM 19.0 - Persistent Cross-Site Scripting
|
|
2019-07-17
|
WinMPG iPod Convert 3.0 - 'Register' Denial of Service
|
|
2019-07-17
|