BigBlueButton versions 2.2.29 and below suffer from a meeting access code brute forcing vulnerability.
7779a47f90e53f789a2fbce3072e0d2ff2ac04320c70d8126d32c0cd38ef8a28
House Rental version 1.0 remote SQL injection exploit that leverages the keywords variable.
f3ce405357239bc159864db3af6456bd0791342c989bbfdf3d252560b427b3d3
This Metasploit module exploits an authenticated PHP code injection vulnerability found in openmediavault versions before 4.1.36 and 5.x versions before 5.5.12 inclusive in the "sortfield" POST parameter of the rpc.php page, because "json_encode_safe()" is not used in config/databasebackend.inc. Successful exploitation grants attackers the ability to execute arbitrary commands on the underlying operating system as root.
e0e5ffa0c0727fd8caae8d1a6288e302aebc6906241ff1131429f2abbcdbe8a1
This Metasploit module uses the Kong admin API to create a route and a serverless function plugin that is associated with the route. The plugin runs Lua code and is used to run a system command using os.execute(). After execution the route is deleted, which also deletes the plugin.
4bafd791ffc69e6f0e7e5e659d5843334eaeb9b206ab4512782cccf29ffe011a
This Metasploit module exploits WordPress Simple File List plugin versions prior to 4.2.3, which allows remote unauthenticated attackers to upload files within a controlled list of extensions. However, the rename function does not conform to the file extension restrictions, thus allowing arbitrary PHP code to be uploaded first as a png then renamed to php and executed.
c76d8f741d62e082e4021197c4f997d2888355186e9e04b1278f52540744b1fa
Ubuntu Security Notice 4644-1 - It was discovered that igraph mishandled certain malformed XML. An attacker could use this vulnerability to cause a denial of service.
36b45e5bfb54b57372c5e59ba133db2f7997fdeb4b4be4e54951e5f434ce0131
SyncBreeze version 10.0.28 suffers from a remote buffer overflow vulnerability.
21147b01f84dbcd01dd7401e1fa1618def57364c73f6c87de1e4deda21699dd9
osCommerce version 2.3.4.1 suffers from a persistent cross site scripting vulnerability.
3a2d13a1bea10737d2fffae795bbf8e8e1456bee046f30ed0b0fc07162a20926
Wondershare Driver Install Service Help version 10.7.1.321 suffers from an unquoted service path vulnerability.
22e81b9e302abbc514142b60342851f9f20aea48f363575022e6b4d599358ec4