Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Voltage SecureMail Server Business Logic Bypass

0
Authored by TING Meng Yean Voltage SecureMail Server versions prior to 7.3.0.1 suffer from a business logic bypass vulnerability. advisories | CVE-2021-38130 Change Mirror Download Security Advisory======================================================================= ...

Shopmetrics Mystery Shopping Software Broken Access Control / XSS

0
Authored by A. Vodyasov, D. Zalmanov | Site sec-consult.com Shopmetrics Mystery Shopping Software SaaS platform versions before v21-11 suffer from broken access control and cross site scripting vulnerabilities. Change Mirror Download SEC...

Chrome storage::BlobBuilderFromStream Uninitializaed On-Stack Pointer

0
Authored by Google Security Research, Mark Brand Chrome suffers from making use of an uninitialized on-stack pointer in storage::BlobBuilderFromStream. advisories | CVE-2022-0115

Backdoor.Win32.Small.er Code Execution

0
Authored by malvuln | Site malvuln.com Backdoor.Win32.Small.er malware suffers from a code execution vulnerability. Change Mirror Download Discovery / credits: Malvuln - malvuln.com (c) 2022Original source: https://malvuln.com/advisory/9f11868c3beaa8e2c1f5c193f5888b85.txtContact: [email protected]: twitter.com/malvulnThreat: Backdoor.Win32.Small.erVulnerability: Unauthenticated Remote...

Hospital Management System 4.0 SQL Injection

0
Authored by nu11secur1ty Hospital Management System version 4.0 suffers from multiple remote SQL injection vulnerabilities. Original discovered of SQL injection in this version is attributed to Metin Yunus Kandemir in...

WordPress International SMS For Contact Form 7 Integration 1.2 XSS

0
Authored by Milad Karimi WordPress International SMS for Contact Form 7 Integration plugin version 1.2 suffers from a cross site scripting vulnerability. Change Mirror Download # Exploit Title: WordPress Plugin International Sms...

WordPress IP2Location Country Blocker 2.26.7 Cross Site Scripting

0
Authored by Ahmet Serkan Ari WordPress IP2Location Country Blocker plugin version 2.26.7 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: WordPress Plugin IP2Location Country Blocker 2.26.7...

FLAME II MODEM USB Unquoted Service Path

0
Authored by Ismael Nava FLAME II MODEM USB suffers from an unquoted service path vulnerability. Change Mirror Download # Exploit Title: FLAME II MODEM USB - Unquoted Service Path# Discovery by: Ismael...

Servisnet Tessa Authentication Bypass

0
Authored by AkkuS | Site metasploit.com This Metasploit module exploits an authentication bypass in Servisnet Tessa, triggered by add new sysadmin user. The app.js is publicly available which acts as...

Servisnet Tessa MQTT Credential Disclosure

0
Authored by AkkuS | Site metasploit.com This Metasploit module exploits an MQTT credential disclosure vulnerability in Servisnet Tessa. The app.js is publicly available which acts as the backend of the...