Windows Container Manager Service Arbitrary Object Directory Creation Privilege Escalation
Authored by James Forshaw, Google Security Research
The Container Manager Service creates an AppContainer process without impersonating the access token leading to privilege escalation.
advisories | CVE-2021-31169
OpenNetAdmin 18.1.1 Remote Command Execution
Authored by Alexandre Zanni
OpenNetAdmin versions 8.5.14 through 18.1.1 remote command execution exploit written in Ruby. This exploit was based on the original discovery of the issue by mattpascoe.
Change Mirror...
AWS CloudShell Terminal Escape Injection / Remote Code Execution
Authored by Google Security Research, Felix Wilhelm
The javascript terminal emulator used by AWS CloudShell handles certain terminal escape codes incorrectly. This can lead to remote code execution if attacker...
Mozilla Windows Maintenance Service Weak DACL
Authored by James Forshaw, Google Security Research
Mozilla's Firefox 85 for Windows has a weak DACL for domain networks.
advisories | CVE-2021-29951
SIS-REWE GO 7.5.0/12C Cross Site Scripting
Authored by S. Robertz, Florian Lienhart | Site sec-consult.com
SIS-REWE GO version 7.5.0/12C suffers from multiple cross site scripting vulnerabilities.
advisories | CVE-2021-31537
Change Mirror Download
SEC Consult Vulnerability Lab Security Advisory <...
ERPNext 12.18.0 / 13.0.0 SQL Injection
Authored by Stefan Pietsch, Nick Decker | Site trovent.io
ERPNext versions 12.18.0 and 13.0.0 suffer from an authenticated remote SQL injection vulnerability.
Change Mirror Download
# Trovent Security Advisory 2103-01 ######################################Authenticated SQL...
ERPNext 12.18.0 / 13.0.0 Cross Site Scripting
Authored by Stefan Pietsch, Nick Decker | Site trovent.io
ERPNext versions 12.18.0 and 13.0.0 suffer from reflective and persistent cross site scripting vulnerabilities.
Change Mirror Download
# Trovent Security Advisory 2103-02 ######################################Multiple...
Hexagon G!nius Auskunftsportal SQL Injection
Authored by Marcel Keiffenheim
Hexagon G!nius Auskunftsportal versions prior to 5.0.0.0 suffer from a remote SQL injection vulnerability.
advisories | CVE-2021-32051
Change Mirror Download
CVE-2021-32051 Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection...
Customer Relationship Management (CRM) System 1.0 SQL Injection
Authored by Richard Jones
Customer Relationship Management (CRM) System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Change Mirror Download
# Exploit Title: Customer Relationship Management...
Customer Relationship Management (CRM) System 1.0 Cross Site Scripting
Authored by Richard Jones
Customer Relationship Management (CRM) System version 1.0 suffers from a persistent cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: Customer Relationship Management (CRM) System 1.0 -...





