LumisXP 16.1.x Cross Site Scripting
Authored by Rodolfo Tavares | Site tempest.com.br
LumisXP versions 15.0.x through 16.1.x suffer from a cross site scripting vulnerability in XsltResultControllerHtml.jsp.
advisories | CVE-2024-33326
Change Mirror Download
===============================LumisXP v15.0.x to v16.1.xAuthor: Rodolfo TavaresTempest...
WordPress Poll Maker 5.3.2 SQL Injection
Authored by tmrswrr
WordPress Poll Maker plugin version 5.3.2 suffers from a remote SQL injection vulnerability.
Change Mirror Download
# Exploit Title: WordPress Poll Maker Plugin SQL Injection # Date: 2024-07-11# Exploit...
LumisXP 16.1.x Hardcoded Credentials / IDOR
Authored by Rodolfo Tavares | Site tempest.com.br
LumisXP versions 15.0.x through 16.1.x have a hardcoded privileged identifier that allows attackers to bypass authentication and access internal pages and other sensitive...
WordPress Poll 2.3.6 SQL Injection
Authored by tmrswrr
WordPress Poll plugin version 2.3.6 suffers from a remote SQL injection vulnerability.
Change Mirror Download
# Exploit Title: WordPress Poll Plugin SQL Injection # Date: 2024-07-06# Exploit Author: tmrswrr#...
Ivanti EPM RecordGoodApp SQL Injection / Remote Code Execution
Authored by Christophe de la Fuente, James Horseman | Site metasploit.com
Ivanti Endpoint Manager (EPM) 2022 SU5 and prior versions are susceptible to an unauthenticated SQL injection vulnerability which can...
Microsoft SharePoint Remote Code Execution
Authored by testanull | Site github.com
This archive contains three proof of concepts exploit for multiple Microsoft SharePoint remote code execution vulnerabilities.
advisories | CVE-2024-38023, CVE-2024-38024, CVE-2024-38094
ESET NOD32 Antivirus 17.2.7.0 Unquoted Service Path
Authored by Milad Karimi
ESET NOD32 Antivirus version 17.2.7.0 suffers from an unquoted service path vulnerability.
Change Mirror Download
# Exploit Title: ESET NOD32 Antivirus 17.2.7.0 - Unquoted Service Path# Exploit Author:...
Progress WhatsUp Gold SetAdminPassword Privilege Escalation
Authored by Sina Kheirkhah | Site summoning.team
Progress WhatsUp Gold SetAdminPassword local privilege escalation proof of concept exploit.
advisories | CVE-2024-5009
Progress WhatsUp Gold GetFileWithoutZip Unauthenticated Remote Code Execution
Authored by Sina Kheirkhah | Site summoning.team
Progress WhatsUp Gold GetFileWithoutZip unauthenticated remote code execution proof of concept exploit.
advisories | CVE-2024-4885
Progress WhatsUp Gold WriteDatafile Unauthenticated Remote Code Execution
Authored by Sina Kheirkhah | Site summoning.team
Progress WhatsUp Gold WriteDatafile unauthenticated remote code execution proof of concept exploit.
advisories | CVE-2024-4883





