Backdoor.Win32.Agent.afq malware suffers from a directory traversal vulnerability.
>> CATEGORY: exploit
Release functionality on GitHub.com allows modification of assets within a release by any project collaborator. This can occur after the release is published, and without notification or audit logging accessible…
PFSense version 2.5.0 suffers from a persistent cross site scripting vulnerability.
Android suffers from an out-of-bounds write in the NFC stack when handling MIFARE Classic TLVs.
Montiorr version 1.7.6m suffers from a cross site scripting vulnerability via a file upload.
This Metasploit module exploits a pre-auth server-side request forgery (CVE-2021-21975) and post-auth file write (CVE-2021-21983) in VMware vRealize Operations Manager to leak admin creds and write/execute a JSP payload. CVE-2021-21975…
WordPress WPGraphQL plugin version 1.3.5 suffers from a denial of service vulnerability.
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests; however, that feature is disabled by default. In Druid versions prior to 0.20.1, an…
Kimai version 1.14 suffers from a CSV injection vulnerability.
Worm.Win32.Busan.k malware suffers from an insecure transit vulnerability.