This is a critical memory corruption vulnerability in any API backed by verify_crt(), including gnutls_x509_trust_list_verify_crt() and related routines in GnuTLS.
A bug in IonMonkeys type inference system when JIT compiling and entering a constructor function via on-stack replacement (OSR) allows the compilation of JITed functions that cause type confusions between…
This Metasploit module demonstrates that an unauthenticated attacker with network access to the Oracle Weblogic Server T3 interface can send a serialized object (weblogic.jms.common.StreamMessag eImpl) to the interface to execute…
This Metasploit module exploits a file upload vulnerability that allows for remote command execution in Showtime2 module versions 3.6.2 and below in CMS Made Simple (CMSMS). An authenticated user with…
Microsoft Visio 2016 16.0.4738.1000 – ‘Log in accounts’ Denial of Service
CMS Made Simple (CMSMS) Showtime2 – File Upload RCE (Metasploit)
Airbnb Clone Script – Multiple SQL Injection
Oracle Weblogic Server Deserialization RCE – Raw Object (Metasploit)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall 4.18.63 – Local File Inclusion
Fat Free CRM 0.19.0 – HTML Injection