MyBB Admin Notes plugin version 1.1 suffers from a cross site request forgery vulnerability.
This advisory documents proof of concept flows for manipulation the HTML tag injection vulnerability discovered in Signal Desktop. Versions affected include 1.7.1, 1.8.0, 1.9.0, 1.10.0, and 1.10.1.
This Metasploit module exploits a remote code execution vulnerability in the Struts Showcase app in the Struts 1 plugin example in Struts 2.3.x series. Remote code execution can be performed…
This Metasploit module exploits a vulnerability in Jenkins. An unsafe deserialization bug exists on the Jenkins, which allows remote arbitrary code execution via HTTP. Authentication is not required to exploit…
RS Authentication Manager versions prior to 8.3 P1 suffer from cross site scripting and XML external entity injection vulnerabilities.
SuperCom Online Shopping Ecommerce Cart 1 – Persistent Cross-Site scripting / Cross site request forgery / Authentication bypass
Linux < 4.16.9 / < 4.14.41 – 4-byte Infoleak via Uninitialized Struct Field in compat adjtimex Syscall
Apache Struts 2 – Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)
Powerlogic/Schneider Electric IONXXXX Series – Cross-Site Request Forgery
Jenkins CLI – HTTP Java Deserialization (Metasploit)