qdPM 9.1 – Remote Code Execution (RCE) (Authenticated) (v2)
qdPM 9.1 – Remote Code Execution (RCE) (Authenticated) (v2)
OpenCart Newsletter module version 3.0.2.0 suffers from a remote blind SQL injection vulnerability.
Blockchain AltExchanger version 1.2.1 suffers from multiple remote SQL injection vulnerabilities.
Blockchain FiatExchanger version 2.2.1 suffers from a remote blind SQL injection vulnerability.
m1k1o’s Blog versions 1.3 and below suffer from an authenticated remote code execution vulnerability.
iTop versions prior to 2.7.5 authenticated remote command execution exploit.
iTop versions prior to 2.7.5 authenticated remote command execution exploit.
m1k1o’s Blog v.10 – Remote Code Execution (RCE) (Authenticated)
OpenCart v3.x Newsletter Module – Blind SQLi
Linux usbnet code tells minidrivers to unbind while netdev is still up, causing use-after-free conditions.