This Metasploit module exploits an unauthenticated OVA file upload and path traversal in VMware vCenter Server to write a JSP payload to a web-accessible directory. Fixed versions are 6.5 Update…
bVPN version 2.5.1 suffers from an unquoted service path vulnerability.
Emerson Smart Wireless Gateway version 1420 4.6.59 suffers from a privilege escalation vulnerability.
Emerson Smart Wireless Gateway version 1420 4.6.59 suffers from a missing authentication vulnerability.
Froala version 3.2.6-1 suffers from persistent cross site scripting vulnerabilities.
FreeLAN version 2.2 suffers from an unquoted service path vulnerability.
Sandboxie Plus version 0.7.2 suffers from an unquoted service path vulnerability.
Golden FTP Server version 4.70 PASS buffer overflow exploit.
There is an out-of-bounds write vulnerability in WindowsCodecsRaw.dll in the COlympusE300LoadRaw::olympus_e300_load_raw function that can be triggered by parsing a crafted Olympus E300 raw image with Windows Imaging Component (WIC). The…
A remotely exploitable vulnerability exists within HPE System Insight Manager (SIM) version 7.6.x that can be leveraged by a remote unauthenticated attacker to execute code within the context of HPE…