4images v1.7.11 – ‘Profile Image’ Stored Cross-Site Scripting
4images v1.7.11 – ‘Profile Image’ Stored Cross-Site Scripting
Mantis Bug Tracker 2.24.3 – ‘access’ SQL Injection
WordPress Core 5.2.2 – ‘post previews’ XSS
sar2html 3.2.1 – ‘plot’ Remote Code Execution
Easy CD & DVD Cover Creator 4.13 – Denial of Service (PoC)
MiniTool ShadowMaker 3.2 – ‘MTAgentService’ Unquoted Service Path
This archive contains all of the 225 exploits added to Packet Storm in December, 2020.
Complete comprehensive archive of all 1,949 exploits added to Packet Storm in 2020.
qdPM versions 9.1 and below suffer from an executeExport PHP object injection vulnerability.
Openpilot has a default SSH key that can allow attackers remote access if not changed. This script port scans and attempts to login to Openpilot SSH servers with the default…