CVE-2020-8242
Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to...
Datarobot — Remote Code Execution
Posted by Michael Coers on Feb 18 Exploit Title: Datarobot -- Remote Code Execution Date: 9/28/2021 Vendor Homepage: https://www.datarobot.com Software Link: https://app.datarobot.com/ Version: TBD -...
MartFury Marketplace – Cross Site Scripting Vulnerability
Posted by info () vulnerability-lab com on Feb 18 Document Title: =============== MartFury Marketplace - Cross Site Scripting Vulnerability References (Source): ==================== https://www.vulnerability-lab.com/get_content.php?id=2282 Release Date:...
Vicidial v2.14-783a – (DB) SQL Injection Web Vulnerability
Posted by info () vulnerability-lab com on Feb 18 Document Title: =============== Vicidial v2.14-783a - (DB) SQL Injection Web Vulnerability References (Source): ==================== https://www.vulnerability-lab.com/get_content.php?id=2312 Release...
WordPress v5.9 – Reflected Cross Site Scripting Web Vulnerability
Posted by info () vulnerability-lab com on Feb 18 Document Title: =============== Wordpress v5.9 - Reflected Cross Site Scripting Web Vulnerability References (Source): ==================== https://www.vulnerability-lab.com/get_content.php?id=2316...
Car Portal Template – (Search) Persistent Web Vulnerability
Posted by info () vulnerability-lab com on Feb 18 Document Title: =============== Car Portal Template - (Search) Persistent Web Vulnerability References (Source): ==================== https://www.vulnerability-lab.com/get_content.php?id=2299 Release...
Multiple Vulnerabilities in Adobe Commerce and Magento Could Allow for Remote Code Execution
Multiple vulnerabilities have been discovered in Adobe Commerce and Magento Open Source, the most severe of which could allow for remote code execution. Adobe Commerce...
CVE-2020-8107
A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL...
ZDI-22-386: Parallels Desktop HDAudio Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code...
ZDI-22-385: Parallels Desktop Service Time-Of-Check Time-Of-Use Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code...