


An issue was discovered on TP-Link TL-WR840N. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…


LiquidPoll – Advanced Polls for Creators and Brands <= 3.3.68 - Missing Authorization via activate_addon

Content Mask < 1.8.4 - Subscriber+ Arbitrary Options Update

PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise

LifterLMS <= 3.34.5 - Unauthenticated Options Import

Nexxt Router 15.03.06.60 Authentication Bypass and Remote Command Execution

CVE-2023-21173 Exploit - Remote Code Execution in SQL Server 2022

Brute Force on Supravizio BPM 10.1.2

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker…


bypass SAML authentication on GitHub Enterprise

Golang implementation of CVE-2019-17662 TinyVNC Arbitrary File Read leading to Authentication Bypass Exploit

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240

Admin account registration in Online Student Rate System

web2py/web2py @ e94946d