
Archived
CVE-2025-46171
Writeup of a Denial of Service vulnerability in the vBulletin 3.8.7 friends list.
database-securitymisconfigurationpenetration-testing+2

Writeup of a Denial of Service vulnerability in the vBulletin 3.8.7 friends list.

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session

EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…


React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the…

TM4WEB Vulnerability - CVE-2022-35497