header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WordPress User Registration & Membership Plugin <= 4.1.1 - Unauthenticated Privilege Escalation

The WordPress User Registration & Membership Plugin version 4.1.1 and below allows unauthenticated users to escalate privileges. An attacker can exploit this vulnerability to gain unauthorized access and perform malicious actions.

Microsoft Windows 11 Pro 23H2 – Ancillary Function Driver for WinSock Privilege Escalation

The Ancillary Function Driver for WinSock in Microsoft Windows 11 Pro 23H2 allows local users to gain privileges via a crafted application, leading to privilege escalation. This vulnerability is identified as CVE-2024-38193.

InfluxDB OSS Operator Privilege Escalation via BusinessLogic Flaw

A business logic flaw in InfluxDB OSS allows users with a valid allAccess token to elevate their privileges to operator level by accessing current authorization tokens. This could lead to unauthorized access to the InfluxDB instance, compromising data confidentiality, integrity, and availability for users across different organizations.

Stored XSS Vulnerability in Nagios Log Server (Privilege Escalation to Admin)

A stored XSS vulnerability in Nagios Log Server 2024R1.3.1 allows a low-privileged user to inject malicious JavaScript into the 'email' field of their profile. When an administrator views the audit logs, the script executes, resulting in privilege escalation via unauthorized admin account creation. The vulnerability can be chained to achieve remote code execution (RCE) in certain configurations.

SureTriggers OttoKit Plugin 1.0.82 – Privilege Escalation

SureTriggers OttoKit Plugin version 1.0.82 and below is vulnerable to privilege escalation. By exploiting this vulnerability, an attacker can create an administrator account on the target WordPress site if the plugin is installed but uninitialized, and the site displays the REST API endpoint '/wp-json/sure-triggers/v1/automation/action'. The attacker can send a crafted HTTP POST request to achieve this.

Microsoft Windows 11 – Kernel Privilege Escalation

The exploit allows an attacker to escalate privileges on Microsoft Windows 11 systems by leveraging a vulnerability in the kernel. By manipulating IOCTL buffers and exploiting the SystemHandleInformation method, an attacker can gain elevated privileges on the target system. This vulnerability has been assigned CVE-2024-21338.

Recent Exploits: