header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Emerson PAC Machine Edition 9.80 Build 8695 – ‘TrapiServer’ Unquoted Service Path

A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.

Network Video Recorder NVR304-16EP – Reflected Cross-Site Scripting (XSS) (Unauthenticated)

A reflected cross-site scripting (XSS) vulnerability exists in Network Video Recorder NVR304-16EP, which allows an unauthenticated attacker to inject arbitrary web script or HTML via the 'LAPI/V1.0/System/Security/Login/' parameter.

ServiceNow – Username Enumeration

Victor Hanna (Trustwave SpiderLabs) discovered a username enumeration vulnerability in ServiceNow Orlando. An attacker can use this vulnerability to enumerate valid usernames by sending a POST request to the /api/now/v2/table/sys_user endpoint with a valid JSESSION, X-UserToken and CSRF Token. This can be used to further attack the system.

Simple Student Quarterly Result/Grade System 1.0 – SQLi Authentication Bypass

A SQL injection vulnerability exists in the Simple Student Quarterly Result/Grade System 1.0, due to improper sanitization of user-supplied input in the 'username' parameter of the 'Actions.php' script. An attacker can exploit this vulnerability to bypass authentication and gain access to the application.

Multi-Vendor Online Groceries Management System 1.0 – ‘id’ Blind SQL Injection

A blind SQL injection vulnerability exists in Multi-Vendor Online Groceries Management System 1.0, due to improper sanitization of user-supplied input to the 'id' parameter in the 'view_product.php' script. An attacker can leverage this vulnerability to execute arbitrary SQL commands on the underlying database, potentially resulting in the disclosure of sensitive information.

Recent Exploits: