header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Chamilo LMS Multiple Cross-Site Scripting and CSRF Vulnerabilities

The vulnerabilities allow an attacker to gain control over valid user accounts in LMS, perform operations on their behalf, redirect them to malicious sites, steal their credentials, and more. Multiple reflected XSS requests can be exploited to execute arbitrary JavaScript code on the victim's browser. The CSRF vulnerabilities allow an attacker to perform unauthorized actions on behalf of a victim user.

Cross-Site Scripting Vulnerability in GRAND FlAGallery Plugin for WordPress

The GRAND FlAGallery plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Yahoo! CD Player ActiveX Control Remote Stack-Based Buffer Overflow Vulnerability

The Yahoo! CD Player ActiveX control ('YoPlyCd.dll') is prone to a remote stack-based buffer-overflow vulnerability because the application fails to properly bounds check user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.

Cross-site Scripting Vulnerability in Pet Listing

Pet Listing is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Cross-Site Scripting Vulnerability in Axis M10 Series Network Cameras

The Axis M10 Series Network Cameras are vulnerable to a cross-site scripting vulnerability due to inadequate sanitization of user-supplied data. This vulnerability allows an attacker to execute arbitrary script code in the browser of a victim user, potentially leading to the theft of authentication credentials and other malicious activities.

Remote Denial-of-Service Vulnerability in Linux Kernel

The Linux kernel is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause an out-of-memory error in certain Linux applications, resulting in denial-of-service conditions.

Recent Exploits: