header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WibuKey Runtime 6.51 – ‘WkSvW32.exe’ Unquoted Service Path

The WibuKey Runtime version 6.51 is affected by an unquoted service path vulnerability. The service 'WkSvW32.exe' has an unquoted service path, which can be exploited by an attacker to escalate privileges and execute arbitrary code with elevated permissions. By placing a malicious executable with the same name in a higher-priority directory in the system's PATH environment variable, the attacker can trick the system into executing the malicious code instead of the legitimate service executable.

Intelbras Router RF 301K – ‘DNS Hijacking’ Cross-Site Request Forgery (CSRF)

This exploit allows an attacker to perform a Cross-Site Request Forgery (CSRF) attack on the Intelbras Router RF 301K. By submitting a specially crafted form, the attacker can change the router's DNS settings, redirecting traffic to a malicious DNS server.

Grav CMS 1.7.10 – Server-Side Template Injection (SSTI) (Authenticated)

This exploit allows an authenticated user to perform server-side template injection (SSTI) in Grav CMS 1.7.10. By creating a malicious page with a crafted template, an attacker can execute arbitrary code on the server.

Recent Exploits: