Pas d'actualité

Soutenez No Hack Me sur Tipeee

L'Actu de la veille

[webapps] XWiki Standard 14.10 - Remote Code Execution (RCE)
XWiki Standard 14.10 - Remote Code Execution (RCE)
https://www.exploit-db.com/exploits/52105
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[local] Solstice Pod 6.2 - API Session Key Extraction via API Endpoint
Solstice Pod 6.2 - API Session Key Extraction via API Endpoint
https://www.exploit-db.com/exploits/52104
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

L'Actu à J-2

[webapps] Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
https://www.exploit-db.com/exploits/52103
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
https://www.exploit-db.com/exploits/52102
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] Sonatype Nexus Repository 3.53.0-01 - Path Traversal
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
https://www.exploit-db.com/exploits/52101
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] CodeCanyon RISE CRM 3.7.0 - SQL Injection
CodeCanyon RISE CRM 3.7.0 - SQL Injection
https://www.exploit-db.com/exploits/52100
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] Litespeed Cache 6.5.0.1 - Authentication Bypass
Litespeed Cache 6.5.0.1 - Authentication Bypass
https://www.exploit-db.com/exploits/52099
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

L'Actu des jours précédents

[webapps] X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
https://www.exploit-db.com/exploits/52098
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
https://www.exploit-db.com/exploits/52097
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] MoziloCMS 3.0 - Remote Code Execution (RCE)
MoziloCMS 3.0 - Remote Code Execution (RCE)
https://www.exploit-db.com/exploits/52096
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[local] NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
https://www.exploit-db.com/exploits/52095
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] TeamPass 3.0.0.21 - SQL Injection
TeamPass 3.0.0.21 - SQL Injection
https://www.exploit-db.com/exploits/52094
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[remote] Aztech DSL5005EN Router - 'sysAccess.asp' Admin Password Change (Unauthenticated)
Aztech DSL5005EN Router - 'sysAccess.asp' Admin Password Change (Unauthenticated)
https://www.exploit-db.com/exploits/52093
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[remote] Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
https://www.exploit-db.com/exploits/52092
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] Jasmin Ransomware - SQL Injection Login Bypass
Jasmin Ransomware - SQL Injection Login Bypass
https://www.exploit-db.com/exploits/52091
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] FluxBB 1.5.11 - Stored Cross-Site Scripting (XSS)
FluxBB 1.5.11 - Stored Cross-Site Scripting (XSS)
https://www.exploit-db.com/exploits/52090
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] JUX Real Estate 3.4.0 - SQL Injection
JUX Real Estate 3.4.0 - SQL Injection
https://www.exploit-db.com/exploits/52089
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[local] VeeVPN 1.6.1 - Unquoted Service Path
VeeVPN 1.6.1 - Unquoted Service Path
https://www.exploit-db.com/exploits/52088
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] Gitea 1.24.0 - HTML Injection
Gitea 1.24.0 - HTML Injection
https://www.exploit-db.com/exploits/52087
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)
TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)
https://www.exploit-db.com/exploits/52086
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
https://www.exploit-db.com/exploits/52085
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

[webapps] Loaded Commerce 6.6 - Client-Side Template Injection(CSTI)
Loaded Commerce 6.6 - Client-Side Template Injection(CSTI)
https://www.exploit-db.com/exploits/52084
Partager : LinkedIn / Twitter / Facebook / View / View (lite)