Security Vulnerabilities & Exploits

[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

The Exploit Database - 11 Září, 2026 - 02:00
CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)

The Exploit Database - 3 Září, 2026 - 02:00
FreePBX 17.0.2 - Remote Code Execution (RCE)

[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution

The Exploit Database - 3 Září, 2026 - 02:00
Metabase 0.61.0 - Authenticated Remote Code Execution

[dos] EVerest 2025.9.0 - DoS

The Exploit Database - 2 Září, 2026 - 02:00
EVerest 2025.9.0 - DoS

[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

The Exploit Database - 2 Září, 2026 - 02:00
Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

[webapps] PodcastGenerator 3.2.9 - Stored XSS

The Exploit Database - 2 Září, 2026 - 02:00
PodcastGenerator 3.2.9 - Stored XSS

[webapps] Ghost_CMS 6.19.0 - Remote Code Execution

The Exploit Database - 2 Září, 2026 - 02:00
Ghost_CMS 6.19.0 - Remote Code Execution

[webapps] Langflow 1.10.0 - RCE

The Exploit Database - 2 Září, 2026 - 02:00
Langflow 1.10.0 - RCE

[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities

The Exploit Database - 2 Září, 2026 - 02:00
Fullhan FH8626V100 - Multiple Vulnerabilities

[webapps] Marimo 0.20.4 - RCE

The Exploit Database - 2 Září, 2026 - 02:00
Marimo 0.20.4 - RCE

[webapps] Wolf CMS 0.8.3.1 - RCE v

The Exploit Database - 1 Září, 2026 - 02:00
Wolf CMS 0.8.3.1 - RCE v

[webapps] Payload CMS 3.72.0 - Blind SQL Injection

The Exploit Database - 1 Září, 2026 - 02:00
Payload CMS 3.72.0 - Blind SQL Injection

[webapps] Bludit CMS - Stored XSS

The Exploit Database - 1 Září, 2026 - 02:00
Bludit CMS - Stored XSS

[webapps] Grav CMS 2.0.7 - RCE

The Exploit Database - 1 Září, 2026 - 02:00
Grav CMS 2.0.7 - RCE

[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass

The Exploit Database - 1 Září, 2026 - 02:00
miniOrange 5.4.3 - Unauthenticated Auth Bypass

[webapps] EasyAppointments 1.5.1 - Blind SQL Injection

The Exploit Database - 1 Září, 2026 - 02:00
EasyAppointments 1.5.1 - Blind SQL Injection

[webapps] C-MOR 6.0104 - Directory Traversal

The Exploit Database - 31 Srpen, 2026 - 02:00
C-MOR 6.0104 - Directory Traversal

[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)

The Exploit Database - 31 Srpen, 2026 - 02:00
C-MOR 6.0104 - Cross-Site Scripting (XSS)

[webapps] CubeCart 6.7.4 - SQL injection

The Exploit Database - 31 Srpen, 2026 - 02:00
CubeCart 6.7.4 - SQL injection

[webapps] CubeCart 6.7.4 - SQL

The Exploit Database - 31 Srpen, 2026 - 02:00
CubeCart 6.7.4 - SQL
Syndikovat obsah