Welcome to cxsecurity. enjoy
Bugtraq Stats

Yesterday: 0
Last month: 29
Current month: 10
Total: 41320

CVE database

Last Update: 40
Last month: 0
Current month: 0
Total CVE: 264299

Random comment
Online Complete - Blind Sql Injection Vulnerability
mrgfy
I tried the demo with "and false" with sqlmap. It took a while but it did work. Well done.

2025-01-07
High
Med.
2025-01-05
Med.
Low
Med.
Low
2025-01-02
Med.
Low
High
Med.
2024-12-28
Med.
Med.
Med.

The latest CVEs

Dorks

2024-10-23
CVE-2024-50066
In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix move_normal_pmd/retract_page_tables race In mremap(), move_page_tables() looks at the type of the PMD entry and the specified address range to figure out by which method the next chunk of page table entries should be moved. At that point, the mmap_lock is held in ...
CVE-2024-9829
The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Subscriber-level access a...
CVE-2024-9583
The RSS Aggregator ?? RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-leve...
CVE-2024-9947
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if th...
CVE-2024-10045
The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the process_actions function. This makes it possible for unauthenticated attackers to delete transients via a forged request granted they can trick a site admini...
CVE-2024-43924
Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7.
CVE-2024-9530
The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.0 via private templates. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the contents of templates that are private.
CVE-2024-31880
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.
CVE-2024-9927
The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.5. This is due to the improper implementation of allow_payment_without_login function. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to log in to WordPre...
CVE-2022-23861
Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution of arbitrary JS code. These fields can be leveraged to perform XSS attacks on legitimate users ...
2025-01-07
Med.
Ecommerce dynamic v1 - Sql Injection
intext:"Ecommerce-dynamic-website"
Razi
2025-01-05
Med.
TheDotStudios Web Application Union-based Sql Injection
TheDotStudios
Razi
Low
VULNERABILITY: Website Iranian goverment admin find and Automatic Bypassing 0day attacker
gov.ir admin login.php
E1.Coders
2025-01-02
Med.
WebSenor InfoTech - Blind Sql Injection Vulnerability
"Powered By: WebSenor InfoTech"
behrouz mansoori
2024-12-25
Med.
Ecommerce-PHP-kurniaramadhan-1.0- Sql Injection To XSS
"Powered by kurniaramadhan"
Maloy Roy Orko

Copyright 2025, cxsecurity.com

 

Back to Top