Aller au contenu
Skip to CUSTOM_HTML-19
Skip to RECENT-POSTS-2
Skip to SEARCH-2
Skip to CUSTOM_HTML-2
Skip to RSS-5
Skip to RSS-4
Skip to BLOCK-2
Skip to META-2
Skip to LISTPACKAGES-2
Skip to CUSTOM_HTML-6
Skip to CUSTOM_HTML-17
Skip to CUSTOM_HTML-16
Skip to CUSTOM_HTML-11
Skip to CUSTOM_HTML-5
Skip to CUSTOM_HTML-7
Skip to CUSTOM_HTML-8
Skip to AKISMET_WIDGET-2
Skip to CUSTOM_HTML-9
Skip to TAG_CLOUD-2
Skip to ARCHIVES-2
Skip to CUSTOM_HTML-13
Skip to CUSTOM_HTML-18
Skip to CUSTOM_HTML-15
Attention à vos informations.
TNT Sécurité
Attention à vos informations.
Shrunk
Expand
Navigation Principale
Open
Contactez-moi
Page de maintenance
Section Privée
Open
Archives de l'Année
Link to Year Archives
2017
Link to Year Archives
2018
Link to Year Archives
2019
1
2
3
4
5
6
7
8
9
10
11
2 Articles archivés
12
TNT Hacking World
Articles récents
Comment installer SilverBullet Pro 1.5.8
Comment les Hackers utilisent OpenBullet 2 pour accéder vos comptes.
Comment installer/configurer OpenBullet 2
Comment les hackers créent des combo lists
Burp Suite Pro 2025
Microsoft Office Pro 2024 LTSC
Evil Portal pour envoyer un payload à un client.
Comment contourner Microsoft Defender et établir une session Meterpreter avec persistence.
Téléchargez le ISO de Windows 11
Office 2021 Pro LTSC
Search for:
Exploit Database
Common Vulnerability Database
CVE-2026-14494
29 août 2026
Critical Severity Description The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation when allowed_file_types is not configured. […]
CVE-2026-82364
29 août 2026
Low Severity Description A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race condition. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said […]
CVE-2026-80725
29 août 2026
High Severity Description In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP (with sufficient MAC header room to insert the temporary HBH jumbo […]
CVE-2026-81346
29 août 2026
Medium Severity Description The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans. Read more at https://www.tenable.com/cve/CVE-2026-81346
CVE-2026-81200
29 août 2026
Medium Severity Description The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs. Read more at https://www.tenable.com/cve/CVE-2026-81200
Bugtraq
FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)
26 août 2026
Posted by Evan Tang on Aug 26https://blog.evan.lat/posts/CVE-2026-65053/ the blog talks about two vulns that are chainable together. for the sake of brevity ill write up on the stored xss one. in lib/Mime/Status.php, we see a pretty viable xss sink: $out .= '' . $val . ''; xrefing this we see that most impls are sanitized […]
[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File
26 août 2026
Posted by advisories on Aug 26---------------------------------------------------------------------------- NotCVE Advisory — NotCVE-2026-0013 ---------------------------------------------------------------------------- [-] Summary: Eval injection in the Kenwood ITM file format driver of CHIRP, an open-source application for programming amateur radios, allows an attacker who can persuade a user to open a crafted radio file to execute arbitrary Python code with the...
[NotCVE-2026-0012] EmpManageX Hardcoded Administrative Credentials in Login API Allow Full Access to Employee Records
26 août 2026
Posted by advisories on Aug 26---------------------------------------------------------------------------- NotCVE Advisory — NotCVE-2026-0012 ---------------------------------------------------------------------------- [-] Summary: kamalpanse18 EmpManageX, a Flask-based employee management application, ships hard-coded administrative credentials in its authentication logic. The username admin and the plaintext password admin123 are module-level constants in app.py,...
[NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Service
26 août 2026
Posted by advisories on Aug 26---------------------------------------------------------------------------- NotCVE Advisory — NotCVE-2026-0011 ---------------------------------------------------------------------------- [-] Summary: Nmap 7.99 and earlier contain a loop with an unreachable exit condition in the Packet:parse_options() method of nselib/packet.lua. A remote host that is the target of a scan can exhaust the memory of the scanning Nmap process and terminate it by...
[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
26 août 2026
Posted by advisories on Aug 26---------------------------------------------------------------------------- NotCVE Advisory — NotCVE-2026-0010 ---------------------------------------------------------------------------- [-] Summary: Barrier 2.4.0 for Windows contains a local privilege escalation vulnerability in the IPC command interface exposed by the barrierd.exe service on 127.0.0.1:24801. The IPC server accepts local TCP clients and processes a command line together...