[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE Exploit-DB.com 10 September 2026 at 20:00 CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE) Exploit-DB.com 2 September 2026 at 20:00 FreePBX 17.0.2 - Remote Code Execution (RCE)
[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution Exploit-DB.com 2 September 2026 at 20:00 Metabase 0.61.0 - Authenticated Remote Code Execution
[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting Exploit-DB.com 1 September 2026 at 20:00 Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
[webapps] PodcastGenerator 3.2.9 - Stored XSS Exploit-DB.com 1 September 2026 at 20:00 PodcastGenerator 3.2.9 - Stored XSS
[webapps] Ghost_CMS 6.19.0 - Remote Code Execution Exploit-DB.com 1 September 2026 at 20:00 Ghost_CMS 6.19.0 - Remote Code Execution
[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities Exploit-DB.com 1 September 2026 at 20:00 Fullhan FH8626V100 - Multiple Vulnerabilities
[webapps] Payload CMS 3.72.0 - Blind SQL Injection Exploit-DB.com 31 August 2026 at 20:00 Payload CMS 3.72.0 - Blind SQL Injection
[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass Exploit-DB.com 31 August 2026 at 20:00 miniOrange 5.4.3 - Unauthenticated Auth Bypass
[webapps] EasyAppointments 1.5.1 - Blind SQL Injection Exploit-DB.com 31 August 2026 at 20:00 EasyAppointments 1.5.1 - Blind SQL Injection
[webapps] C-MOR 6.0104 - Directory Traversal Exploit-DB.com 30 August 2026 at 20:00 C-MOR 6.0104 - Directory Traversal
[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS) Exploit-DB.com 30 August 2026 at 20:00 C-MOR 6.0104 - Cross-Site Scripting (XSS)
[webapps] CubeCart 6.7.4 - SQL injection Exploit-DB.com 30 August 2026 at 20:00 CubeCart 6.7.4 - SQL injection