victoni

3 exploits Active since Jan 2024
CVE-2023-52271 NOMISEC MEDIUM WORKING POC
Topaz Antifraud <2.0.0.0 - Privilege Escalation
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).
6 stars
CVSS 6.5
CVE-2024-42010 GITHUB HIGH javascript WORKING POC
Roundcube <1.5.7, <1.6.0-1.6.7 - Info Disclosure
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.
2 stars
CVSS 7.5
CVE-2024-42008 NOMISEC CRITICAL WORKING POC
Roundcube Webmail < 1.5.8 - XSS
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
2 stars
CVSS 9.3