Decline in Rig Exploit Kit
Rig exploit kit activity dropped roughly 75% after the pseudo-Darkleech and EITest campaigns stopped using EKs, reflecting an overall decline in exploit kit activity.
Rig EK activity fell sharply in 2017: the pseudo-Darkleech campaign disappeared at the end of March, cutting Rig traffic about 50%, and the EITest campaign switched to tech support scams in late April, cutting another 50% in May. Broader causes include a shrinking browser target base, no major EK zero-day in over a year, and community takedowns of domain shadowing infrastructure. Criminals are shifting to malspam, social engineering schemes like fake HoeflerText notifications, and tech support scams.
add a DefangedMode advanced options as teh exploit modifies the targe…
A Metasploit Framework commit adds a DefangedMode advanced option to an exploit module that modifies the target host configuration.
The commit introduces a DefangedMode advanced option so that the exploit's modification of the target configuration runs only explicitly, making the behavior visible to the user. No target product, affected software, or CVE identifier is named in the commit message.
[webapps] PodcastGenerator 3.2.9 - Stored XSS
A stored cross-site scripting flaw in PodcastGenerator 3.2.9 is documented with a public proof-of-concept exploit on Exploit-DB.
Exploit-DB published exploit ID 52677 targeting PodcastGenerator 3.2.9, a web application affected by stored cross-site scripting. The listing provides a proof-of-concept for the flaw but includes no CVE identifier or reports of active exploitation.
[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
A reflected cross-site scripting flaw in Bludit CMS 3.20.0 is documented with a public proof-of-concept exploit on Exploit-DB.
Exploit-DB published exploit ID 52678 targeting Bludit CMS 3.20.0, a web application affected by reflected cross-site scripting. The listing contains a proof-of-concept but includes no CVE identifier or evidence of active exploitation.
[webapps] Wolf CMS 0.8.3.1 - RCE v
A proof-of-concept exploit for remote code execution in Wolf CMS 0.8.3.1 has been published on Exploit-DB.
Exploit-DB lists a public proof-of-concept exploit for a remote code execution vulnerability in Wolf CMS 0.8.3.1. The listing is categorized under web applications. No exploitation in the wild or CVE identifier is stated in the listing.
[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass
A proof-of-concept exploit for an unauthenticated authentication bypass in miniOrange 5.4.3 has been published on Exploit-DB.
Exploit-DB lists a public proof-of-concept exploit for an unauthenticated authentication bypass in miniOrange 5.4.3. The flaw allows attackers to bypass authentication without credentials. No in-the-wild exploitation or CVE identifier is stated in the listing.
[webapps] Grav CMS 2.0.7 - RCE
A proof-of-concept exploit for remote code execution in Grav CMS 2.0.7 has been published on Exploit-DB.
Exploit-DB lists a public proof-of-concept exploit for a remote code execution vulnerability in Grav CMS 2.0.7. The listing is for web applications and provides code defenders can use to reproduce the issue. No exploitation in the wild or CVE assignment is stated in the listing.
[webapps] Payload CMS 3.72.0 - Blind SQL Injection
A proof-of-concept exploit for a blind SQL injection vulnerability in Payload CMS 3.72.0 has been published on Exploit-DB.
Exploit-DB lists a public proof-of-concept exploit for a blind SQL injection flaw in Payload CMS 3.72.0. The listing falls under the webapps category and allows reproduction of the injection. No in-the-wild exploitation or CVE identifier is stated in the listing.
[webapps] EasyAppointments 1.5.1 - Blind SQL Injection
A proof-of-concept exploit for a blind SQL injection vulnerability in EasyAppointments 1.5.1 has been published on Exploit-DB.
Exploit-DB lists a public proof-of-concept exploit for a blind SQL injection flaw in EasyAppointments 1.5.1. The listing falls under the webapps category and enables reproduction of the injection. No in-the-wild exploitation or CVE identifier is stated in the listing.
[webapps] CubeCart 6.7.4 - Stored XSS
A proof-of-concept stored cross-site scripting exploit targeting CubeCart 6.7.4 was published on Exploit-DB.
Exploit-DB lists a proof-of-concept exploit for a stored cross-site scripting (XSS) vulnerability in CubeCart 6.7.4, a PHP-based e-commerce web application. The listing demonstrates injection of attacker-controlled script that persists in the application, but no exploitation in the wild or CVE assignment is reported in the provided text.
[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)
A proof-of-concept cross-site scripting exploit for C-MOR video surveillance software 6.0104 appeared on Exploit-DB.
Exploit-DB published a proof-of-concept cross-site scripting (XSS) exploit against C-MOR 6.0104, an IP video surveillance platform. The listing demonstrates script injection in the web interface, but the provided text contains no CVE identifier or indication of active exploitation. Successful XSS against the surveillance console could enable session hijacking or manipulation of the monitoring interface.
[webapps] CubeCart 6.7.4 - SQL injection
A second proof-of-concept SQL injection exploit for CubeCart 6.7.4 was published on Exploit-DB.
Exploit-DB lists a SQL injection proof-of-concept affecting CubeCart 6.7.4, the open-source shopping cart application. The entry demonstrates the flaw but the provided text does not include a CVE identifier or reports of exploitation in the wild. It appears alongside related CubeCart XSS and SQL injection listings published the same day.
[webapps] CubeCart 6.7.4 - SQL
A proof-of-concept SQL injection exploit targeting CubeCart 6.7.4 was published on Exploit-DB.
Exploit-DB carries a proof-of-concept exploit for a SQL injection vulnerability in CubeCart 6.7.4, an open-source e-commerce platform. The listing demonstrates the injection issue but the provided text includes no CVE identifier or evidence of active exploitation. SQL injection in the storefront could expose or modify store data.
[webapps] CubeCart 6.7.4 - Cross-Site Scripting
A cross-site scripting exploit targeting CubeCart 6.7.4 web applications was published on Exploit-DB as entry 52661.
Exploit-DB listing 52661 discloses a cross-site scripting vulnerability in CubeCart version 6.7.4, classified under webapps. The listing makes a public exploit available, but no CVE id, exploitation evidence, or vendor patch status is provided in the item text.
[remote] PCMan 2.0.7 - Buffer Overflow
A remote buffer overflow in PCMan 2.0.7 has a public proof-of-concept exploit published on Exploit-DB.
Exploit-DB listing 52657 discloses a remote buffer overflow vulnerability in PCMan version 2.0.7. A proof-of-concept exploit is publicly available, allowing attackers to potentially crash or compromise affected instances. The listing includes no CVE identifier and reports no observed exploitation in the wild.
[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
A public proof-of-concept exploit for an SSRF flaw in Linuxfabrik monitoring_plugins 6.0.0 appeared on Exploit-DB.
Exploit-DB listing 52653 discloses a server-side request forgery (SSRF) vulnerability in Linuxfabrik monitoring_plugins version 6.0.0, classified under web applications. A proof-of-concept exploit is publicly available. No CVE identifier or evidence of in-the-wild exploitation is provided in the listing.
[webapps] flyto-core 2.26.7 - Arbitrary File Write
flyto-core 2.26.7 has an arbitrary file write vulnerability with a public proof-of-concept exploit on Exploit-DB.
Exploit-DB listing 52655 discloses an arbitrary file write vulnerability in flyto-core version 2.26.7. A proof-of-concept exploit is publicly available. The listing provides no CVE identifier and no indication of active exploitation; arbitrary file writes can potentially enable code execution depending on write locations.
[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities
Multiple vulnerabilities in the Fullhan FH8626V100 hardware chip have been disclosed alongside public proof-of-concept exploits.
Exploit-DB lists an entry covering multiple vulnerabilities in the Fullhan FH8626V100, a hardware component. The listing provides no CVE ids, vulnerability classes, or evidence of in-the-wild exploitation. Impact is likely limited to devices embedding the affected chip.
[dos] EVerest 2025.9.0 - DoS
A public proof-of-concept denial-of-service exploit has been published for the EVerest 2025.9.0 open-source EV charging framework.
Exploit-DB lists a denial-of-service proof of concept targeting EVerest version 2025.9.0. EVerest is an open-source software framework used for EV charging infrastructure. No in-the-wild exploitation or CVE mapping is stated in the listing.