Offensive Security
de260aeac6
DB: 2021-10-30
...
95 changes to exploits/shellcodes
Product Key Explorer 4.2.7 - 'multiple' Denial of Service (PoC)
Managed Switch Port Mapping Tool 2.85.2 - Denial of Service (PoC)
AgataSoft PingMaster Pro 2.1 - Denial of Service (PoC)
Nsauditor 3.2.2.0 - 'Event Description' Denial of Service (PoC)
WordPress Plugin WPGraphQL 1.3.5 - Denial of Service
Sandboxie 5.49.7 - Denial of Service (PoC)
WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service (PoC)
iDailyDiary 4.30 - Denial of Service (PoC)
RarmaRadio 2.72.8 - Denial of Service (PoC)
DupTerminator 1.4.5639.37199 - Denial of Service (PoC)
Color Notes 1.4 - Denial of Service (PoC)
Macaron Notes great notebook 5.5 - Denial of Service (PoC)
My Notes Safe 5.3 - Denial of Service (PoC)
n+otes 1.6.2 - Denial of Service (PoC)
Telegram Desktop 2.9.2 - Denial of Service (PoC)
Mini-XML 3.2 - Heap Overflow
Solaris 10 (Intel) - 'dtprintinfo' Local Privilege Escalation (2)
Solaris 10 (Intel) - 'dtprintinfo' Local Privilege Escalation (3)
Solaris 10 (SPARC) - 'dtprintinfo' Local Privilege Escalation (1)
Solaris 10 (SPARC) - 'dtprintinfo' Local Privilege Escalation (2)
MariaDB 10.2 - 'wsrep_provider' OS Command Execution
Microsoft Internet Explorer 11 and WPAD service 'Jscript.dll' - Use-After-Free
Visual Studio Code 1.47.1 - Denial of Service (PoC)
DELL dbutil_2_3.sys 2.3 - Arbitrary Write to Local Privilege Escalation (LPE)
MySQL User-Defined (Linux) x32 / x86_64 - 'sys_exec' Local Privilege Escalation (2)
Cmder Console Emulator 1.3.18 - 'Cmder.exe' Denial of Service (PoC)
GNU Wget < 1.18 - Arbitrary File Upload (2)
WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
E-Learning System 1.0 - Authentication Bypass
PEEL Shopping 9.3.0 - 'Comments' Persistent Cross-Site Scripting
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting
EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Persistent Cross-Site Scripting
Selea Targa 512 IP OCR-ANPR Camera - Stream Disclosure (Unauthenticated)
Library System 1.0 - Authentication Bypass
Web Based Quiz System 1.0 - 'name' Persistent Cross-Site Scripting
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
GetSimple CMS My SMTP Contact Plugin 1.1.1 - Cross-Site Request Forgery
GravCMS 1.10.7 - Unauthenticated Arbitrary File Write (Metasploit)
Umbraco v8.14.1 - 'baseUrl' SSRF
Cacti 1.2.12 - 'filter' SQL Injection
GetSimple CMS Custom JS 0.1 - Cross-Site Request Forgery
Internship Portal Management System 1.0 - Remote Code Execution(Unauthenticated)
Markdown Explorer 0.1.1 - Persistent Cross-Site Scripting
Xmind 2020 - Persistent Cross-Site Scripting
Tagstoo 2.0.1 - Persistent Cross-Site Scripting
SnipCommand 0.1.0 - Persistent Cross-Site Scripting
Moeditor 0.2.0 - Persistent Cross-Site Scripting
Marky 0.0.1 - Persistent Cross-Site Scripting
StudyMD 0.3.2 - Persistent Cross-Site Scripting
Freeter 1.2.1 - Persistent Cross-Site Scripting
Markright 1.0 - Persistent Cross-Site Scripting
Markdownify 1.2.0 - Persistent Cross-Site Scripting
Anote 1.0 - Persistent Cross-Site Scripting
Subrion CMS 4.2.1 - Arbitrary File Upload
Printable Staff ID Card Creator System 1.0 - 'email' SQL Injection
Schlix CMS 2.2.6-6 - Arbitary File Upload (Authenticated)
Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver)
CHIYU IoT Devices - Denial of Service (DoS)
Zenario CMS 8.8.52729 - 'cID' SQL injection (Authenticated)
TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated)
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal
Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
Scratch Desktop 3.17 - Remote Code Execution
Church Management System 1.0 - Arbitrary File Upload (Authenticated)
Phone Shop Sales Managements System 1.0 - Arbitrary File Upload
Zoo Management System 1.0 - 'Multiple' Persistent Cross-Site-Scripting (XSS)
WordPress Plugin Current Book 1.0.1 - 'Book Title' Persistent Cross-Site Scripting
ForgeRock Access Manager 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
KevinLAB BEMS 1.0 - Authentication Bypass
Event Registration System with QR Code 1.0 - Authentication Bypass
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF)
Panasonic Sanyo CCTV Network Camera 2.03-0x - Cross-Site Request Forgery (Change Password)
qdPM 9.2 - Password Exposure (Unauthenticated)
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
GeoVision Geowebserver 5.3.3 - Local FIle Inclusion
Simple Phone Book 1.0 - 'Username' SQL Injection (Unauthenticated)
Umbraco CMS 8.9.1 - Directory Traversal
Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
Dolibarr ERP 14.0.1 - Privilege Escalation
Compro Technology IP Camera - 'killps.cgi' Denial of Service (DoS)
Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation
Phpwcms 1.9.30 - Arbitrary File Upload
Windows/x86 - Download File (http://10.10.10.5:8080/2NWyfQ9T.hta ) Via mshta + Execute + Stager Shellcode (143 bytes)
Linux/x64 - Bind_tcp (0.0.0.0:4444) + Password (12345678) + Shell (/bin/sh) Shellcode (142 bytes)
Linux/x64 - execve _cat /etc/shadow_ Shellcode (66 bytes)
Windows/x86 - Add User Alfred to Administrators/Remote Desktop Users Group Shellcode (240 bytes)
Windows/x64 - Dynamic Null-Free WinExec PopCalc Shellcode (205 Bytes)
Windows/x64 - Dynamic NoNull Add RDP Admin (BOKU:SP3C1ALM0V3) Shellcode (387 Bytes)
Linux/x86 - setreuid(0) + execve(_/bin/sh_) Shellcode (29 bytes)
Linux/x86 - Bind (User Specified Port) Shell (/bin/sh) Shellcode (102 bytes)
Linux/x86 - Reverse (dynamic IP and port/TCP) Shell (/bin/sh) Shellcode (86 bytes)
Linux/x86 - Egghunter Reverse TCP Shell dynamic IP and port Shellcode
Windows/x86 - WinExec PopCalc PEB & Export Directory Table NullFree Dynamic Shellcode (178 bytes)
Windows/x86 - MessageBoxA PEB & Export Address Table NullFree/Dynamic Shellcode (230 bytes)
2021-10-30 05:02:09 +00:00
Offensive Security
f33a724e0b
DB: 2021-10-29
...
58 changes to exploits/shellcodes
Yenkee Hornet Gaming Mouse - 'GM312Fltr.sys' Denial of Service (PoC)
Easy CD & DVD Cover Creator 4.13 - Denial of Service (PoC)
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Device Reboot (Unauthenticated)
ProFTPD 1.3.7a - Remote Denial of Service
glFTPd 2.11a - Remote Denial of Service
Hasura GraphQL 1.3.3 - Denial of Service
Sticky Notes & Color Widgets 1.4.2 - Denial of Service (PoC)
NBMonitor 1.6.8 - Denial of Service (PoC)
Nsauditor 3.2.3 - Denial of Service (PoC)
Sticky Notes Widget Version 3.0.6 - Denial of Service (PoC)
Secure Notepad Private Notes 3.0.3 - Denial of Service (PoC)
Post-it 5.0.1 - Denial of Service (PoC)
Notex the best notes 6.4 - Denial of Service (PoC)
SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Service (PoC)
Redragon Gaming Mouse - 'REDRAGON_MOUSE.sys' Denial of Service (PoC)
GeoGebra Graphing Calculator 6.0.631.0 - Denial Of Service (PoC)
GeoGebra Classic 5.0.631.0-d - Denial of Service (PoC)
GeoGebra CAS Calculator 6.0.631.0 - Denial of Service (PoC)
Backup Key Recovery 2.2.7 - Denial of Service (PoC)
memono Notepad Version 4.2 - Denial of Service (PoC)
Disk Sorter Enterprise 13.6.12 - 'Disk Sorter Enterprise' Unquoted Service Path
Cyberfox Web Browser 52.9.1 - Denial of Service (PoC)
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Hard coded Credentials Shell Access
vsftpd 3.0.3 - Remote Denial of Service
Dlink DSL2750U - 'Reboot' Command Injection
PHPGurukul Hostel Management System 2.1 - Cross-site request forgery (CSRF) to Cross-site Scripting (XSS)
Netsia SEBA+ 0.16.1 - Add Root User (Metasploit)
Arteco Web Client DVR/NVR - 'SessionId' Brute Force
Resumes Management and Job Application Website 1.0 - Authentication Bypass
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Command Injection (Authenticated)
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Authentication Bypass
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Remote Code Execution
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Factory Reset (Unauthenticated)
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Config Download (Unauthenticated)
'customhs_js_content' - 'customhs_js_content' Cross-Site Request Forgery
Regis Inventory And Monitoring System 1.0 - 'Item List' Persistent Cross-Site Scripting
rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1)
Mini Mouse 9.3.0 - Local File inclusion
rconfig 3.9.6 - Arbitrary File Upload
Sipwise C5 NGCP CSC - 'Multiple' Persistent Cross-Site Scripting (XSS)
Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated)
OpenEMR 5.0.1.3 - Authentication Bypass
VMware vCenter Server 7.0 - Remote Code Execution (RCE) (Unauthenticated)
WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS)
Patient Appointment Scheduler System 1.0 - Persistent Cross-Site Scripting
Apartment Visitor Management System (AVMS) 1.0 - 'username' SQL Injection
Budget and Expense Tracker System 1.0 - Authenticated Bypass
Budget and Expense Tracker System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF)
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
Blood Bank System 1.0 - Authentication Bypass
Lodging Reservation Management System 1.0 - Authentication Bypass
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
Linux/x64 - /sbin/halt -p Shellcode (51 bytes)
Linux/x86 - execve(/bin/sh) Shellcode (17 bytes)
Linux/x64 - execve(/bin/sh) Shellcode (21 bytes) (2)
Linux/x86 - execve /bin/sh Shellcode (fstenv eip GetPC technique) (70 bytes_ xor encoded)
Windows/x86 - Bind TCP shellcode / Dynamic PEB & EDT method null-free Shellcode (415 bytes)
2021-10-29 05:02:12 +00:00
Offensive Security
358c35770a
DB: 2021-10-26
...
17 changes to exploits/shellcodes
Netgear Genie 2.4.64 - Unquoted Service Path
OpenClinic GA 5.194.18 - Local Privilege Escalation
Gestionale Open 11.00.00 - Local Privilege Escalation
Hikvision Web Server Build 210702 - Command Injection
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE)
Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated)
Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS)
Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
Engineers Online Portal 1.0 - 'multiple' Authentication Bypass
Engineers Online Portal 1.0 - 'id' SQL Injection
WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS)
WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS)
Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2)
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
2021-10-26 05:02:12 +00:00
Offensive Security
4f2cf56b31
DB: 2021-10-23
...
11 changes to exploits/shellcodes
Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection
OpenSIS 8.0 'modname' - Directory Traversal
Patient Appointment Scheduler System 1.0 - Unauthenticated File Upload
Budget and Expense Tracker System 1.0 - Arbitrary File Upload
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access)
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
Jetty 9.4.37.v20210219 - Information Disclosure
Clinic Management System 1.0 - SQL injection to Remote Code Execution
Online Course Registration 1.0 - Blind Boolean-Based SQL Injection (Authenticated)
Windows/x64 - Reverse TCP (192.168.201.11:4444) Shellcode (330 Bytes)
2021-10-23 05:02:09 +00:00
Offensive Security
2ee235ed78
DB: 2021-10-21
...
3 changes to exploits/shellcodes
Macro Expert 4.7 - Unquoted Service Path
AssetMan 2.4a - 'download_pdf.php' Remote File Disclosure
PHP-Nuke addon Nuke Mobile Entartainment 1.0 - Local File Inclusion
xKiosk 3.0.1i - 'xkurl.php?PEARPATH' Remote File Inclusion
InstaGuide Weather Script 1.0 - 'index.php' Local File Inclusion
CMSbright - 'id_rub_page' SQL Injection
ParsBlogger - 'blog.asp' SQL Injection
Blog System 1.x - 'note' SQL Injection
PHP Joke Site Software - 'sbjoke_id' SQL Injection
PHP Classifieds ADS - 'sid' Blind SQL Injection
Softbiz Article Directory Script - 'sbiz_id' Blind SQL Injection
Storyteller CMS - 'var' Local File Inclusion
MyPhpAuction 2010 - 'id' SQL Injection
PHP Lowbids - 'viewfaqs.php' Blind SQL Injection
BetMore Site Suite 4 - 'bid' Blind SQL Injection
PHP auctions - 'viewfaqs.php' Blind SQL Injection
PHP Coupon Script 6.0 - 'bus' Blind SQL Injection
PHP Link Directory Software - 'sbcat_id' SQL Injection
PHP Classified ads software - 'cid' Blind SQL Injection
PHP Script Directory Software - 'sbcat_id' SQL Injection
PHP Link Directory Software - 'sbcat_id' SQL Injection
PHP Classified ads software - 'cid' Blind SQL Injection
PHP Script Directory Software - 'sbcat_id' SQL Injection
Weekly Drawing Contest 0.0.1 - 'Check_Vote.php' Local File Inclusion
Holtstraeter Rot 13 - 'Enkrypt.php' Directory Traversal
easyGB 2.1.1 - 'index.php' Local File Inclusion
PHPAuctions - 'viewfaqs.php' SQL Injection
SonicWall SMA 10.2.1.0-17sv - Password Reset
Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
2021-10-21 05:02:11 +00:00
Offensive Security
b17b7fe4b2
DB: 2021-10-20
...
10 changes to exploits/shellcodes
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
2021-10-20 05:02:11 +00:00
Offensive Security
679a62755b
DB: 2021-10-14
...
28 changes to exploits/shellcodes
Cypress Solutions CTM-200/CTM-ONE - Hard-coded Credentials Remote Root (Telnet/SSH)
Cypress Solutions CTM-200 2.7.1 - Root Remote OS Command Injection
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
Simple Payroll System 1.0 - SQLi Authentication Bypass
Dolibarr ERP/CRM 14.0.1 - Privilege Escalation
Patient Appointment Scheduler System 1.0 - Unauthenticated File Upload & Remote Code Execution (RCE)
Budget and Expense Tracker System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
Budget and Expense Tracker System 1.0 - Arbitrary File Upload
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access)
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation
Company's Recruitment Management System 1.0 - 'Multiple' SQL Injection (Unauthenticated)
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
Pharmacy Point of Sale System 1.0 - 'Add New User' Cross-Site Request Forgery (CSRF)
Online Learning System 2.0 - 'Multiple' SQLi Authentication Bypass
Simple Issue Tracker System 1.0 - SQLi Authentication Bypass
Student Quarterly Grading System 1.0 - 'grade' Stored Cross-Site Scripting (XSS)
Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS)
Sonicwall SonicOS 7.0 - Host Header Injection
Windows/x64 - Reverse TCP (192.168.201.11:4444) Shellcode (330 Bytes)
2021-10-14 05:02:11 +00:00
Offensive Security
1cf7d7364a
DB: 2021-10-13
...
176 changes to exploits/shellcodes
Easy CD & DVD Cover Creator 4.13 - Denial of Service (PoC)
Managed Switch Port Mapping Tool 2.85.2 - Denial of Service (PoC)
Nsasoft Hardware Software Inventory 1.6.4.0 - 'multiple' Denial of Service (PoC)
Sandboxie 5.49.7 - Denial of Service (PoC)
WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service (PoC)
iDailyDiary 4.30 - Denial of Service (PoC)
RarmaRadio 2.72.8 - Denial of Service (PoC)
DupTerminator 1.4.5639.37199 - Denial of Service (PoC)
Color Notes 1.4 - Denial of Service (PoC)
Macaron Notes great notebook 5.5 - Denial of Service (PoC)
My Notes Safe 5.3 - Denial of Service (PoC)
Sticky Notes & Color Widgets 1.4.2 - Denial of Service (PoC)
NBMonitor 1.6.8 - Denial of Service (PoC)
Nsauditor 3.2.3 - Denial of Service (PoC)
Sticky Notes Widget Version 3.0.6 - Denial of Service (PoC)
n+otes 1.6.2 - Denial of Service (PoC)
Secure Notepad Private Notes 3.0.3 - Denial of Service (PoC)
Post-it 5.0.1 - Denial of Service (PoC)
Notex the best notes 6.4 - Denial of Service (PoC)
Solaris 10 1/13 (Intel) - 'dtprintinfo' Local Privilege Escalation (2)
Solaris 10 1/13 (Intel) - 'dtprintinfo' Local Privilege Escalation (3)
Solaris 10 1/13 (SPARC) - 'dtprintinfo' Local Privilege Escalation (1)
Solaris 10 1/13 (SPARC) - 'dtprintinfo' Local Privilege Escalation (2)
Solaris 10 1/13 (SPARC) - 'dtprintinfo' Local Privilege Escalation (3)
MariaDB 10.2 /MySQL - 'wsrep_provider' OS Command Execution
Visual Studio Code 1.47.1 - Denial of Service (PoC)
DELL dbutil_2_3.sys 2.3 - Arbitrary Write to Local Privilege Escalation (LPE)
Backup Key Recovery 2.2.7 - Denial of Service (PoC)
memono Notepad Version 4.2 - Denial of Service (PoC)
Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon)
Dlink DSL2750U - 'Reboot' Command Injection
E-Learning System 1.0 - Authentication Bypass & RCE POC
Netsia SEBA+ 0.16.1 - Authentication Bypass and Add Root User (Metasploit)
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Scripting and Session Fixation
GetSimple CMS 3.3.16 - Reflected XSS to RCE
House Rental and Property Listing 1.0 - Multiple Stored XSS
Resumes Management and Job Application Website 1.0 - Authentication Bypass (Sql Injection)
EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Multiple Stored Cross-Site Scripting
Cisco RV110W 1.2.1.7 - 'vpn_account' Denial of Service (PoC)
Inteno IOPSYS 3.16.4 - root filesystem access via sambashare (Authenticated)
Selea Targa IP OCR-ANPR Camera - RTP/RTSP/M-JPEG Stream Disclosure (Unauthenticated)
CMSUno 1.6.2 - 'lang/user' Remote Code Execution (Authenticated)
WordPress Plugin SuperForms 4.9 - Arbitrary File Upload to Remote Code Execution
Home Assistant Community Store (HACS) 1.10.0 - Path Traversal to Account Takeover
Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated)
Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon) (PoC)
Dolibarr ERP/CRM 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
Montiorr 1.7.6m - File Upload to XSS
GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE
Internship Portal Management System 1.0 - Remote Code Execution Via File Upload (Unauthenticated)
Markdown Explorer 0.1.1 - XSS to RCE
Xmind 2020 - XSS to RCE
Tagstoo 2.0.1 - Stored XSS to RCE
SnipCommand 0.1.0 - XSS to RCE
Moeditor 0.2.0 - XSS to RCE
Marky 0.0.1 - XSS to RCE
StudyMD 0.3.2 - XSS to RCE
Freeter 1.2.1 - XSS to RCE
Markright 1.0 - XSS to RCE
Markdownify 1.2.0 - XSS to RCE
Anote 1.0 - XSS to RCE
Subrion CMS 4.2.1 - File Upload Bypass to RCE (Authenticated)
Printable Staff ID Card Creator System 1.0 - SQLi & RCE via Arbitrary File Upload
Schlix CMS 2.2.6-6 - Arbitary File Upload And Directory Traversal Leads To RCE (Authenticated)
Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver)
CHIYU IoT Devices - Denial of Service (DoS)
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated)
TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated)
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal
Atlassian Jira Server/Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
Phone Shop Sales Managements System 1.0 - 'Multiple' Arbitrary File Upload to Remote Code Execution
ForgeRock Access Manager/OpenAM 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection
Dolibarr ERP/CRM 10.0.6 - Login Brute Force
qdPM 9.2 - DB Connection String and Password Exposure (Unauthenticated)
Simple Phone book/directory 1.0 - 'Username' SQL Injection (Unauthenticated)
ECOA Building Automation System - Hidden Backdoor Accounts and backdoor() Function
Budget and Expense Tracker System 1.0 - Authenticated Bypass
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting (XSS)
Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation via XML Signature Wrapping
Phpwcms 1.9.30 - File Upload to XSS
Linux/x86 - execve(/bin/sh) Shellcode (17 bytes)
Linux/x64 - execve(/bin/sh) Shellcode (21 bytes) (2)
Linux/x86 - setreuid(0) + execve(_/bin/sh_) Shellcode (29 bytes)
Linux/x86 - Bind (User Specified Port) Shell (/bin/sh) Shellcode (102 bytes)
Linux/x86 - Reverse (dynamic IP and port/TCP) Shell (/bin/sh) Shellcode (86 bytes)
Linux/x86 - Egghunter Reverse TCP Shell dynamic IP and port Shellcode
2021-10-13 05:02:15 +00:00
Offensive Security
a250e82458
DB: 2021-10-12
...
176 changes to exploits/shellcodes
Yenkee Hornet Gaming Mouse - 'GM312Fltr.sys' Denial-Of-Service (PoC)
Product Key Explorer 4.2.7 - 'multiple' Denial of Service (PoC)
jQuery UI 1.12.1 - Denial of Service (DoS)
AgataSoft PingMaster Pro 2.1 - Denial of Service (PoC)
Nsauditor 3.2.2.0 - 'Event Description' Denial of Service (PoC)
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Device Reboot (Unauthenticated)
ProFTPD 1.3.7a - Remote Denial of Service
glFTPd 2.11a - Remote Denial of Service
Hasura GraphQL 1.3.3 - Denial of Service
WordPress Plugin WPGraphQL 1.3.5 - Denial of Service
Telegram Desktop 2.9.2 - Denial of Service (PoC)
SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Service
Redragon Gaming Mouse - 'REDRAGON_MOUSE.sys' Denial-Of-Service (PoC)
GeoGebra Graphing Calculator 6.0.631.0 - Denial Of Service (PoC)
GeoGebra Classic 5.0.631.0-d - Denial of Service (PoC)
GeoGebra CAS Calculator 6.0.631.0 - Denial of Service (PoC)
Microsoft Internet Explorer 8/11 and WPAD service 'Jscript.dll' - Use-After-Free
MySQL User-Defined (Linux) x32 / x86_64 - 'sys_exec' Local Privilege Escalation (2)
Cyberfox Web Browser 52.9.1 - Denial-of-Service (PoC)
Cmder Console Emulator 1.3.18 - 'Cmder.exe' Denial-of-Service (PoC)
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Hard coded Credentials Shell Access
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Weak Default WiFi Password Algorithm
vsftpd 3.0.3 - Remote Denial of Service
GNU Wget < 1.18 - Arbitrary File Upload / Remote Code Execution (2)
PEEL Shopping 9.3.0 - 'Comments/Special Instructions' Stored Cross-Site Scripting
Arteco Web Client DVR/NVR - 'SessionId' Brute Force
Resumes Management and Job Application Website 1.0 - Multiple Stored XSS
Library System 1.0 - Authentication Bypass Via SQL Injection
MyBB Timeline Plugin 1.0 - Cross-Site Scripting / CSRF
SonicWall SSL-VPN 8.0.0.0 - 'shellshock/visualdoor' Remote Code Execution (Unauthenticated)
Web Based Quiz System 1.0 - 'MCQ options' Persistent/Stored Cross-Site Scripting
Web Based Quiz System 1.0 - 'name' Persistent/Stored Cross-Site Scripting
Online Ordering System 1.0 - Arbitrary File Upload to Remote Code Execution
MagpieRSS 0.72 - 'url' Command Injection and Server Side Request Forgery
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Command Injection (Authenticated)
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Authentication Bypass
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Remote Code Execution
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Factory Reset (Unauthenticated)
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Config Download (Unauthenticated)
GetSimple CMS Custom JS Plugin 0.1 - CSRF to Persistent XSS
Regis Inventory And Monitoring System 1.0 - 'Item List' Stored XSS
rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1)
Mini Mouse 9.3.0 - Local File inclusion / Path Traversal
GetSimple CMS My SMTP Contact Plugin 1.1.1 - CSRF to RCE
Discourse 2.7.0 - Rate Limit Bypass leads to 2FA Bypass
rconfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (2)
GravCMS 1.10.7 - Unauthenticated Arbitrary YAML Write/Update (Metasploit)
GetSimple CMS My SMTP Contact Plugin 1.1.2 - CSRF to Stored XSS to RCE
Sipwise C5 NGCP CSC - 'Multiple' Stored/Reflected Cross-Site Scripting (XSS)
Cacti 1.2.12 - 'filter' SQL Injection / Remote Code Execution
Zenario CMS 8.8.52729 - 'cID' Blind & Error based SQL injection (Authenticated)
OpenEMR 5.0.1.3 - '/portal/account/register.php' Authentication Bypass
VMware vCenter Server RCE 6.5 / 6.7 / 7.0 - Remote Code Execution (RCE) (Unauthenticated)
Scratch Desktop 3.17 - Cross-Site Scripting/Remote Code Execution (XSS/RCE)
Church Management System 1.0 - Unrestricted File Upload to Remote Code Execution (Authenticated)
Zoo Management System 1.0 - 'Multiple' Stored Cross-Site-Scripting (XSS)
WordPress Plugin Current Book 1.0.1 - 'Book Title and Author field' Stored Cross-Site Scripting (XSS)
KevinLAB BEMS 1.0 - Unauthenticated SQL Injection / Authentication Bypass
Event Registration System with QR Code 1.0 - Authentication Bypass & RCE
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF) to Remote Code Execution (RCE)
Panasonic Sanyo CCTV Network Camera 2.03-0x - 'Disable Authentication / Change Password' CSRF
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE) via Unsafe Deserialization of XMLRPC arguments
WordPress Plugin LifterLMS 4.21.1 - Access Other Student Grades/Answers via IDOR
GeoVision Geowebserver 5.3.3 - LFI / XSS / HHI / RCE
Umbraco CMS 8.9.1 - Path traversal and Arbitrary File Write (Authenticated)
Traffic Offense Management System 1.0 - SQLi to Remote Code Execution (RCE) (Unauthenticated)
Compro Technology IP Camera - 'killps.cgi' Denial-of-Service (DoS)
OpenSIS 8.0 'modname' - Directory/Path Traversal
Patient Appointment Scheduler System 1.0 - Persistent/Stored XSS
Apartment Visitor Management System (AVMS) 1.0 - SQLi to RCE
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF)
Wordpress Plugin JS Jobs Manager 1.1.7 - Unauthenticated Plugin Install/Activation
PlaceOS 1.2109.1 - Open Redirection
Blood Bank System 1.0 - SQL Injection / Authentication Bypass
Lodging Reservation Management System 1.0 - SQL Injection / Authentication Bypass
Atlassian Jira Server/Data Center 8.16.0 - Arbitrary File Read
Linux/x64 - Reverse (127.1.1.1:4444/TCP) Shell (/bin/sh) Shellcode (123 Bytes)
Linux/x86 - Bind Socat (0.0.0.0:1000/TCP) Shell (Bash) Shellcode (113 bytes)
Linux/x86 - Bind (0.0.0.0:13377/TCP) Shell (/bin/sh) Shellcode (65 bytes)
Windows/x86 - Download File (http://10.10.10.5:8080/2NWyfQ9T.hta ) Via mshta + Execute + Stager Shellcode (143 bytes)
Linux/x64 - Bind_tcp (0.0.0.0:4444) + Password (12345678) + Shell (/bin/sh) Shellcode (142 bytes)
Linux/x64 - execve _cat /etc/shadow_ Shellcode (66 bytes)
Windows/x86 - Add User Alfred to Administrators/Remote Desktop Users Group Shellcode (240 bytes)
Windows/x64 - Dynamic Null-Free WinExec PopCalc Shellcode (205 Bytes)
Windows/x64 - Dynamic NoNull Add RDP Admin (BOKU:SP3C1ALM0V3) Shellcode (387 Bytes)
Linux/x86 - execve /bin/sh Shellcode (fstenv eip GetPC technique) (70 bytes_ xor encoded)
Windows/x86 - WinExec PopCalc PEB & Export Directory Table NullFree Dynamic Shellcode (178 bytes)
Windows/x86 - Bind TCP shellcode / Dynamic PEB & EDT method null-free Shellcode (415 bytes)
2021-10-12 05:02:16 +00:00
Offensive Security
68d01808ce
DB: 2021-09-30
...
6 changes to exploits/shellcodes
Mitrastar GPT-2541GNAC-N1 - Privilege escalation
Storage Unit Rental Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting (XSS)
OpenSIS 8.0 - 'cp_id_miss_attn' Reflected Cross-Site Scripting (XSS)
Pet Shop Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
2021-09-30 05:02:08 +00:00
Offensive Security
d2b0bf596b
DB: 2021-09-29
...
10 changes to exploits/shellcodes
Apache James Server 2.3.2 - Remote Command Execution (RCE) (Authenticated) (2)
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF)
FatPipe Networks WARP 10.2.2 - Authorization Bypass
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Config Download (Unauthenticated)
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access)
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
2021-09-29 05:02:13 +00:00
Offensive Security
b104992c7d
DB: 2021-09-28
...
7 changes to exploits/shellcodes
Ether_MP3_CD_Burner 1.3.8 - Buffer Overflow (SEH)
Cyberfox Web Browser 52.9.1 - Denial-of-Service (PoC)
XAMPP 7.4.3 - Local Privilege Escalation
Cisco small business RV130W 1.0.3.44 - Inject Counterfeit Routers
WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS)
Library System 1.0 - 'student_id' SQL injection (Authenticated)
2021-09-28 05:02:15 +00:00
Offensive Security
1148d69c62
DB: 2021-09-22
...
5 changes to exploits/shellcodes
Yenkee Hornet Gaming Mouse - 'GM312Fltr.sys' Denial-Of-Service (PoC)
VSAT Sailor 900 - Remote Overflow
Budget and Expense Tracker System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
2021-09-22 05:02:16 +00:00
Offensive Security
723d6685ec
DB: 2021-09-16
...
4 changes to exploits/shellcodes
Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated)
Seowon 130-SLC router - 'queriesCnt' Remote Code Execution (Unauthenticated)
Evolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated)
AlphaWeb XE - File Upload Remote Code Execution (RCE) (Authenticated)
2021-09-16 05:02:08 +00:00
Offensive Security
629e350774
DB: 2021-09-14
...
18 changes to exploits/shellcodes
Active WebCam 11.5 - Unquoted Service Path
ECOA Building Automation System - Missing Encryption Of Sensitive Information
Facebook ParlAI 1.0.0 - Deserialization of Untrusted Data in parlai
ECOA Building Automation System - Hard-coded Credentials SSH Access
Men Salon Management System 1.0 - Multiple Vulnerabilities
ECOA Building Automation System - Weak Default Credentials
ECOA Building Automation System - Path Traversal Arbitrary File Upload
ECOA Building Automation System - Directory Traversal Content Disclosure
ECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF)
ECOA Building Automation System - Cookie Poisoning Authentication Bypass
ECOA Building Automation System - Configuration Download Information Disclosure
ECOA Building Automation System - Hidden Backdoor Accounts and backdoor() Function
ECOA Building Automation System - Remote Privilege Escalation
ECOA Building Automation System - Local File Disclosure
ECOA Building Automation System - Arbitrary File Deletion
Wordpress Plugin Download From Files 1.48 - Arbitrary File Upload
Apartment Visitor Management System (AVMS) 1.0 - SQLi to RCE
Windows/x64 - Reverse TCP (192.168.201.11:4444) Shellcode (330 Bytes)
2021-09-14 05:02:12 +00:00
Offensive Security
c9a65a1f7b
DB: 2021-09-03
...
52 changes to exploits/shellcodes
2021-09-03 21:04:54 +00:00
Offensive Security
b4c96a5864
DB: 2021-09-03
...
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00
Offensive Security
6cbe6ebbb6
DB: 2021-09-03
...
395 changes to exploits/shellcodes
EO Video 1.36 - Local Heap Overflow Denial of Service / (PoC)
Electronics Workbench - '.ewb' Local Stack Overflow (PoC)
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
Easy Web Password 1.2 - Local Heap Memory Consumption (PoC)
Compface 1.5.2 - '.xbm' Local Buffer Overflow (PoC)
eEye Retina WiFi Security Scanner 1.0 - '.rws Parsing' Buffer Overflow (PoC)
Zortam MP3 Media Studio 9.40 - Multiple Memory Corruption Vulnerabilities
ImTOO MPEG Encoder 3.1.53 - '.cue' / '.m3u' Local Buffer Overflow (PoC)
ZoIPer 2.22 - Call-Info Remote Denial of Service
PHP < 5.3.1 - 'MultiPart/form-data' Denial of Service
PHP - MultiPart Form-Data Denial of Service (PoC)
PHP < 5.3.1 - 'MultiPart/form-data' Denial of Service
PHP - MultiPart Form-Data Denial of Service (PoC)
Nuked KLan 1.7.7 & SP4 - Denial of Service
AIC Audio Player 1.4.1.587 - Local Crash (PoC)
Xerox 4595 - Denial of Service
WinMerge 2.12.4 - Project File Handling Stack Overflow
Acoustica Mixcraft 1.00 - Local Crash
SopCast 3.4.7 - 'sop://' URI Handling Remote Stack Buffer Overflow (PoC)
Oreans WinLicense 2.1.8.0 - XML File Handling Memory Corruption
Spotify 0.8.2.610 - search func Memory Exhaustion
Apple iTunes 10.6.1.7 - '.m3u' Walking Heap Buffer Overflow (PoC)
WaveSurfer 1.8.8p4 - Memory Corruption (PoC)
DIMIN Viewer 5.4.0 - Crash (PoC)
FreeVimager 4.1.0 - Crash (PoC)
DIMIN Viewer 5.4.0 - Crash (PoC)
FreeVimager 4.1.0 - Crash (PoC)
CoolPlayer+ Portable 2.19.4 - Local Buffer Overflow
Light Audio Player 1.0.14 - Memory Corruption (PoC)
Image Transfer IOS - Remote Crash (PoC)
Larson VizEx Reader 9.7.5 - Local Buffer Overflow (SEH)
VUPlayer 2.49 - '.cue' Universal Buffer Overflow
Apple Mac OSX xnu 1228.x - 'hfs-fcntl' Kernel Privilege Escalation
IBM AIX 5.3 - 'libc' MALLOCDEBUG File Overwrite
Hex Workshop 4.23/5.1/6.0 - '.hex' Universal Local Buffer Overflow (SEH)
Soritong MP3 Player 1.0 - '.m3u' / UI.txt Universal Local Buffer Overflow
Adobe Acrobat/Reader < 7.1.1/8.1.3/9.1 - Collab getIcon Universal
Millenium MP3 Studio - '.pls' / '.mpf' / '.m3u' Universal Local Buffer Overflow (SEH)
Alleycode HTML Editor 2.2.1 - Local Buffer Overflow
GPG2/Kleopatra 2.0.11 - Malformed Certificate
Free WMA MP3 Converter 1.1 - '.wav' Local Buffer Overflow
OtsTurntables Free 1.00.047 - '.olf' Universal Buffer Overflow
Watermark Master 2.2.23 - '.wstyle' Local Buffer Overflow (SEH)
Dropbox < 3.3.x - OSX FinderLoadBundle Privilege Escalation
MySQL / MariaDB / PerconaDB 5.5.51/5.6.32/5.7.14 - Code Execution / Privilege Escalation
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (1)
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (2)
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (1)
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (2)
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (3)
QK SMTP 3.01 - 'RCPT TO' Remote Buffer Overflow (2)
CA BrightStor ARCserve - 'msgeng.exe' Remote Stack Overflow
quickshare file share 1.2.1 - Directory Traversal (1)
SPlayer 3.7 (build 2055) - Remote Buffer Overflow
Acunetix 8 build 20120704 - Remote Stack Overflow
Omeka 2.2.1 - Remote Code Execution
D-Link DSL-2740R - Remote DNS Change
D-Link DSL-2730U/2750U/2750E ADSL Router - Remote File Disclosure
Netgear JNR1010 ADSL Router - (Authenticated) Remote File Disclosure
D-Link DSL-2730U/2750U/2750E ADSL Router - Remote File Disclosure
Netgear JNR1010 ADSL Router - (Authenticated) Remote File Disclosure
Websphere/JBoss/OpenNMS/Symantec Endpoint Protection Manager - Java Deserialization Remote Code Execution
TorrentTrader 1.0 RC2 - SQL Injection
WEBInsta CMS 0.3.1 - 'templates_dir' Remote File Inclusion
MiniPort@l 0.1.5 Beta - 'skiny' Remote File Inclusion
PHP DocWriter 0.3 - 'script' Remote File Inclusion
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
RSSonate - 'xml2rss.php' Remote File Inclusion
CASTOR 1.1.1 - '/lib/rs.php' Remote File Inclusion
RSSonate - 'xml2rss.php' Remote File Inclusion
CASTOR 1.1.1 - '/lib/rs.php' Remote File Inclusion
QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
BrewBlogger 1.3.1 - 'printLog.php' SQL Injection
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
Tucows Client Code Suite (CSS) 1.2.1015 - Remote File Inclusion
Gizzar 03162002 - 'index.php' Remote File Inclusion
SH-News 0.93 - 'misc.php' Remote File Inclusion
JSBoard 2.0.10 - 'login.php?table' Local File Inclusion
XOOPS Module WF-Links 1.03 - 'cid' SQL Injection
Scorp Book 1.0 - 'smilies.php?config' Remote File Inclusion
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
mxBB Module FAQ & RULES 2.0.0 - Remote File Inclusion
EQdkp 1.3.2 - 'listmembers.php' SQL Injection
FlashBB 1.1.8 - 'sendmsg.php' Remote File Inclusion
SimpleBlog 3.0 - 'comments_get.asp?id' SQL Injection
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CCMS 3.1 Demo - SQL Injection
MoinMoin 1.5.x - 'MOIND_ID' Cookie Login Bypass
BlogPHP 2 - 'id' Cross-Site Scripting / SQL Injection
AuraCMS 1.62 - Multiple SQL Injections
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
RevokeBB 1.0 RC11 - 'Search' SQL Injection
Galatolo Web Manager 1.0 - Cross-Site Scripting / Local File Inclusion
CaupoShop Classic 1.3 - 'saArticle[ID]' SQL Injection
PHPortal 1.2 - Multiple Remote File Inclusions
Libera CMS 1.12 - 'cookie' SQL Injection
Zanfi CMS lite 2.1 / Jaw Portal free - 'FCKeditor' Arbitrary File Upload
WCMS 1.0b - Arbitrary Add Admin
FOSS Gallery Admin 1.0 - Arbitrary File Upload
MemHT Portal 4.0.1 - SQL Injection / Code Execution
Mediatheka 4.2 - Blind SQL Injection
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
XOOPS 2.3.2 - 'mydirname' PHP Remote Code Execution
Joomla! Component Casino 0.3.1 - Multiple SQL Injections s
ZeusCart 2.3 - 'maincatid' SQL Injection
ASP Football Pool 2.3 - Remote Database Disclosure
LightNEasy sql/no-db 2.2.x - System Configuration Disclosure
Zen Cart 1.3.8 - Remote Code Execution
Joomla! Component com_pinboard - 'task' SQL Injection
Joomla! Component com_bookflip - 'book_id' SQL Injection
Messages Library 2.0 - Arbitrary Delete Message
Arab Portal 2.2 - Blind Cookie Authentication Bypass
Joomla! Plugin JD-WordPress 2.0 RC2 - Remote File Inclusion
REZERVI 3.0.2 - Remote Command Execution
Joomla! Component BF Quiz 1.0 - SQL Injection (2)
E-Xoopport Samsara 3.1 (eCal Module) - Blind SQL Injection
AJ Matrix DNA - SQL Injection
Joomla! Component JE Story Submit - Local File Inclusion
CF Image Hosting Script 1.3.82 - File Disclosure
hastymail2 webmail 1.1 rc2 - Persistent Cross-Site Scripting
CMSLogik 1.2.1 - Multiple Vulnerabilities
C.P.Sub 4.5 - Authentication Bypass
WordPress Plugin Slideshow Gallery 1.4.6 - Arbitrary File Upload
Joomla! Component com_hdflvplayer < 2.1.0.1 - SQL Injection
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload
PHPMailer < 5.2.20 - Remote Code Execution
phpIPAM 1.4 - SQL Injection
Joomla! 3.9.0 < 3.9.7 - CSV Injection
2021-09-03 14:58:20 +00:00
Offensive Security
36c084c351
DB: 2021-09-03
...
45419 changes to exploits/shellcodes
2 new exploits/shellcodes
Too many to list!
2021-09-03 13:39:06 +00:00
Offensive Security
23acd8a13b
DB: 2021-09-03
...
9 changes to exploits/shellcodes
Dolibarr ERP/CRM 14.0.1 - Privilege Escalation
OpenSIS Community 8.0 - 'cp_id_miss_attn' SQL Injection
Compro Technology IP Camera - 'killps.cgi' Denial-of-Service (DoS)
Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated)
Compro Technology IP Camera - 'Multiple' Credential Disclosure
Compro Technology IP Camera - ' index_MJpeg.cgi' Stream Disclosure
WordPress Plugin Duplicate Page 4.4.1 - Stored Cross-Site Scripting (XSS)
Compro Technology IP Camera - ' mjpegStreamer.cgi' Screenshot Disclosure
WPanel 4.3.1 - Remote Code Execution (RCE) (Authenticated)
2021-09-03 05:01:58 +00:00
Offensive Security
ac4322c402
DB: 2021-08-28
...
3 changes to exploits/shellcodes
CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated)
COMMAX WebViewer ActiveX Control 2.1.4.5 - 'Commax_WebViewer.ocx' Buffer Overflow
COMMAX UMS Client ActiveX Control 1.7.0.2 - 'CNC_Ctrl.dll' Heap Buffer Overflow
2021-08-28 05:01:59 +00:00
Offensive Security
0388680649
DB: 2021-08-26
...
3 changes to exploits/shellcodes
WordPress Plugin Mail Masta 1.0 - Local File Inclusion (2)
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
Online Leave Management System 1.0 - Arbitrary File Upload to Shell (Unauthenticated)
2021-08-26 05:02:00 +00:00
Offensive Security
4e7ab00187
DB: 2021-08-20
...
204 changes to exploits/shellcodes
Charity Management System CMS 1.0 - Multiple Vulnerabilities
2021-08-20 05:01:51 +00:00
Offensive Security
0105a5abef
DB: 2021-08-18
...
2 changes to exploits/shellcodes
SonicWall NetExtender 10.2.0.300 - Unquoted Service Path
GeoVision Geowebserver 5.3.3 - LFI / XSS / HHI / RCE
2021-08-18 05:01:56 +00:00
Offensive Security
dc3bff8caf
DB: 2021-08-17
...
9 changes to exploits/shellcodes
NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS)
CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS)
Simple Water Refilling Station Management System 1.0 - Authentication Bypass
Simple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File Upload
COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass
COMMAX Smart Home IoT Control System CDP-1020n - SQL Injection Authentication Bypass
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - RTSP Credentials Disclosure
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - Config Write / DoS (Unauthenticated)
COMMAX CVD-Axx DVR 5.1.4 - Weak Default Credentials Stream Disclosure
2021-08-17 05:01:53 +00:00
Offensive Security
dfe7376951
DB: 2021-08-03
...
5 changes to exploits/shellcodes
Neo4j 3.4.18 - RMI based Remote Code Execution (RCE)
Men Salon Management System 1.0 - SQL Injection Authentication Bypass
Online Hotel Reservation System 1.0 - 'Multiple' Cross-site scripting (XSS)
Panasonic Sanyo CCTV Network Camera 2.03-0x - 'Disable Authentication / Change Password' CSRF
2021-08-03 05:02:02 +00:00
Offensive Security
8461d963fa
DB: 2021-07-30
...
9 changes to exploits/shellcodes
Splinterware System Scheduler Professional 5.30 - Privilege Escalation
Denver IP Camera SHO-110 - Unauthenticated Snapshot
Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download
IntelliChoice eFORCE Software Suite 2.5.9 - Username Enumeration
Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF) to Remote Code Execution (RCE)
Oracle Fatwire 6.3 - Multiple Vulnerabilities
2021-07-30 05:01:56 +00:00
Offensive Security
e7fc5a3e03
DB: 2021-07-29
...
3 changes to exploits/shellcodes
Denver Smart Wifi Camera SHC-150 - 'Telnet' Remote Code Execution (RCE)
PHP 7.3.15-3 - 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection
Event Registration System with QR Code 1.0 - Authentication Bypass & RCE
TripSpark VEO Transportation - Blind SQL Injection
2021-07-29 05:01:55 +00:00
Offensive Security
e4e9d54ac6
DB: 2021-07-22
...
4 changes to exploits/shellcodes
KevinLAB BEMS 1.0 - Undocumented Backdoor Account
KevinLAB BEMS 1.0 - Unauthenticated SQL Injection / Authentication Bypass
KevinLAB BEMS 1.0 - File Path Traversal Information Disclosure (Authenticated)
CSZ CMS 1.2.9 - 'Multiple' Arbitrary File Deletion
2021-07-22 05:01:53 +00:00
Offensive Security
29558b9c84
DB: 2021-07-17
...
6 changes to exploits/shellcodes
Argus Surveillance DVR 4.0 - Weak Password Encryption
Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation
Aruba Instant 8.7.1.0 - Arbitrary File Modification
Aruba Instant (IAP) - Remote Code Execution
ForgeRock Access Manager/OpenAM 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection
2021-07-17 05:01:54 +00:00
Offensive Security
1514ca02a7
DB: 2021-07-07
...
13 changes to exploits/shellcodes
Huawei dg8045 - Authentication Bypass
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal
perfexcrm 1.10 - 'State' Stored Cross-site scripting (XSS)
Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated)
Netgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated)
Black Box Kvm Extender 3.4.31307 - Local File Inclusion
Pallets Werkzeug 0.15.4 - Path Traversal
Billing System Project 1.0 - Remote Code Execution (RCE) (Unauthenticated)
Exam Hall Management System 1.0 - Unrestricted File Upload (Unauthenticated)
Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation
Phone Shop Sales Managements System 1.0 - Authentication Bypass (SQLi)
Phone Shop Sales Managements System 1.0 - 'Multiple' Arbitrary File Upload to Remote Code Execution
2021-07-07 05:02:02 +00:00
Offensive Security
540825f140
DB: 2021-07-06
...
11 changes to exploits/shellcodes
WordPress Plugin WP Learn Manager 1.1.2 - Stored Cross-Site Scripting (XSS)
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2)
Online Voting System 1.0 - SQLi (Authentication Bypass) + Remote Code Execution (RCE)
Online Birth Certificate System 1.1 - 'Multiple' Stored Cross-Site Scripting (XSS)
Church Management System 1.0 - Unrestricted File Upload to Remote Code Execution (Authenticated)
Church Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
Church Management System 1.0 - 'password' SQL Injection (Authentication Bypass)
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
Simple Client Management System 1.0 - Remote Code Execution (RCE)
TextPattern CMS 4.9.0-dev - Remote Command Execution (RCE) (Authenticated)
Ricon Industrial Cellular Router S9922XL - Remote Command Execution (RCE)
2021-07-06 05:02:03 +00:00
Offensive Security
5bd61e68a2
DB: 2021-07-03
...
7 changes to exploits/shellcodes
WinWaste.NET 1.0.6183.16475 - Privilege Escalation due Incorrect Access Control
Scratch Desktop 3.17 - Cross-Site Scripting/Remote Code Execution (XSS/RCE)
AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)
b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF)
Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated)
Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated)
Garbage Collection Management System 1.0 - SQL Injection (Unauthenticated)
2021-07-03 05:01:54 +00:00
Offensive Security
9008c67d8b
DB: 2021-06-29
...
5 changes to exploits/shellcodes
WordPress Plugin YOP Polls 6.2.7 - Stored Cross Site Scripting (XSS)
SAS Environment Manager 2.5 - 'name' Stored Cross-Site Scripting (XSS)
Atlassian Jira Server/Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
Netgear WNAP320 2.0.3 - 'macAddress' Remote Code Execution (RCE) (Unauthenticated)
2021-06-29 05:01:55 +00:00
Offensive Security
135e56dda8
DB: 2021-06-25
...
16 changes to exploits/shellcodes
BasicNote 1.1.9 - Denial of Service (PoC)
ColorNote 4.1.9 - Denial of Service (PoC)
Notepad notes 2.6.7 - Denial of Service (PoC)
Blacknote 2.2.1 - Denial of Service (PoC)
Inkpad Notepad & To do list 4.3.61 - Denial of Service (PoC)
GeoGebra 3D Calculator 5.0.511.0 - Denial of Service (PoC)
VMware vCenter Server RCE 6.5 / 6.7 / 7.0 - Remote Code Execution (RCE) (Unauthenticated)
Adobe ColdFusion 8 - Remote Command Execution (RCE)
TP-Link TL-WR841N - Command Injection
Huawei dg8045 - Authentication Bypass
2021-06-25 05:01:52 +00:00
Offensive Security
eb316547aa
DB: 2021-06-19
...
5 changes to exploits/shellcodes
Dlink DSL2750U - 'Reboot' Command Injection
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Scripting and Session Fixation
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF)
ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS)
Node.JS - 'node-serialize' Remote Code Execution (3)
2021-06-19 05:01:57 +00:00
Offensive Security
83051cc8db
DB: 2021-06-10
...
5 changes to exploits/shellcodes
Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF)
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS)
GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
2021-06-10 05:01:53 +00:00
Offensive Security
d6a44bd00b
DB: 2021-06-08
...
11 changes to exploits/shellcodes
Sticky Notes & Color Widgets 1.4.2 - Denial of Service (PoC)
IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
GitLab Community Edition (CE) 13.10.3 - 'Sign_Up' User Enumeration
OptiLink ONT1GEW GPON 2.1.11_X101 Build 1127.190306 - Remote Code Execution (Authenticated)
WordPress Plugin Smart Slider-3 3.5.0.8 - 'name' Stored Cross-Site Scripting (XSS)
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated)
Grav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated)
Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)
2021-06-08 05:02:03 +00:00
Offensive Security
a9fa314bbf
DB: 2021-06-04
...
14 changes to exploits/shellcodes
BasicNote 1.1.9 - Denial of Service (PoC)
ColorNote 4.1.9 - Denial of Service (PoC)
Notepad notes 2.6.7 - Denial of Service (PoC)
Blacknote 2.2.1 - Denial of Service (PoC)
CHIYU IoT Devices - 'Telnet' Authentication Bypass
PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution
Seo Panel 4.8.0 - 'from_time' Reflected XSS
CHIYU IoT Devices - Denial of Service (DoS)
FUDForum 3.1.0 - 'srch' Reflected XSS
FUDForum 3.1.0 - 'author' Reflected XSS
Gitlab 13.9.3 - Remote Code Execution (Authenticated)
4Images 1.8 - 'redirect' Reflected XSS
2021-06-04 05:01:54 +00:00
Offensive Security
b7bdc3f375
DB: 2021-06-03
...
7 changes to exploits/shellcodes
Intel(R) Audio Service x64 01.00.1080.0 - 'IntelAudioService' Unquoted Service Path
Thecus N4800Eco Nas Server Control Panel - Comand Injection
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
GetSimple CMS 3.3.4 - Information Disclosure
Products.PluggableAuthService 2.6.0 - Open Redirect
Seo Panel 4.8.0 - 'search_name' Reflected XSS
Seo Panel 4.8.0 - 'category' Reflected XSS
2021-06-03 05:01:55 +00:00
Offensive Security
44903d83c7
DB: 2021-06-02
...
9 changes to exploits/shellcodes
DupTerminator 1.4.5639.37199 - Denial of Service (PoC)
Veyon 4.4.1 - 'VeyonService' Unquoted Service Path
LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)
ProjeQtOr Project Management 9.1.4 - Remote Code Execution
Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)
WordPress Plugin WP Prayer version 1.6.1 - 'prayer_messages' Stored Cross-Site Scripting (XSS) (Authenticated)
CHIYU IoT devices - 'Multiple' Cross-Site Scripting (XSS)
CHIYU TCP/IP Converter devices - CRLF injection
Atlassian Jira 8.15.0 - Information Disclosure (Username Enumeration)
2021-06-02 05:02:06 +00:00
Offensive Security
23c2c2fa04
DB: 2021-05-01
...
4 changes to exploits/shellcodes
GNU Wget < 1.18 - Arbitrary File Upload / Remote Code Execution (2)
FortiOS < 5.6.0 - Cross-Site Scripting
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure
Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure
FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit)
FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit)
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure
Moodle 3.6.1 - Persistent Cross-Site Scripting (XSS)
2021-05-01 05:01:55 +00:00
Offensive Security
092f2f0697
DB: 2021-04-27
...
6 changes to exploits/shellcodes
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (1)
Hasura GraphQL 1.3.3 - Remote Code Execution
OpenPLC 3 - Remote Code Execution (Authenticated)
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2)
2021-04-27 05:02:00 +00:00
Offensive Security
37baf23611
DB: 2021-04-24
...
7 changes to exploits/shellcodes
Moodle 3.10.3 - 'url' Persistent Cross Site Scripting
GetSimple CMS My SMTP Contact Plugin 1.1.2 - CSRF to Stored XSS to RCE
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
Sipwise C5 NGCP CSC - 'Multiple' Stored/Reflected Cross-Site Scripting (XSS)
Sipwise C5 NGCP CSC - Click2Dial Cross-Site Request Forgery (CSRF)
2021-04-24 05:01:56 +00:00
Offensive Security
7fa85628bd
DB: 2021-04-22
...
19 changes to exploits/shellcodes
Hasura GraphQL 1.3.3 - Denial of Service
Tenda D151 & D301 - Configuration Download (Unauthenticated)
rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated)
rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1)
Multilaser Router RE018 AC1200 - Cross-Site Request Forgery (Enable Remote Access)
Fast PHP Chat 1.3 - 'my_item_search' SQL Injection
WordPress Plugin RSS for Yandex Turbo 1.29 - Stored Cross-Site Scripting (XSS)
BlackCat CMS 1.3.6 - 'Multiple' Stored Cross-Site Scripting (XSS)
Discourse 2.7.0 - Rate Limit Bypass leads to 2FA Bypass
RemoteClinic 2 - 'Multiple' Cross-Site Scripting (XSS)
rconfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (2)
OpenEMR 5.0.2.1 - Remote Code Execution
Adtran Personal Phone Manager 10.8.1 - 'emailAddress' Stored Cross-Site Scripting (XSS)
Adtran Personal Phone Manager 10.8.1 - 'Multiple' Reflected Cross-Site Scripting (XSS)
Adtran Personal Phone Manager 10.8.1 - DNS Exfiltration
GravCMS 1.10.7 - Unauthenticated Arbitrary YAML Write/Update (Metasploit)
Hasura GraphQL 1.3.3 - Local File Read
Hasura GraphQL 1.3.3 - Service Side Request Forgery (SSRF)
2021-04-22 05:01:54 +00:00
Offensive Security
bccca11e26
DB: 2021-04-15
...
8 changes to exploits/shellcodes
MariaDB 10.2 /MySQL - 'wsrep_provider' OS Command Execution
Digital Crime Report Management System 1.0 - SQL Injection (Authentication Bypass)
CITSmart ITSM 9.1.2.22 - LDAP Injection
CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
jQuery 1.2 - Cross-Site Scripting (XSS)
jQuery 1.0.3 - Cross-Site Scripting (XSS)
2021-04-15 05:01:57 +00:00
Offensive Security
cbe5b3f2e5
DB: 2021-04-03
...
2 changes to exploits/shellcodes
ZBL EPON ONU Broadband Router 1.0 - Remote Privilege Escalation
F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated)
2021-04-03 05:01:57 +00:00
Offensive Security
3145bbcf80
DB: 2021-04-01
...
3 changes to exploits/shellcodes
DD-WRT 45723 - UPNP Buffer Overflow (PoC)
Zabbix 3.4.7 - Stored XSS
CourseMS 2.1 - 'name' Stored XSS
2021-04-01 05:02:01 +00:00
Offensive Security
e6cd1b38eb
DB: 2021-03-30
...
9 changes to exploits/shellcodes
Microsoft Internet Explorer Windows 10 1809 17763.316 - Scripting Engine Memory Corruption
vsftpd 3.0.3 - Remote Denial of Service
WordPress Plugin WP Super Cache 1.7.1 - Remote Code Execution (Authenticated)
TP-Link Devices - 'setDefaultHostname' Stored Cross-site Scripting (Unauthenticated)
Concrete5 8.5.4 - 'name' Stored XSS
Equipment Inventory System 1.0 - 'multiple' Stored XSS
Budget Management System 1.0 - 'Budget title' Stored XSS
Novel Boutique House-plus 3.5.1 - Arbitrary File Download
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
2021-03-30 05:01:56 +00:00
Offensive Security
06a83531de
DB: 2021-03-26
...
4 changes to exploits/shellcodes
Ovidentia 6 - 'id' SQL injection (Authenticated)
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
Genexis Platinum-4410 P4410-V2-1.31A - 'start_addr' Persistent Cross-Site Scripting
Dolibarr ERP/CRM 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
2021-03-26 05:01:58 +00:00