Exploit-DB
|
989122095f
|
DB: 2025-04-04
11 changes to exploits/shellcodes/ghdb
AppSmith 1.47 - Remote Code Execution (RCE)
ollama 0.6.4 - Server Side Request Forgery (SSRF)
Vite 6.2.2 - Arbitrary File Read
ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)
Nagios Log Server 2024R1.3.1 - Stored XSS
Webmin Usermin 2.100 - Username Enumeration
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
openSIS 9.1 - SQLi (Authenticated)
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
ProSSHD 1.2 - Denial of Service (DOS)
|
2025-04-04 00:16:25 +00:00 |
|
Exploit-DB
|
c773b14d1c
|
DB: 2025-04-03
6 changes to exploits/shellcodes/ghdb
Mitel mitel-cs018 - Call Data Information Disclosure
SAP NetWeaver - 7.53 - HTTP Request Smuggling
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
ProSSHD 1.2 - Denial of Service (DOS)
|
2025-04-03 00:16:28 +00:00 |
|
Exploit-DB
|
51ef1693d4
|
DB: 2025-03-23
4 changes to exploits/shellcodes/ghdb
Aztech DSL5005EN Router - 'sysAccess.asp' Admin Password Change (Unauthenticated)
TeamPass 3.0.0.21 - SQL Injection
Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
|
2025-03-23 00:16:32 +00:00 |
|
Exploit-DB
|
859e322e5c
|
DB: 2024-07-03
13 changes to exploits/shellcodes/ghdb
ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) & SSH Access
Zyxel IKE Packet Decoder - Unauthenticated Remote Code Execution (Metasploit)
Rebar3 3.13.2 - Command Injection
Craft CMS Logs Plugin 3.0.3 - Path Traversal (Authenticated)
ZwiiCMS 12.2.04 - Remote Code Execution (Authenticated)
Wipro Holmes Orchestrator 20.4.1 - Log File Disclosure
|
2024-07-03 00:16:27 +00:00 |
|
Exploit-DB
|
ea4df5672e
|
DB: 2024-06-02
6 changes to exploits/shellcodes/ghdb
ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) & SSH Access
Akaunting 3.1.8 - Server-Side Template Injection (SSTI)
Craft CMS Logs Plugin 3.0.3 - Path Traversal (Authenticated)
FreePBX 16 - Remote Code Execution (RCE) (Authenticated)
Wipro Holmes Orchestrator 20.4.1 - Log File Disclosure
|
2024-06-02 00:16:32 +00:00 |
|
Exploit-DB
|
e791587e41
|
DB: 2024-03-29
10 changes to exploits/shellcodes/ghdb
RouterOS 6.40.5 - 6.44 and 6.48.1 - 6.49.10 - Denial of Service
Siklu MultiHaul TG series < 2.0.0 - unauthenticated credential disclosure
Dell Security Management Server <1.9.0 - Local Privilege Escalation
Asterisk AMI - Partial File Content & Path Disclosure (Authenticated)
Broken Access Control - on NodeBB v3.6.7
liveSite Version 2019.1 - Remote Code Execution
Purei CMS 1.0 - SQL Injection
Workout Journal App 1.0 - Stored XSS
WinRAR version 6.22 - Remote Code Execution via ZIP archive
|
2024-03-29 00:16:30 +00:00 |
|
Exploit-DB
|
26a991fc28
|
DB: 2024-03-23
2 changes to exploits/shellcodes/ghdb
minaliC 2.0.0 - Denied of Service
|
2024-03-23 00:16:33 +00:00 |
|
Exploit-DB
|
81ae91fdae
|
DB: 2024-02-03
14 changes to exploits/shellcodes/ghdb
Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution
Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal
TP-LINK TL-WR740N - Multiple HTML Injection
TP-Link TL-WR740N - UnAuthenticated Directory Transversal
Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)
mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page
PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow
WebCatalog 48.4 - Arbitrary Protocol Execution
|
2024-02-03 00:16:34 +00:00 |
|
Exploit-DB
|
cbe784b087
|
DB: 2023-09-09
16 changes to exploits/shellcodes/ghdb
Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
Drupal 10.1.2 - web-cache-poisoning-External-service-interaction
Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
soosyze 2.0.0 - File Upload
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
Wp2Fac - OS Command Injection
Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
SyncBreeze 15.2.24 - 'login' Denial of Service
GOM Player 2.3.90.5360 - Buffer Overflow (PoC)
GOM Player 2.3.90.5360 - Remote Code Execution (RCE)
Windows/x64 - PIC Null-Free TCP Reverse Shell Shellcode (476 Bytes)
|
2023-09-09 00:16:33 +00:00 |
|
Exploit-DB
|
4e246a01fb
|
DB: 2023-09-05
18 changes to exploits/shellcodes/ghdb
DLINK DPH-400SE - Exposure of Sensitive Information
FileMage Gateway 1.10.9 - Local File Inclusion
Academy LMS 6.1 - Arbitrary File Upload
AdminLTE PiHole 5.18 - Broken Access Control
Blood Donor Management System v1.0 - Stored XSS
Bus Reservation System 1.1 - Multiple-SQLi
Credit Lite 1.5.4 - SQL Injection
CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')
Hyip Rio 2.1 - Arbitrary File Upload
Member Login Script 3.3 - Client-side desync
SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)
Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow
Kingo ROOT 1.5.8 - Unquoted Service Path
NVClient v5.0 - Stack Buffer Overflow (DoS)
Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
|
2023-09-05 00:16:27 +00:00 |
|
Exploit-DB
|
e07f33f24d
|
DB: 2023-08-22
17 changes to exploits/shellcodes/ghdb
EuroTel ETL3100 - Transmitter Authorization Bypass (IDOR)
EuroTel ETL3100 - Transmitter Default Credentials
EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download
Color Prediction Game v1.0 - SQL Injection
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
Dolibarr Version 17.0.1 - Stored XSS
Global - Multi School Management System Express v1.0- SQL Injection
OVOO Movie Portal CMS v3.3.3 - SQL Injection
PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities
Taskhub CRM Tool 2.8.6 - SQL Injection
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
TSplus 16.0.0.0 - Remote Work Insecure Files and Folders
TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions
Linux/x64 - memfd_create ELF loader Shellcode (170 bytes)
|
2023-08-22 00:16:22 +00:00 |
|
Exploit-DB
|
743db0e747
|
DB: 2023-07-08
4 changes to exploits/shellcodes/ghdb
Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
Bus Pass Management System 1.0 - 'Search' SQL injection
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
Bus Pass Management System 1.0 - 'Search' SQL injection
Faculty Evaluation System v1.0 - SQL Injection
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
|
2023-07-08 00:16:23 +00:00 |
|
Exploit-DB
|
d7c9ba572a
|
DB: 2023-04-07
50 changes to exploits/shellcodes/ghdb
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
ABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root Access
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
Osprey Pump Controller 1.0.1 - (eventFileSelected) Command Injection
Osprey Pump Controller 1.0.1 - (pseudonym) Semi-blind Command Injection
Osprey Pump Controller 1.0.1 - (userName) Blind Command Injection
Osprey Pump Controller 1.0.1 - Administrator Backdoor Access
Osprey Pump Controller 1.0.1 - Authentication Bypass Credentials Modification
Osprey Pump Controller 1.0.1 - Cross-Site Request Forgery
Osprey Pump Controller 1.0.1 - Predictable Session Token / Session Hijack
Osprey Pump Controller 1.0.1 - Unauthenticated File Disclosure
Osprey Pump Controller 1.0.1 - Unauthenticated Remote Code Execution Exploit
Osprey Pump Controller v1.0.1 - Unauthenticated Reflected XSS
WIMAX SWC-5100W Firmware V(1.11.0.1 :1.9.9.4) - Authenticated RCE
HospitalRun 1.0.0-beta - Local Root Exploit for macOS
Adobe Connect 10 - Username Disclosure
craftercms 4.x.x - CORS
EasyNas 1.1.0 - OS Command Injection
Agilebio Lab Collector Electronic Lab Notebook v4.234 - Remote Code Execution (RCE)
Art Gallery Management System Project in PHP v 1.0 - SQL injection
atrocore 1.5.25 User interaction - Unauthenticated File upload - RCE
Auto Dealer Management System 1.0 - Broken Access Control Exploit
Auto Dealer Management System v1.0 - SQL Injection
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
Auto Dealer Management System v1.0 - SQL Injection on manage_user.php
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
Best pos Management System v1.0 - SQL Injection
ChurchCRM v4.5.3-121fcc1 - SQL Injection
Dompdf 1.2.1 - Remote Code Execution (RCE)
Employee Task Management System v1.0 - Broken Authentication
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
Employee Task Management System v1.0 - SQL Injection on edit-task.php
flatnux 2021-03.25 - Remote Code Execution (Authenticated)
Intern Record System v1.0 - SQL Injection (Unauthenticated)
Kimai-1.30.10 - SameSite Cookie-Vulnerability session hijacking
LDAP Tool Box Self Service Password v1.5.2 - Account takeover
Music Gallery Site v1.0 - Broken Access Control
Music Gallery Site v1.0 - SQL Injection on music_list.php
Music Gallery Site v1.0 - SQL Injection on page Master.php
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
POLR URL 2.3.0 - Shortener Admin Takeover
Purchase Order Management-1.0 - Local File Inclusion
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
modoboa 2.0.4 - Admin TakeOver
pdfkit v0.8.7.2 - Command Injection
FileZilla Client 3.63.1 - 'TextShaping.dl' DLL Hijacking
Windows 11 10.0.22000 - Backup service Privilege Escalation
TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)
Unified Remote 3.13.0 - Remote Code Execution (RCE)
|
2023-04-07 00:16:28 +00:00 |
|
Exploit-DB
|
d46ab98863
|
DB: 2023-04-06
32 changes to exploits/shellcodes/ghdb
Answerdev 1.0.3 - Account Takeover
D-Link DIR-846 - Remote Command Execution (RCE) vulnerability
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
SOUND4 LinkAndShare Transmitter 1.1.2 - Format String Stack Buffer Overflow
ERPNext 12.29 - Cross-Site Scripting (XSS)
Liferay Portal 6.2.5 - Insecure Permissions
GNU screen v4.9.0 - Privilege Escalation
Apache Tomcat 10.1 - Denial Of Service
PostgreSQL 9.6.1 - Remote Code Execution (RCE) (Authenticated)
BTCPay Server v1.7.4 - HTML Injection.
Provide Server v.14.4 XSS - CSRF & Remote Code Execution (RCE)
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
ImageMagick 7.1.0-49 - DoS
bgERP v22.31 (Orlovets) - Cookie Session vulnerability & Cross-Site Scripting (XSS)
Bus Pass Management System 1.0 - Stored Cross-Site Scripting (XSS)
Calendar Event Multi View 1.4.07 - Unauthenticated Arbitrary Event Creation to Cross-Site Scripting (XSS)
CKEditor 5 35.4.0 - Cross-Site Scripting (XSS)
Control Web Panel 7 (CWP7) v0.9.8.1147 - Remote Code Execution (RCE)
Froxlor 2.0.3 Stable - Remote Code Execution (RCE)
ImageMagick 7.1.0-49 - Arbitrary File Read
itech TrainSmart r1044 - SQL injection
Online Eyewear Shop 1.0 - SQL Injection (Unauthenticated)
PhotoShow 3.0 - Remote Code Execution
projectSend r1605 - Remote Code Exectution RCE
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
zstore 6.6.0 - Cross-Site Scripting (XSS)
Binwalk v2.3.2 - Remote Command Execution (RCE)
XWorm Trojan 2.1 - Null Pointer Derefernce DoS
Kardex Mlog MCC 5.7.12 - RCE (Remote Code Execution)
Linux/x86_64 - bash Shellcode with xor encoding
|
2023-04-06 00:16:31 +00:00 |
|
Exploit-DB
|
564d2ddf47
|
DB: 2023-03-30
13 changes to exploits/shellcodes/ghdb
DSL-124 Wireless N300 ADSL2+ - Backup File Disclosure
Uniview NVR301-04S2-P4 - Reflected Cross-Site Scripting (XSS)
Book Store Management System 1.0.0 - Stored Cross-Site Scripting (XSS)
Helmet Store Showroom v1.0 - SQL Injection
Human Resource Management System 1.0 - SQL Injection (unauthenticated)
Revenue Collection System v1.0 - Remote Code Execution (RCE)
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
Outline V1.6.0 - Unquoted Service Path
Inbit Messenger v4.9.0 - Unauthenticated Remote Command Execution (RCE)
Inbit Messenger v4.9.0 - Unauthenticated Remote SEH Overflow
Internet Download Manager v6.41 Build 3 - Remote Code Execution (RCE)
|
2023-03-30 00:16:31 +00:00 |
|
Exploit-DB
|
b137003172
|
DB: 2023-03-28
36 changes to exploits/shellcodes/ghdb
MiniDVBLinux 5.4 - Change Root Password
MiniDVBLinux 5.4 - Remote Root Command Injection
MiniDVBLinux 5.4 - Arbitrary File Read
MiniDVBLinux 5.4 - Unauthenticated Stream Disclosure
MiniDVBLinux 5.4 Simple VideoDiskRecorder Protocol SVDRP - Remote Code Execution (RCE)
MiniDVBLinux <=5.4 - Config Download Exploit
Desktop Central 9.1.0 - Multiple Vulnerabilities
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
Aero CMS v0.0.1 - PHP Code Injection (auth)
Aero CMS v0.0.1 - SQL Injection (no auth)
Atom CMS v2.0 - SQL Injection (no auth)
Canteen-Management v1.0 - SQL Injection
Canteen-Management v1.0 - XSS-Reflected
Clansphere CMS 2011.4 - Stored Cross-Site Scripting (XSS)
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
FlatCore CMS 2.1.1 - Stored Cross-Site Scripting (XSS)
Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) & Remote Command Execution (RCE)
WebTareas 2.4 - RCE (Authorized)
WebTareas 2.4 - Reflected XSS (Unauthorised)
WebTareas 2.4 - SQL Injection (Unauthorised)
WPN-XM Serverstack for Windows 0.8.6 - Multiple Vulnerabilities
Zentao Project Management System 17.0 - Authenticated Remote Code Execution (RCE)
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Grafana <=6.2.4 - HTML Injection
Hex Workshop v6.7 - Buffer overflow DoS
Scdbg 1.0 - Buffer overflow DoS
Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)
AVS Audio Converter 10.3 - Stack Overflow (SEH)
Explorer32++ v1.3.5.531 - Buffer overflow
Frhed (Free hex editor) v1.6.0 - Buffer overflow
Gestionale Open 12.00.00 - 'DB_GO_80' Unquoted Service Path
Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path
Resource Hacker v3.6.0.92 - Buffer overflow
Tftpd32_SE 4.60 - 'Tftpd32_svc' Unquoted Service Path
WiFi Mouse 1.8.3.2 - Remote Code Execution (RCE)
|
2023-03-28 00:16:27 +00:00 |
|
Offensive Security
|
ec8ac60c13
|
DB: 2022-11-22
93 changes to exploits/shellcodes/ghdb
|
2022-11-22 11:08:59 +00:00 |
|
Offensive Security
|
c9e53fa57b
|
DB: 2022-11-12
7 changes to exploits/shellcodes/ghdb
AVEVA InTouch Access Anywhere Secure Gateway 2020 R2 - Path Traversal
MSNSwitch Firmware MNT.2408 - Remote Code Exectuion (RCE)
SmartRG Router SR510n 2.6.13 - RCE (Remote Code Execution)
Open Web Analytics 1.7.3 - Remote Code Execution (RCE)
CVAT 2.0 - SSRF (Server Side Request Forgery)
IOTransfer V4 - Unquoted Service Path
NetTransport 2.96L - Remote Buffer Overflow (DEP Bypass)
Linux/MIPS (Little Endian) - system(telnetd -l /bin/sh) Shellcode (80 bytes)
Linux/MIPS - reboot() Shellcode (32 bytes)
Linux/x86 - execve(/bin/sh) + Socket Re-Use Shellcode (50 bytes)
Linux/x86 - setuid(0) + setgid(0) + execve(/bin/sh_ [/bin/sh_ NULL]) Shellcode (37 bytes)
Windows/x86 - Write-to-file ('pwned' ./f.txt) + Null-Free Shellcode (278 bytes)
|
2022-11-12 09:02:02 +00:00 |
|
Offensive Security
|
b6e780c138
|
DB: 2022-11-10
20 changes to exploits/shellcodes/ghdb
0 new exploits/shellcodes
Too many to list!
|
2022-11-10 23:30:40 +00:00 |
|
Offensive Security
|
d63de06c7a
|
DB: 2022-11-10
2776 changes to exploits/shellcodes/ghdb
|
2022-11-10 16:39:50 +00:00 |
|
Offensive Security
|
3d2fa2f00a
|
DB: 2022-09-22
2 changes to exploits/shellcodes
Wifi HD Wireless Disk Drive 11 - Local File Inclusion
WiFiMouse 1.8.3.4 - Remote Code Execution (RCE)
|
2022-09-22 05:01:51 +00:00 |
|
Offensive Security
|
7cbe771564
|
DB: 2022-09-21
5 changes to exploits/shellcodes
Blink1Control2 2.2.7 - Weak Password Encryption
Mobile Mouse 3.6.0.4 - Remote Code Execution (RCE)
Airspan AirSpot 5410 version 0.3.4.1 - Remote Code Execution (RCE)
Buffalo TeraStation Network Attached Storage (NAS) 1.66 - Authentication Bypass
Bookwyrm v0.4.3 - Authentication Bypass
|
2022-09-21 05:01:54 +00:00 |
|
Offensive Security
|
34afdf0a9d
|
DB: 2022-08-04
1 changes to exploits/shellcodes
|
2022-08-04 05:01:48 +00:00 |
|
Offensive Security
|
16b24da825
|
DB: 2022-08-02
19 changes to exploits/shellcodes
Omnia MPX 1.5.0+r1 - Path Traversal
Easy Chat Server 3.1 - Remote Stack Buffer Overflow (SEH)
OctoBot WebInterface 0.4.3 - Remote Code Execution (RCE)
Wavlink WN533A8 - Cross-Site Scripting (XSS)
Wavlink WN530HG4 - Password Disclosure
Wavlink WN533A8 - Password Disclosure
WordPress Plugin Duplicator 1.4.6 - Unauthenticated Backup Download
WordPress Plugin Duplicator 1.4.7 - Information Disclosure
CuteEditor for PHP 6.6 - Directory Traversal
mPDF 7.0 - Local File Inclusion
NanoCMS v0.4 - Remote Code Execution (RCE) (Authenticated)
Webmin 1.996 - Remote Code Execution (RCE) (Authenticated)
|
2022-08-02 05:01:49 +00:00 |
|
Offensive Security
|
46346f8944
|
DB: 2022-07-22
6 changes to exploits/shellcodes
Kite 1.2021.610.0 - Unquoted Service Path
Dr. Fone 4.0.8 - 'net_updater32.exe' Unquoted Service Path
IOTransfer 4.0 - Remote Code Execution (RCE)
Magnolia CMS 6.2.19 - Stored Cross-Site Scripting (XSS)
CodoForum v5.1 - Remote Code Execution (RCE)
OctoBot WebInterface 0.4.3 - Remote Code Execution (RCE)
|
2022-07-22 05:01:50 +00:00 |
|
Offensive Security
|
3bd99ff836
|
DB: 2022-07-02
1 changes to exploits/shellcodes
WiFi Mouse 1.7.8.5 - Remote Code Execution(v2)
|
2022-07-02 05:01:54 +00:00 |
|
Offensive Security
|
29e275db94
|
DB: 2022-06-15
16 changes to exploits/shellcodes
Real Player v.20.0.8.310 G2 Control - 'DoGoToURL()' Remote Code Execution (RCE)
Real Player 16.0.3.51 - 'external::Import()' Directory Traversal to Remote Code Execution (RCE)
HP LaserJet Professional M1210 MFP Series Receive Fax Service - Unquoted Service Path
Marval MSM v14.19.0.12476 - Remote Code Execution (RCE) (Authenticated)
Virtua Software Cobranca 12S - SQLi
Marval MSM v14.19.0.12476 - Cross-Site Request Forgery (CSRF)
Algo 8028 Control Panel - Remote Code Execution (RCE) (Authenticated)
TP-Link Router AX50 firmware 210730 - Remote Code Execution (RCE) (Authenticated)
Sourcegraph Gitserver 3.36.3 - Remote Code Execution (RCE)
Avantune Genialcloud ProJ 10 - Cross-Site Scripting (XSS)
Pandora FMS v7.0NG.742 - Remote Code Execution (RCE) (Authenticated)
phpIPAM 1.4.5 - Remote Code Execution (RCE) (Authenticated)
ChurchCRM 4.4.5 - SQLi
Old Age Home Management System 1.0 - SQLi Authentication Bypass
SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting (XSS)
SolarView Compact 6.00 - 'pow' Cross-Site Scripting (XSS)
|
2022-06-15 05:01:57 +00:00 |
|
Offensive Security
|
6b9b8c5434
|
DB: 2022-05-13
7 changes to exploits/shellcodes
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (InstallAssistService)
Wondershare Dr.Fone 12.0.7 - Remote Code Execution (RCE)
F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
College Management System 1.0 - 'course_code' SQL Injection (Authenticated)
Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)
TLR-2005KSH - Arbitrary File Delete
|
2022-05-13 05:01:39 +00:00 |
|
Offensive Security
|
be24992411
|
DB: 2022-05-12
42 changes to exploits/shellcodes
UDisk Monitor Z5 Phone - 'MonServiceUDisk.exe' Unquoted Service Path
TCQ - ITeCProteccioAppServer.exe - Unquoted Service Path
Wondershare Dr.Fone 11.4.10 - Insecure File Permissions
ExifTool 12.23 - Arbitrary Code Execution
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (InstallAssistService)
Prime95 Version 30.7 build 9 - Remote Code Execution (RCE)
Akka HTTP 10.1.14 - Denial of Service
USR IOT 4G LTE Industrial Cellular VPN Router 1.0.36 - Remote Root Backdoor
Bookeen Notea - Directory Traversal
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
DLINK DIR850 - Insecure Access Control
DLINK DIR850 - Open Redirect
Apache CouchDB 3.2.1 - Remote Code Execution (RCE)
Tenda HG6 v3.3.0 - Remote Command Injection
Google Chrome 78.0.3904.70 - Remote Code Execution
PyScript - Read Remote Python Source Code
DLINK DAP-1620 A1 v1.01 - Directory Traversal
Ruijie Reyee Mesh Router - Remote Code Execution (RCE) (Authenticated)
ImpressCMS v1.4.4 - Unrestricted File Upload
Microfinance Management System 1.0 - 'customer_number' SQLi
WebTareas 2.4 - Blind SQLi (Authenticated)
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
Magento eCommerce CE v2.3.5-p2 - Blind SQLi
Bitrix24 - Remote Code Execution (RCE) (Authenticated)
CSZ CMS 1.3.0 - 'Multiple' Blind SQLi
Cyclos 4.14.7 - DOM Based Cross-Site Scripting (XSS)
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
e107 CMS v3.2.1 - Multiple Vulnerabilities
Anuko Time Tracker - SQLi (Authenticated)
TLR-2005KSH - Arbitrary File Upload
Explore CMS 1.0 - SQL Injection
Navigate CMS 2.9.4 - Server-Side Request Forgery (SSRF) (Authenticated)
PHProjekt PhpSimplyGest v1.3. - Stored Cross-Site Scripting (XSS)
Beehive Forum - Account Takeover
MyBB 1.8.29 - MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
WordPress Plugin Blue Admin 21.06.01 - Cross-Site Request Forgery (CSRF)
Joomla Plugin SexyPolling 2.1.7 - SQLi
WordPress Plugin stafflist 3.1.2 - SQLi (Authenticated)
|
2022-05-12 05:01:39 +00:00 |
|
Offensive Security
|
093714dc70
|
DB: 2022-04-20
21 changes to exploits/shellcodes
Microsoft Exchange Mailbox Assistants 15.0.847.40 - 'Service MSExchangeMailboxAssistants' Unquoted Service Path
Microsoft Exchange Active Directory Topology 15.0.847.40 - 'Service MSExchangeADTopology' Unquoted Service Path
7-zip - Code Execution / Local Privilege Escalation
PTPublisher v2.3.4 - Unquoted Service Path
EaseUS Data Recovery - 'ensserver.exe' Unquoted Service Path
Zyxel NWA-1100-NH - Command Injection
ManageEngine ADSelfService Plus 6.1 - User Enumeration
Verizon 4G LTE Network Extender - Weak Credentials Algorithm
Delta Controls enteliTOUCH 3.40.3935 - Cross-Site Request Forgery (CSRF)
Delta Controls enteliTOUCH 3.40.3935 - Cross-Site Scripting (XSS)
Delta Controls enteliTOUCH 3.40.3935 - Cookie User Password Disclosure
Scriptcase 9.7 - Remote Code Execution (RCE)
WordPress Plugin Motopress Hotel Booking Lite 4.2.4 - SQL Injection
Easy Appointments 1.4.2 - Information Disclosure
WordPress Plugin Videos sync PDF 1.7.4 - Stored Cross Site Scripting (XSS)
WordPress Plugin Popup Maker 1.16.5 - Stored Cross-Site Scripting (Authenticated)
REDCap 11.3.9 - Stored Cross Site Scripting
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
WordPress Plugin Elementor 3.6.2 - Remote Code Execution (RCE) (Authenticated)
Fuel CMS 1.5.0 - Cross-Site Request Forgery (CSRF)
|
2022-04-20 05:01:45 +00:00 |
|
Offensive Security
|
00bdb64074
|
DB: 2022-03-03
5 changes to exploits/shellcodes
Prowise Reflect v1.0.9 - Remote Keystroke Injection
Printix Client 1.3.1106.0 - Remote Code Execution (RCE)
Xerte 3.10.3 - Directory Traversal (Authenticated)
Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
|
2022-03-03 05:01:37 +00:00 |
|
Offensive Security
|
7755ac3af6
|
DB: 2022-02-24
9 changes to exploits/shellcodes
Adobe ColdFusion 11 - LDAP Java Object Deserialization Remode Code Execution (RCE)
ICL ScadaFlex II SCADA Controllers SC-1/SC-2 1.03.07 - Remote File CRUD
Simple Real Estate Portal System 1.0 - 'id' SQLi
Air Cargo Management System v1.0 - SQLi
aaPanel 6.8.21 - Directory Traversal (Authenticated)
Student Record System 1.0 - 'cid' SQLi (Authenticated)
WebHMI 4.1.1 - Remote Code Execution (RCE) (Authenticated)
WebHMI 4.1 - Stored Cross Site Scripting (XSS) (Authenticated)
Microweber CMS 1.2.10 - Local File Inclusion (Authenticated) (Metasploit)
|
2022-02-24 05:01:36 +00:00 |
|
Offensive Security
|
07b4b32301
|
DB: 2022-02-12
4 changes to exploits/shellcodes
Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated)
Accounting Journal Management System 1.0 - 'id' SQLi (Authenticated)
Subrion CMS 4.2.1 - Cross Site Request Forgery (CSRF) (Add Amin)
|
2022-02-12 05:02:07 +00:00 |
|
Offensive Security
|
41553c4004
|
DB: 2022-02-09
11 changes to exploits/shellcodes
Wing FTP Server 4.3.8 - Remote Code Execution (RCE) (Authenticated)
Hotel Reservation System 1.0 - SQLi (Unauthenticated)
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
Hospital Management System 4.0 - 'multiple' SQL Injection
WordPress Plugin International Sms For Contact Form 7 Integration V1.2 - Cross Site Scripting (XSS)
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
Windows/x86 - Locate kernel32 base address / Stack Crack method NullFree Shellcode (171 bytes)
|
2022-02-09 05:02:00 +00:00 |
|
Offensive Security
|
d3b7d652cc
|
DB: 2022-01-28
5 changes to exploits/shellcodes
PolicyKit-1 0.105-31 - Privilege Escalation
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)
WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
|
2022-01-28 05:01:59 +00:00 |
|
Offensive Security
|
eb2b6f5cfd
|
DB: 2022-01-19
12 changes to exploits/shellcodes
WorkTime 10.20 Build 4967 - Unquoted Service Path
Archeevo 5.0 - Local File Inclusion
Online Resort Management System 1.0 - SQLi (Authenticated)
OpenBMCS 2.4 - Cross Site Request Forgery (CSRF)
OpenBMCS 2.4 - SQLi (Authenticated)
OpenBMCS 2.4 - Create Admin / Remote Privilege Escalation
OpenBMCS 2.4 - Server Side Request Forgery (SSRF) (Unauthenticated)
OpenBMCS 2.4 - Information Disclosure
Simple Chatbot Application 1.0 - Remote Code Execution (RCE)
Simple Chatbot Application 1.0 - 'message' Blind SQLi
Nyron 1.0 - SQLi (Unauthenticated)
Creston Web Interface 1.0.0.2159 - Credential Disclosure
|
2022-01-19 05:01:58 +00:00 |
|
Offensive Security
|
6a94460ed6
|
DB: 2022-01-11
8 changes to exploits/shellcodes
VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
CoreFTP Server build 725 - Directory Traversal (Authenticated)
HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS)
Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated)
Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated)
Online Railway Reservation System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS) (Unauthenticated)
Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated)
|
2022-01-11 05:01:55 +00:00 |
|
Offensive Security
|
1472d8e723
|
DB: 2022-01-06
32 changes to exploits/shellcodes
Siemens S7 Layer 2 - Denial of Service (DoS)
TRIGONE Remote System Monitor 3.61 - Unquoted Service Path
Automox Agent 32 - Local Privilege Escalation
ConnectWise Control 19.2.24707 - Username Enumeration
Accu-Time Systems MAXIMUS 1.0 - Telnet Remote Buffer Overflow (DoS)
AWebServer GhostBuilding 18 - Denial of Service (DoS)
TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
Dixell XWEB 500 - Arbitrary File Write
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
CMSimple 5.4 - Cross Site Scripting (XSS)
RiteCMS 3.1.0 - Arbitrary File Overwrite (Authenticated)
RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated)
RiteCMS 3.1.0 - Remote Code Execution (RCE) (Authenticated)
WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated)
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
Movie Rating System 1.0 - Broken Access Control (Admin Account Creation) (Unauthenticated)
Movie Rating System 1.0 - SQLi to RCE (Unauthenticated)
Online Admission System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
Library System in PHP 1.0 - 'publisher name' Stored Cross-Site Scripting (XSS)
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
Nettmp NNT 5.1 - SQLi Authentication Bypass
Hostel Management System 2.1 - Cross Site Scripting (XSS)
Hospitals Patient Records Management System 1.0 - 'id' SQL Injection (Authenticated)
BeyondTrust Remote Support 6.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
Hospitals Patient Records Management System 1.0 - Account TakeOver
Virtual Airlines Manager 2.6.2 - 'multiple' SQL Injection
Terramaster TOS 4.2.15 - Remote Code Execution (RCE) (Unauthenticated)
Vodafone H-500-s 3.5.10 - WiFi Password Disclosure
openSIS Student Information System 8.0 - 'multiple' SQL Injection
Projeqtor v9.3.1 - Stored Cross Site Scripting (XSS)
WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated)
|
2022-01-06 05:01:54 +00:00 |
|
Offensive Security
|
3d06837f80
|
DB: 2021-12-16
2 changes to exploits/shellcodes
Oliver Library Server v5 - Arbitrary File Download
|
2021-12-16 05:01:55 +00:00 |
|
Offensive Security
|
27af25c8c3
|
DB: 2021-11-02
19 changes to exploits/shellcodes
jQuery UI 1.12.1 - Denial of Service (DoS)
Nsasoft Hardware Software Inventory 1.6.4.0 - 'multiple' Denial of Service (PoC)
Solaris 10 (SPARC) - 'dtprintinfo' Local Privilege Escalation (3)
Microsoft Exchange 2019 - Server-Side Request Forgery
KZTech T3500V 4G LTE CPE 2.0.1 - Weak Default WiFi Password Algorithm
MyBB Timeline Plugin 1.0 - Persistent Cross-Site Scripting
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
WordPress Plugin SuperForms 4.9 - Arbitrary File Upload
Home Assistant Community Store (HACS) 1.10.0 - Directory Traversal
SonicWall SSL-VPN 8.0.0.0 - 'visualdoor' Remote Code Execution (Unauthenticated)
Web Based Quiz System 1.0 - 'MCQ options' Persistent Cross-Site Scripting
Online Ordering System 1.0 - Arbitrary File Upload
Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated)
CouchCMS 2.2.1 - Persistent Cross-Site Scripting
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
MagpieRSS 0.72 - 'url' Command Injection
CouchCMS 2.2.1 - Server-Side Request Forgery
GetSimple CMS My SMTP Contact Plugin 1.1.2 - Persistent Cross-Site Scripting
Montiorr 1.7.6m - Persistent Cross-Site Scripting
|
2021-11-02 05:02:13 +00:00 |
|
Offensive Security
|
1cf7d7364a
|
DB: 2021-10-13
176 changes to exploits/shellcodes
Easy CD & DVD Cover Creator 4.13 - Denial of Service (PoC)
Managed Switch Port Mapping Tool 2.85.2 - Denial of Service (PoC)
Nsasoft Hardware Software Inventory 1.6.4.0 - 'multiple' Denial of Service (PoC)
Sandboxie 5.49.7 - Denial of Service (PoC)
WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service (PoC)
iDailyDiary 4.30 - Denial of Service (PoC)
RarmaRadio 2.72.8 - Denial of Service (PoC)
DupTerminator 1.4.5639.37199 - Denial of Service (PoC)
Color Notes 1.4 - Denial of Service (PoC)
Macaron Notes great notebook 5.5 - Denial of Service (PoC)
My Notes Safe 5.3 - Denial of Service (PoC)
Sticky Notes & Color Widgets 1.4.2 - Denial of Service (PoC)
NBMonitor 1.6.8 - Denial of Service (PoC)
Nsauditor 3.2.3 - Denial of Service (PoC)
Sticky Notes Widget Version 3.0.6 - Denial of Service (PoC)
n+otes 1.6.2 - Denial of Service (PoC)
Secure Notepad Private Notes 3.0.3 - Denial of Service (PoC)
Post-it 5.0.1 - Denial of Service (PoC)
Notex the best notes 6.4 - Denial of Service (PoC)
Solaris 10 1/13 (Intel) - 'dtprintinfo' Local Privilege Escalation (2)
Solaris 10 1/13 (Intel) - 'dtprintinfo' Local Privilege Escalation (3)
Solaris 10 1/13 (SPARC) - 'dtprintinfo' Local Privilege Escalation (1)
Solaris 10 1/13 (SPARC) - 'dtprintinfo' Local Privilege Escalation (2)
Solaris 10 1/13 (SPARC) - 'dtprintinfo' Local Privilege Escalation (3)
MariaDB 10.2 /MySQL - 'wsrep_provider' OS Command Execution
Visual Studio Code 1.47.1 - Denial of Service (PoC)
DELL dbutil_2_3.sys 2.3 - Arbitrary Write to Local Privilege Escalation (LPE)
Backup Key Recovery 2.2.7 - Denial of Service (PoC)
memono Notepad Version 4.2 - Denial of Service (PoC)
Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon)
Dlink DSL2750U - 'Reboot' Command Injection
E-Learning System 1.0 - Authentication Bypass & RCE POC
Netsia SEBA+ 0.16.1 - Authentication Bypass and Add Root User (Metasploit)
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Scripting and Session Fixation
GetSimple CMS 3.3.16 - Reflected XSS to RCE
House Rental and Property Listing 1.0 - Multiple Stored XSS
Resumes Management and Job Application Website 1.0 - Authentication Bypass (Sql Injection)
EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Multiple Stored Cross-Site Scripting
Cisco RV110W 1.2.1.7 - 'vpn_account' Denial of Service (PoC)
Inteno IOPSYS 3.16.4 - root filesystem access via sambashare (Authenticated)
Selea Targa IP OCR-ANPR Camera - RTP/RTSP/M-JPEG Stream Disclosure (Unauthenticated)
CMSUno 1.6.2 - 'lang/user' Remote Code Execution (Authenticated)
WordPress Plugin SuperForms 4.9 - Arbitrary File Upload to Remote Code Execution
Home Assistant Community Store (HACS) 1.10.0 - Path Traversal to Account Takeover
Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated)
Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon) (PoC)
Dolibarr ERP/CRM 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
Montiorr 1.7.6m - File Upload to XSS
GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE
Internship Portal Management System 1.0 - Remote Code Execution Via File Upload (Unauthenticated)
Markdown Explorer 0.1.1 - XSS to RCE
Xmind 2020 - XSS to RCE
Tagstoo 2.0.1 - Stored XSS to RCE
SnipCommand 0.1.0 - XSS to RCE
Moeditor 0.2.0 - XSS to RCE
Marky 0.0.1 - XSS to RCE
StudyMD 0.3.2 - XSS to RCE
Freeter 1.2.1 - XSS to RCE
Markright 1.0 - XSS to RCE
Markdownify 1.2.0 - XSS to RCE
Anote 1.0 - XSS to RCE
Subrion CMS 4.2.1 - File Upload Bypass to RCE (Authenticated)
Printable Staff ID Card Creator System 1.0 - SQLi & RCE via Arbitrary File Upload
Schlix CMS 2.2.6-6 - Arbitary File Upload And Directory Traversal Leads To RCE (Authenticated)
Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver)
CHIYU IoT Devices - Denial of Service (DoS)
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated)
TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated)
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal
Atlassian Jira Server/Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
Phone Shop Sales Managements System 1.0 - 'Multiple' Arbitrary File Upload to Remote Code Execution
ForgeRock Access Manager/OpenAM 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection
Dolibarr ERP/CRM 10.0.6 - Login Brute Force
qdPM 9.2 - DB Connection String and Password Exposure (Unauthenticated)
Simple Phone book/directory 1.0 - 'Username' SQL Injection (Unauthenticated)
ECOA Building Automation System - Hidden Backdoor Accounts and backdoor() Function
Budget and Expense Tracker System 1.0 - Authenticated Bypass
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting (XSS)
Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation via XML Signature Wrapping
Phpwcms 1.9.30 - File Upload to XSS
Linux/x86 - execve(/bin/sh) Shellcode (17 bytes)
Linux/x64 - execve(/bin/sh) Shellcode (21 bytes) (2)
Linux/x86 - setreuid(0) + execve(_/bin/sh_) Shellcode (29 bytes)
Linux/x86 - Bind (User Specified Port) Shell (/bin/sh) Shellcode (102 bytes)
Linux/x86 - Reverse (dynamic IP and port/TCP) Shell (/bin/sh) Shellcode (86 bytes)
Linux/x86 - Egghunter Reverse TCP Shell dynamic IP and port Shellcode
|
2021-10-13 05:02:15 +00:00 |
|
Offensive Security
|
c9a65a1f7b
|
DB: 2021-09-03
52 changes to exploits/shellcodes
|
2021-09-03 21:04:54 +00:00 |
|
Offensive Security
|
b4c96a5864
|
DB: 2021-09-03
28807 changes to exploits/shellcodes
|
2021-09-03 20:19:21 +00:00 |
|
Offensive Security
|
6cbe6ebbb6
|
DB: 2021-09-03
395 changes to exploits/shellcodes
EO Video 1.36 - Local Heap Overflow Denial of Service / (PoC)
Electronics Workbench - '.ewb' Local Stack Overflow (PoC)
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
Easy Web Password 1.2 - Local Heap Memory Consumption (PoC)
Compface 1.5.2 - '.xbm' Local Buffer Overflow (PoC)
eEye Retina WiFi Security Scanner 1.0 - '.rws Parsing' Buffer Overflow (PoC)
Zortam MP3 Media Studio 9.40 - Multiple Memory Corruption Vulnerabilities
ImTOO MPEG Encoder 3.1.53 - '.cue' / '.m3u' Local Buffer Overflow (PoC)
ZoIPer 2.22 - Call-Info Remote Denial of Service
PHP < 5.3.1 - 'MultiPart/form-data' Denial of Service
PHP - MultiPart Form-Data Denial of Service (PoC)
PHP < 5.3.1 - 'MultiPart/form-data' Denial of Service
PHP - MultiPart Form-Data Denial of Service (PoC)
Nuked KLan 1.7.7 & SP4 - Denial of Service
AIC Audio Player 1.4.1.587 - Local Crash (PoC)
Xerox 4595 - Denial of Service
WinMerge 2.12.4 - Project File Handling Stack Overflow
Acoustica Mixcraft 1.00 - Local Crash
SopCast 3.4.7 - 'sop://' URI Handling Remote Stack Buffer Overflow (PoC)
Oreans WinLicense 2.1.8.0 - XML File Handling Memory Corruption
Spotify 0.8.2.610 - search func Memory Exhaustion
Apple iTunes 10.6.1.7 - '.m3u' Walking Heap Buffer Overflow (PoC)
WaveSurfer 1.8.8p4 - Memory Corruption (PoC)
DIMIN Viewer 5.4.0 - Crash (PoC)
FreeVimager 4.1.0 - Crash (PoC)
DIMIN Viewer 5.4.0 - Crash (PoC)
FreeVimager 4.1.0 - Crash (PoC)
CoolPlayer+ Portable 2.19.4 - Local Buffer Overflow
Light Audio Player 1.0.14 - Memory Corruption (PoC)
Image Transfer IOS - Remote Crash (PoC)
Larson VizEx Reader 9.7.5 - Local Buffer Overflow (SEH)
VUPlayer 2.49 - '.cue' Universal Buffer Overflow
Apple Mac OSX xnu 1228.x - 'hfs-fcntl' Kernel Privilege Escalation
IBM AIX 5.3 - 'libc' MALLOCDEBUG File Overwrite
Hex Workshop 4.23/5.1/6.0 - '.hex' Universal Local Buffer Overflow (SEH)
Soritong MP3 Player 1.0 - '.m3u' / UI.txt Universal Local Buffer Overflow
Adobe Acrobat/Reader < 7.1.1/8.1.3/9.1 - Collab getIcon Universal
Millenium MP3 Studio - '.pls' / '.mpf' / '.m3u' Universal Local Buffer Overflow (SEH)
Alleycode HTML Editor 2.2.1 - Local Buffer Overflow
GPG2/Kleopatra 2.0.11 - Malformed Certificate
Free WMA MP3 Converter 1.1 - '.wav' Local Buffer Overflow
OtsTurntables Free 1.00.047 - '.olf' Universal Buffer Overflow
Watermark Master 2.2.23 - '.wstyle' Local Buffer Overflow (SEH)
Dropbox < 3.3.x - OSX FinderLoadBundle Privilege Escalation
MySQL / MariaDB / PerconaDB 5.5.51/5.6.32/5.7.14 - Code Execution / Privilege Escalation
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (1)
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (2)
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (1)
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (2)
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (3)
QK SMTP 3.01 - 'RCPT TO' Remote Buffer Overflow (2)
CA BrightStor ARCserve - 'msgeng.exe' Remote Stack Overflow
quickshare file share 1.2.1 - Directory Traversal (1)
SPlayer 3.7 (build 2055) - Remote Buffer Overflow
Acunetix 8 build 20120704 - Remote Stack Overflow
Omeka 2.2.1 - Remote Code Execution
D-Link DSL-2740R - Remote DNS Change
D-Link DSL-2730U/2750U/2750E ADSL Router - Remote File Disclosure
Netgear JNR1010 ADSL Router - (Authenticated) Remote File Disclosure
D-Link DSL-2730U/2750U/2750E ADSL Router - Remote File Disclosure
Netgear JNR1010 ADSL Router - (Authenticated) Remote File Disclosure
Websphere/JBoss/OpenNMS/Symantec Endpoint Protection Manager - Java Deserialization Remote Code Execution
TorrentTrader 1.0 RC2 - SQL Injection
WEBInsta CMS 0.3.1 - 'templates_dir' Remote File Inclusion
MiniPort@l 0.1.5 Beta - 'skiny' Remote File Inclusion
PHP DocWriter 0.3 - 'script' Remote File Inclusion
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
RSSonate - 'xml2rss.php' Remote File Inclusion
CASTOR 1.1.1 - '/lib/rs.php' Remote File Inclusion
RSSonate - 'xml2rss.php' Remote File Inclusion
CASTOR 1.1.1 - '/lib/rs.php' Remote File Inclusion
QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
BrewBlogger 1.3.1 - 'printLog.php' SQL Injection
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
Tucows Client Code Suite (CSS) 1.2.1015 - Remote File Inclusion
Gizzar 03162002 - 'index.php' Remote File Inclusion
SH-News 0.93 - 'misc.php' Remote File Inclusion
JSBoard 2.0.10 - 'login.php?table' Local File Inclusion
XOOPS Module WF-Links 1.03 - 'cid' SQL Injection
Scorp Book 1.0 - 'smilies.php?config' Remote File Inclusion
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
mxBB Module FAQ & RULES 2.0.0 - Remote File Inclusion
EQdkp 1.3.2 - 'listmembers.php' SQL Injection
FlashBB 1.1.8 - 'sendmsg.php' Remote File Inclusion
SimpleBlog 3.0 - 'comments_get.asp?id' SQL Injection
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CCMS 3.1 Demo - SQL Injection
MoinMoin 1.5.x - 'MOIND_ID' Cookie Login Bypass
BlogPHP 2 - 'id' Cross-Site Scripting / SQL Injection
AuraCMS 1.62 - Multiple SQL Injections
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
RevokeBB 1.0 RC11 - 'Search' SQL Injection
Galatolo Web Manager 1.0 - Cross-Site Scripting / Local File Inclusion
CaupoShop Classic 1.3 - 'saArticle[ID]' SQL Injection
PHPortal 1.2 - Multiple Remote File Inclusions
Libera CMS 1.12 - 'cookie' SQL Injection
Zanfi CMS lite 2.1 / Jaw Portal free - 'FCKeditor' Arbitrary File Upload
WCMS 1.0b - Arbitrary Add Admin
FOSS Gallery Admin 1.0 - Arbitrary File Upload
MemHT Portal 4.0.1 - SQL Injection / Code Execution
Mediatheka 4.2 - Blind SQL Injection
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
XOOPS 2.3.2 - 'mydirname' PHP Remote Code Execution
Joomla! Component Casino 0.3.1 - Multiple SQL Injections s
ZeusCart 2.3 - 'maincatid' SQL Injection
ASP Football Pool 2.3 - Remote Database Disclosure
LightNEasy sql/no-db 2.2.x - System Configuration Disclosure
Zen Cart 1.3.8 - Remote Code Execution
Joomla! Component com_pinboard - 'task' SQL Injection
Joomla! Component com_bookflip - 'book_id' SQL Injection
Messages Library 2.0 - Arbitrary Delete Message
Arab Portal 2.2 - Blind Cookie Authentication Bypass
Joomla! Plugin JD-WordPress 2.0 RC2 - Remote File Inclusion
REZERVI 3.0.2 - Remote Command Execution
Joomla! Component BF Quiz 1.0 - SQL Injection (2)
E-Xoopport Samsara 3.1 (eCal Module) - Blind SQL Injection
AJ Matrix DNA - SQL Injection
Joomla! Component JE Story Submit - Local File Inclusion
CF Image Hosting Script 1.3.82 - File Disclosure
hastymail2 webmail 1.1 rc2 - Persistent Cross-Site Scripting
CMSLogik 1.2.1 - Multiple Vulnerabilities
C.P.Sub 4.5 - Authentication Bypass
WordPress Plugin Slideshow Gallery 1.4.6 - Arbitrary File Upload
Joomla! Component com_hdflvplayer < 2.1.0.1 - SQL Injection
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload
PHPMailer < 5.2.20 - Remote Code Execution
phpIPAM 1.4 - SQL Injection
Joomla! 3.9.0 < 3.9.7 - CSV Injection
|
2021-09-03 14:58:20 +00:00 |
|
Offensive Security
|
36c084c351
|
DB: 2021-09-03
45419 changes to exploits/shellcodes
2 new exploits/shellcodes
Too many to list!
|
2021-09-03 13:39:06 +00:00 |
|
Offensive Security
|
4e7ab00187
|
DB: 2021-08-20
204 changes to exploits/shellcodes
Charity Management System CMS 1.0 - Multiple Vulnerabilities
|
2021-08-20 05:01:51 +00:00 |
|
Offensive Security
|
e6cd1b38eb
|
DB: 2021-03-30
9 changes to exploits/shellcodes
Microsoft Internet Explorer Windows 10 1809 17763.316 - Scripting Engine Memory Corruption
vsftpd 3.0.3 - Remote Denial of Service
WordPress Plugin WP Super Cache 1.7.1 - Remote Code Execution (Authenticated)
TP-Link Devices - 'setDefaultHostname' Stored Cross-site Scripting (Unauthenticated)
Concrete5 8.5.4 - 'name' Stored XSS
Equipment Inventory System 1.0 - 'multiple' Stored XSS
Budget Management System 1.0 - 'Budget title' Stored XSS
Novel Boutique House-plus 3.5.1 - Arbitrary File Download
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
|
2021-03-30 05:01:56 +00:00 |
|
Offensive Security
|
1f32ac253c
|
DB: 2021-03-19
9 changes to exploits/shellcodes
VFS for Git 1.0.21014.1 - 'GVFS.Service' Unquoted Service Path
Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon)
WordPress Plugin Wp-FileManager 6.8 - RCE
Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon)
Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon) (PoC)
rConfig 3.9.6 - 'path' Local File Inclusion (Authenticated)
VestaCP 0.9.8 - 'v_interface' Add IP Stored XSS
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection
Hestia Control Panel 1.3.2 - Arbitrary File Write
rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated)
|
2021-03-19 05:02:05 +00:00 |
|
Offensive Security
|
9a9ff3d288
|
DB: 2021-03-10
4 changes to exploits/shellcodes
FreeLAN 2.2 - 'FreeLAN Service' Unquoted Service Path
Sandboxie Plus v0.7.2 - 'SbieSvc' Unquoted Service Path
bVPN 2.5.1 - 'waselvpnserv' Unquoted Service Path
Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
|
2021-03-10 05:01:56 +00:00 |
|
Offensive Security
|
75667550f6
|
DB: 2021-03-02
5 changes to exploits/shellcodes
WiFi Mouse 1.7.8.5 - Remote Code Execution
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
VMware vCenter Server 7.0 - Unauthenticated File Upload
Online Catering Reservation System 1.0 - Remote Code Execution (Unauthenticated)
Covid-19 Contact Tracing System 1.0 - Remote Code Execution (Unauthenticated)
|
2021-03-02 05:02:01 +00:00 |
|