Exploit-DB
|
3de26153c8
|
DB: 2023-04-02
23 changes to exploits/shellcodes/ghdb
ELSI Smart Floor V3.3.3 - Stored Cross-Site Scripting (XSS)
Hughes Satellite Router HX200 v8.3.1.14 - Remote File Inclusion
Nexxt Router Firmware 42.103.1.5095 - Remote Code Execution (RCE) (Authenticated)
TP-Link TL-WR902AC firmware 210730 (V3) - Remote Code Execution (RCE) (Authenticated)
GeoVision Camera GV-ADR2701 - Authentication Bypass
AD Manager Plus 7122 - Remote Code Execution (RCE)
Enlightenment v0.25.3 - Privilege escalation
Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)
Apache 2.4.x - Buffer Overflow
perfSONAR v4.4.5 - Partial Blind CSRF
SugarCRM 12.2.0 - Remote Code Execution (RCE)
XCMS v1.83 - Remote Command Execution (RCE)
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
AimOne Video Converter V2.04 Build 103 - Buffer Overflow (DoS)
NetIQ/Microfocus Performance Endpoint v5.1 - remote root/SYSTEM exploit
Splashtop 8.71.12001.0 - Unquoted Service Path
Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)
FlipRotation v1.0 decoder - Shellcode (146 bytes)
Linux/x86 - Polymorphic linux x86 Shellcode (92 Bytes)
macOS/x64 - Execve Caesar Cipher String Null-Free Shellcode
|
2023-04-02 00:16:21 +00:00 |
|
Exploit-DB
|
9b56e8731e
|
DB: 2023-04-01
25 changes to exploits/shellcodes/ghdb
EQ Enterprise management system v2.2.0 - SQL Injection
qubes-mirage-firewall v0.8.3 - Denial Of Service (DoS)
ASKEY RTF3505VW-N1 - Privilege Escalation
Bangresto 1.0 - SQL Injection
Bludit 3-14-1 Plugin 'UploadPlugin' - Remote Code Execution (RCE) (Authenticated)
Cacti v1.2.22 - Remote Command Execution (RCE)
Judging Management System v1.0 - Authentication Bypass
Judging Management System v1.0 - Remote Code Execution (RCE)
rconfig 3.9.7 - Sql Injection (Authenticated)
Senayan Library Management System v9.0.0 - SQL Injection
Spitfire CMS 1.0.475 - PHP Object Injection
Textpattern 4.8.8 - Remote Code Execution (RCE) (Authenticated)
WooCommerce v7.1.0 - Remote Code Execution(RCE)
CoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service Path
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Denial Of Service (DoS)
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Authorization Bypass (IDOR)
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Authentication Bypass
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Cross-Site Request Forgery
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Directory Traversal File Write Exploit
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Remote Command Execution (RCE)
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Unauthenticated Factory Reset
SOUND4 Server Service 4.1.102 - Local Privilege Escalation
macOS/x64 - Execve Null-Free Shellcode
|
2023-04-01 00:16:31 +00:00 |
|
Exploit-DB
|
42ade901fe
|
DB: 2023-03-31
22 changes to exploits/shellcodes/ghdb
LISTSERV 17 - Insecure Direct Object Reference (IDOR)
LISTSERV 17 - Reflected Cross Site Scripting (XSS)
Router ZTE-H108NS - Stack Buffer Overflow (DoS)
Router ZTE-H108NS - Authentication Bypass
Boa Web Server v0.94.14 - Authentication Bypass
Covenant v0.5 - Remote Code Execution (RCE)
Dreamer CMS v4.0.0 - SQL Injection
Shoplazza 1.1 - Stored Cross-Site Scripting (XSS)
Virtual Reception v1.0 - Web Server Directory Traversal
4images 1.9 - Remote Command Execution (RCE)
ClicShopping v3.402 - Cross-Site Scripting (XSS)
Concrete5 CME v9.1.3 - Xpath injection
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
Ecommerse v1.0 - Cross-Site Scripting (XSS)
Eve-ng 5.0.1-13 - Stored Cross-Site Scripting (XSS)
myBB forums 1.8.26 - Stored Cross-Site Scripting (XSS)
WPForms 1.7.8 - Cross-Site Scripting (XSS)
CrowdStrike Falcon AGENT 6.44.15806 - Uninstall without Installation Token
Lavasoft web companion 4.1.0.409 - 'DCIservice' Unquoted Service Path
Zillya Total Security 3.0.2367.0 - Local Privilege Escalation
|
2023-03-31 00:16:26 +00:00 |
|
Exploit-DB
|
564d2ddf47
|
DB: 2023-03-30
13 changes to exploits/shellcodes/ghdb
DSL-124 Wireless N300 ADSL2+ - Backup File Disclosure
Uniview NVR301-04S2-P4 - Reflected Cross-Site Scripting (XSS)
Book Store Management System 1.0.0 - Stored Cross-Site Scripting (XSS)
Helmet Store Showroom v1.0 - SQL Injection
Human Resource Management System 1.0 - SQL Injection (unauthenticated)
Revenue Collection System v1.0 - Remote Code Execution (RCE)
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
Outline V1.6.0 - Unquoted Service Path
Inbit Messenger v4.9.0 - Unauthenticated Remote Command Execution (RCE)
Inbit Messenger v4.9.0 - Unauthenticated Remote SEH Overflow
Internet Download Manager v6.41 Build 3 - Remote Code Execution (RCE)
|
2023-03-30 00:16:31 +00:00 |
|
Exploit-DB
|
6bc7a6f9b0
|
DB: 2023-03-29
25 changes to exploits/shellcodes/ghdb
ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
Tapo C310 RTSP server v1.3.0 - Unauthorised Video Stream Access
ZKTeco ZEM/ZMM 8.88 - Missing Authentication
Hashicorp Consul v1.0 - Remote Command Execution (RCE)
X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF)
OPSWAT Metadefender Core - Privilege Escalation
Pega Platform 8.1.0 - Remote Code Execution (RCE)
Beauty-salon v1.0 - Remote Code Execution (RCE)
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
iBooking v1.0.8 - Arbitrary File Upload
Jetpack 11.4 - Cross Site Scripting (XSS)
Moodle LMS 4.0 - Cross-Site Scripting (XSS)
Online shopping system advanced 1.0 - Multiple Vulnerabilities
rukovoditel 3.2.1 - Cross-Site Scripting (XSS)
Senayan Library Management System v9.5.0 - SQL Injection
Social-Share-Buttons v2.2.3 - SQL Injection
Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
YouPHPTube<= 7.8 - Multiple Vulnerabilities
Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
SuperMailer v11.20 - Buffer overflow DoS
Tunnel Interface Driver - Denial of Service
VMware Workstation 15 Pro - Denial of Service
HDD Health 4.2.0.112 - 'HDDHealth' Unquoted Service Path
SugarSync 4.1.3 - 'SugarSync Service' Unquoted Service Path
|
2023-03-29 00:16:31 +00:00 |
|
Exploit-DB
|
b137003172
|
DB: 2023-03-28
36 changes to exploits/shellcodes/ghdb
MiniDVBLinux 5.4 - Change Root Password
MiniDVBLinux 5.4 - Remote Root Command Injection
MiniDVBLinux 5.4 - Arbitrary File Read
MiniDVBLinux 5.4 - Unauthenticated Stream Disclosure
MiniDVBLinux 5.4 Simple VideoDiskRecorder Protocol SVDRP - Remote Code Execution (RCE)
MiniDVBLinux <=5.4 - Config Download Exploit
Desktop Central 9.1.0 - Multiple Vulnerabilities
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
Aero CMS v0.0.1 - PHP Code Injection (auth)
Aero CMS v0.0.1 - SQL Injection (no auth)
Atom CMS v2.0 - SQL Injection (no auth)
Canteen-Management v1.0 - SQL Injection
Canteen-Management v1.0 - XSS-Reflected
Clansphere CMS 2011.4 - Stored Cross-Site Scripting (XSS)
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
FlatCore CMS 2.1.1 - Stored Cross-Site Scripting (XSS)
Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) & Remote Command Execution (RCE)
WebTareas 2.4 - RCE (Authorized)
WebTareas 2.4 - Reflected XSS (Unauthorised)
WebTareas 2.4 - SQL Injection (Unauthorised)
WPN-XM Serverstack for Windows 0.8.6 - Multiple Vulnerabilities
Zentao Project Management System 17.0 - Authenticated Remote Code Execution (RCE)
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Grafana <=6.2.4 - HTML Injection
Hex Workshop v6.7 - Buffer overflow DoS
Scdbg 1.0 - Buffer overflow DoS
Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)
AVS Audio Converter 10.3 - Stack Overflow (SEH)
Explorer32++ v1.3.5.531 - Buffer overflow
Frhed (Free hex editor) v1.6.0 - Buffer overflow
Gestionale Open 12.00.00 - 'DB_GO_80' Unquoted Service Path
Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path
Resource Hacker v3.6.0.92 - Buffer overflow
Tftpd32_SE 4.60 - 'Tftpd32_svc' Unquoted Service Path
WiFi Mouse 1.8.3.2 - Remote Code Execution (RCE)
|
2023-03-28 00:16:27 +00:00 |
|
Exploit-DB
|
79023d1f9c
|
DB: 2023-03-26
22 changes to exploits/shellcodes/ghdb
Password Manager for IIS v2.0 - XSS
DLink DIR 819 A1 - Denial of Service
D-Link DNR-322L <=2.60B15 - Authenticated Remote Code Execution
Abantecart v1.3.2 - Authenticated Remote Code Execution
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
Employee Performance Evaluation System v1.0 - File Inclusion and RCE
GuppY CMS v6.00.10 - Remote Code Execution
Human Resources Management System v1.0 - Multiple SQLi
ImpressCMS v1.4.3 - Authenticated SQL Injection
Lavalite v9.0.0 - XSRF-TOKEN cookie File path traversal
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
Online Diagnostic Lab Management System v1.0 - Remote Code Execution (RCE) (Unauthenticated)
PHPGurukul Online Birth Certificate System V 1.2 - Blind XSS
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
Yoga Class Registration System v1.0 - Multiple SQLi
NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
_camp_ Raspberry Pi camera server 1.0 - Authentication Bypass
System Mechanic v15.5.0.61 - Arbitrary Read/Write
|
2023-03-26 00:16:30 +00:00 |
|
Offensive Security
|
ec8ac60c13
|
DB: 2022-11-22
93 changes to exploits/shellcodes/ghdb
|
2022-11-22 11:08:59 +00:00 |
|
Offensive Security
|
c9e53fa57b
|
DB: 2022-11-12
7 changes to exploits/shellcodes/ghdb
AVEVA InTouch Access Anywhere Secure Gateway 2020 R2 - Path Traversal
MSNSwitch Firmware MNT.2408 - Remote Code Exectuion (RCE)
SmartRG Router SR510n 2.6.13 - RCE (Remote Code Execution)
Open Web Analytics 1.7.3 - Remote Code Execution (RCE)
CVAT 2.0 - SSRF (Server Side Request Forgery)
IOTransfer V4 - Unquoted Service Path
NetTransport 2.96L - Remote Buffer Overflow (DEP Bypass)
Linux/MIPS (Little Endian) - system(telnetd -l /bin/sh) Shellcode (80 bytes)
Linux/MIPS - reboot() Shellcode (32 bytes)
Linux/x86 - execve(/bin/sh) + Socket Re-Use Shellcode (50 bytes)
Linux/x86 - setuid(0) + setgid(0) + execve(/bin/sh_ [/bin/sh_ NULL]) Shellcode (37 bytes)
Windows/x86 - Write-to-file ('pwned' ./f.txt) + Null-Free Shellcode (278 bytes)
|
2022-11-12 09:02:02 +00:00 |
|
Offensive Security
|
b6e780c138
|
DB: 2022-11-10
20 changes to exploits/shellcodes/ghdb
0 new exploits/shellcodes
Too many to list!
|
2022-11-10 23:30:40 +00:00 |
|
Offensive Security
|
8bf3aee631
|
DB: 2022-11-10
2 changes to exploits/shellcodes/ghdb
|
2022-11-10 17:10:37 +00:00 |
|
Offensive Security
|
d63de06c7a
|
DB: 2022-11-10
2776 changes to exploits/shellcodes/ghdb
|
2022-11-10 16:39:50 +00:00 |
|
Offensive Security
|
3d2fa2f00a
|
DB: 2022-09-22
2 changes to exploits/shellcodes
Wifi HD Wireless Disk Drive 11 - Local File Inclusion
WiFiMouse 1.8.3.4 - Remote Code Execution (RCE)
|
2022-09-22 05:01:51 +00:00 |
|
Offensive Security
|
7cbe771564
|
DB: 2022-09-21
5 changes to exploits/shellcodes
Blink1Control2 2.2.7 - Weak Password Encryption
Mobile Mouse 3.6.0.4 - Remote Code Execution (RCE)
Airspan AirSpot 5410 version 0.3.4.1 - Remote Code Execution (RCE)
Buffalo TeraStation Network Attached Storage (NAS) 1.66 - Authentication Bypass
Bookwyrm v0.4.3 - Authentication Bypass
|
2022-09-21 05:01:54 +00:00 |
|
Offensive Security
|
34afdf0a9d
|
DB: 2022-08-04
1 changes to exploits/shellcodes
|
2022-08-04 05:01:48 +00:00 |
|
Offensive Security
|
16b24da825
|
DB: 2022-08-02
19 changes to exploits/shellcodes
Omnia MPX 1.5.0+r1 - Path Traversal
Easy Chat Server 3.1 - Remote Stack Buffer Overflow (SEH)
OctoBot WebInterface 0.4.3 - Remote Code Execution (RCE)
Wavlink WN533A8 - Cross-Site Scripting (XSS)
Wavlink WN530HG4 - Password Disclosure
Wavlink WN533A8 - Password Disclosure
WordPress Plugin Duplicator 1.4.6 - Unauthenticated Backup Download
WordPress Plugin Duplicator 1.4.7 - Information Disclosure
CuteEditor for PHP 6.6 - Directory Traversal
mPDF 7.0 - Local File Inclusion
NanoCMS v0.4 - Remote Code Execution (RCE) (Authenticated)
Webmin 1.996 - Remote Code Execution (RCE) (Authenticated)
|
2022-08-02 05:01:49 +00:00 |
|
Offensive Security
|
dfb28913d0
|
DB: 2022-07-30
7 changes to exploits/shellcodes
Asus GameSDK v1.0.0.4 - 'GameSDK.exe' Unquoted Service Path
rpc.py 0.6.0 - Remote Code Execution (RCE)
Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) - Remote Code Execution
Geonetwork 4.2.0 - XML External Entity (XXE)
Dingtian-DT-R002 3.1.276A - Authentication Bypass
Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Directory Traversal
WordPress Plugin WP-UserOnline 2.87.6 - Stored Cross-Site Scripting (XSS)
|
2022-07-30 05:01:47 +00:00 |
|
Offensive Security
|
46346f8944
|
DB: 2022-07-22
6 changes to exploits/shellcodes
Kite 1.2021.610.0 - Unquoted Service Path
Dr. Fone 4.0.8 - 'net_updater32.exe' Unquoted Service Path
IOTransfer 4.0 - Remote Code Execution (RCE)
Magnolia CMS 6.2.19 - Stored Cross-Site Scripting (XSS)
CodoForum v5.1 - Remote Code Execution (RCE)
OctoBot WebInterface 0.4.3 - Remote Code Execution (RCE)
|
2022-07-22 05:01:50 +00:00 |
|
Offensive Security
|
3bd99ff836
|
DB: 2022-07-02
1 changes to exploits/shellcodes
WiFi Mouse 1.7.8.5 - Remote Code Execution(v2)
|
2022-07-02 05:01:54 +00:00 |
|
Offensive Security
|
29e275db94
|
DB: 2022-06-15
16 changes to exploits/shellcodes
Real Player v.20.0.8.310 G2 Control - 'DoGoToURL()' Remote Code Execution (RCE)
Real Player 16.0.3.51 - 'external::Import()' Directory Traversal to Remote Code Execution (RCE)
HP LaserJet Professional M1210 MFP Series Receive Fax Service - Unquoted Service Path
Marval MSM v14.19.0.12476 - Remote Code Execution (RCE) (Authenticated)
Virtua Software Cobranca 12S - SQLi
Marval MSM v14.19.0.12476 - Cross-Site Request Forgery (CSRF)
Algo 8028 Control Panel - Remote Code Execution (RCE) (Authenticated)
TP-Link Router AX50 firmware 210730 - Remote Code Execution (RCE) (Authenticated)
Sourcegraph Gitserver 3.36.3 - Remote Code Execution (RCE)
Avantune Genialcloud ProJ 10 - Cross-Site Scripting (XSS)
Pandora FMS v7.0NG.742 - Remote Code Execution (RCE) (Authenticated)
phpIPAM 1.4.5 - Remote Code Execution (RCE) (Authenticated)
ChurchCRM 4.4.5 - SQLi
Old Age Home Management System 1.0 - SQLi Authentication Bypass
SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting (XSS)
SolarView Compact 6.00 - 'pow' Cross-Site Scripting (XSS)
|
2022-06-15 05:01:57 +00:00 |
|
Offensive Security
|
6b9b8c5434
|
DB: 2022-05-13
7 changes to exploits/shellcodes
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (InstallAssistService)
Wondershare Dr.Fone 12.0.7 - Remote Code Execution (RCE)
F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
College Management System 1.0 - 'course_code' SQL Injection (Authenticated)
Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)
TLR-2005KSH - Arbitrary File Delete
|
2022-05-13 05:01:39 +00:00 |
|
Offensive Security
|
be24992411
|
DB: 2022-05-12
42 changes to exploits/shellcodes
UDisk Monitor Z5 Phone - 'MonServiceUDisk.exe' Unquoted Service Path
TCQ - ITeCProteccioAppServer.exe - Unquoted Service Path
Wondershare Dr.Fone 11.4.10 - Insecure File Permissions
ExifTool 12.23 - Arbitrary Code Execution
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (InstallAssistService)
Prime95 Version 30.7 build 9 - Remote Code Execution (RCE)
Akka HTTP 10.1.14 - Denial of Service
USR IOT 4G LTE Industrial Cellular VPN Router 1.0.36 - Remote Root Backdoor
Bookeen Notea - Directory Traversal
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
DLINK DIR850 - Insecure Access Control
DLINK DIR850 - Open Redirect
Apache CouchDB 3.2.1 - Remote Code Execution (RCE)
Tenda HG6 v3.3.0 - Remote Command Injection
Google Chrome 78.0.3904.70 - Remote Code Execution
PyScript - Read Remote Python Source Code
DLINK DAP-1620 A1 v1.01 - Directory Traversal
Ruijie Reyee Mesh Router - Remote Code Execution (RCE) (Authenticated)
ImpressCMS v1.4.4 - Unrestricted File Upload
Microfinance Management System 1.0 - 'customer_number' SQLi
WebTareas 2.4 - Blind SQLi (Authenticated)
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
Magento eCommerce CE v2.3.5-p2 - Blind SQLi
Bitrix24 - Remote Code Execution (RCE) (Authenticated)
CSZ CMS 1.3.0 - 'Multiple' Blind SQLi
Cyclos 4.14.7 - DOM Based Cross-Site Scripting (XSS)
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
e107 CMS v3.2.1 - Multiple Vulnerabilities
Anuko Time Tracker - SQLi (Authenticated)
TLR-2005KSH - Arbitrary File Upload
Explore CMS 1.0 - SQL Injection
Navigate CMS 2.9.4 - Server-Side Request Forgery (SSRF) (Authenticated)
PHProjekt PhpSimplyGest v1.3. - Stored Cross-Site Scripting (XSS)
Beehive Forum - Account Takeover
MyBB 1.8.29 - MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
WordPress Plugin Blue Admin 21.06.01 - Cross-Site Request Forgery (CSRF)
Joomla Plugin SexyPolling 2.1.7 - SQLi
WordPress Plugin stafflist 3.1.2 - SQLi (Authenticated)
|
2022-05-12 05:01:39 +00:00 |
|
Offensive Security
|
004fdfd467
|
DB: 2022-04-27
4 changes to exploits/shellcodes
7-zip - Code Execution / Local Privilege Escalation
Gitlab 14.9 - Authentication Bypass
GitLab 14.9 - Stored Cross-Site Scripting (XSS)
|
2022-04-27 05:01:59 +00:00 |
|
Offensive Security
|
093714dc70
|
DB: 2022-04-20
21 changes to exploits/shellcodes
Microsoft Exchange Mailbox Assistants 15.0.847.40 - 'Service MSExchangeMailboxAssistants' Unquoted Service Path
Microsoft Exchange Active Directory Topology 15.0.847.40 - 'Service MSExchangeADTopology' Unquoted Service Path
7-zip - Code Execution / Local Privilege Escalation
PTPublisher v2.3.4 - Unquoted Service Path
EaseUS Data Recovery - 'ensserver.exe' Unquoted Service Path
Zyxel NWA-1100-NH - Command Injection
ManageEngine ADSelfService Plus 6.1 - User Enumeration
Verizon 4G LTE Network Extender - Weak Credentials Algorithm
Delta Controls enteliTOUCH 3.40.3935 - Cross-Site Request Forgery (CSRF)
Delta Controls enteliTOUCH 3.40.3935 - Cross-Site Scripting (XSS)
Delta Controls enteliTOUCH 3.40.3935 - Cookie User Password Disclosure
Scriptcase 9.7 - Remote Code Execution (RCE)
WordPress Plugin Motopress Hotel Booking Lite 4.2.4 - SQL Injection
Easy Appointments 1.4.2 - Information Disclosure
WordPress Plugin Videos sync PDF 1.7.4 - Stored Cross Site Scripting (XSS)
WordPress Plugin Popup Maker 1.16.5 - Stored Cross-Site Scripting (Authenticated)
REDCap 11.3.9 - Stored Cross Site Scripting
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
WordPress Plugin Elementor 3.6.2 - Remote Code Execution (RCE) (Authenticated)
Fuel CMS 1.5.0 - Cross-Site Request Forgery (CSRF)
|
2022-04-20 05:01:45 +00:00 |
|
Offensive Security
|
6457d1796d
|
DB: 2022-04-12
7 changes to exploits/shellcodes
MiniTool Partition Wizard - Unquoted Service Path
Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI)
SAM SUNNY TRIPOWER 5.0 - Insecure Direct Object Reference (IDOR)
Telesquare TLR-2855KS6 - Arbitrary File Creation
Telesquare TLR-2855KS6 - Arbitrary File Deletion
Razer Sila - Local File Inclusion (LFI)
Razer Sila - Command Injection
|
2022-04-12 05:01:35 +00:00 |
|
Offensive Security
|
50cc2edafe
|
DB: 2022-04-08
9 changes to exploits/shellcodes
Sherpa Connector Service v2020.2.20328.2050 - Unquoted Service Path
binutils 2.37 - Objdump Segmentation Fault
Kramer VIAware - Remote Code Execution (RCE) (Root)
Opmon 9.11 - Cross-site Scripting
Zenario CMS 9.0.54156 - Remote Code Execution (RCE) (Authenticated)
KLiK Social Media Website 1.0 - 'Multiple' SQLi
minewebcms 1.15.2 - Cross-site Scripting (XSS)
qdPM 9.2 - Cross-site Request Forgery (CSRF)
ICEHRM 31.0.0.0S - Cross-site Request Forgery (CSRF) to Account Deletion
|
2022-04-08 05:01:37 +00:00 |
|
Offensive Security
|
498e749e36
|
DB: 2022-03-24
3 changes to exploits/shellcodes
ProtonVPN 1.26.0 - Unquoted Service Path
WordPress Plugin amministrazione-aperta 3.7.3 - Local File Read - Unauthenticated
|
2022-03-24 05:01:37 +00:00 |
|
Offensive Security
|
e55394b7d4
|
DB: 2022-03-23
6 changes to exploits/shellcodes
Sysax FTP Automation 6.9.0 - Privilege Escalation
iRZ Mobile Router - CSRF to RCE
Ivanti Endpoint Manager 4.6 - Remote Code Execution (RCE)
ICT Protege GX/WX 2.08 - Stored Cross-Site Scripting (XSS)
ICT Protege GX/WX 2.08 - Client-Side SHA1 Password Hash Disclosure
ICEHRM 31.0.0.0S - Cross-site Request Forgery (CSRF) to Account Takeover
|
2022-03-23 05:01:38 +00:00 |
|
Offensive Security
|
2ad6c86451
|
DB: 2022-03-15
4 changes to exploits/shellcodes
VIVE Runtime Service - 'ViveAgentService' Unquoted Service Path
Siemens S7-1200 - Unauthenticated Start/Stop Command
Baixar GLPI Project 9.4.6 - SQLi
|
2022-03-15 05:01:36 +00:00 |
|
Offensive Security
|
88a02fb8d8
|
DB: 2022-03-11
8 changes to exploits/shellcodes
Sony playmemories home - 'PMBDeviceInfoProvider' Unquoted Service Path
McAfee(R) Safe Connect VPN - Unquoted Service Path Elevation Of Privilege
BattlEye 0.9 - 'BEService' Unquoted Service Path
WOW21 5.0.1.9 - 'Service WOW21_Service' Unquoted Service Path
Sandboxie-Plus 5.50.2 - 'Service SbieSvc' Unquoted Service Path
Siemens S7-1200 - Unauthenticated Start/Stop Command
Zabbix 5.0.17 - Remote Code Execution (RCE) (Authenticated)
|
2022-03-11 05:01:39 +00:00 |
|
Offensive Security
|
280b8f430a
|
DB: 2022-03-10
5 changes to exploits/shellcodes
Cobian Backup 0.9 - Unquoted Service Path
Audio Conversion Wizard v2.01 - Buffer Overflow
Printix Client 1.3.1106.0 - Privilege Escalation
Wondershare Dr.Fone 12.0.18 - 'Wondershare InstallAssist' Unquoted Service Path
Webmin 1.984 - Remote Code Execution (Authenticated)
|
2022-03-10 05:01:37 +00:00 |
|
Offensive Security
|
e8863e001f
|
DB: 2022-03-08
9 changes to exploits/shellcodes
Private Internet Access 3.3 - 'pia-service' Unquoted Service Path
Cloudflare WARP 1.4 - Unquoted Service Path
Malwarebytes 4.5 - Unquoted Service Path
Foxit PDF Reader 11.0 - Unquoted Service Path
Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
part-db 0.5.11 - Remote Code Execution (RCE)
Attendance and Payroll System v1.0 - Remote Code Execution (RCE)
Attendance and Payroll System v1.0 - SQLi Authentication Bypass
Hasura GraphQL 2.2.0 - Information Disclosure
|
2022-03-08 05:01:37 +00:00 |
|
Offensive Security
|
00bdb64074
|
DB: 2022-03-03
5 changes to exploits/shellcodes
Prowise Reflect v1.0.9 - Remote Keystroke Injection
Printix Client 1.3.1106.0 - Remote Code Execution (RCE)
Xerte 3.10.3 - Directory Traversal (Authenticated)
Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
|
2022-03-03 05:01:37 +00:00 |
|
Offensive Security
|
bba496461e
|
DB: 2022-03-01
6 changes to exploits/shellcodes
Cobian Reflector 0.9.93 RC1 - 'Password' Denial of Service (PoC)
Cobian Backup 11 Gravity 11.2.0.582 - 'Password' Denial of Service (PoC)
Cobian Backup Gravity 11.2.0.582 - 'CobianBackup11' Unquoted Service Path
WAGO 750-8212 PFC200 G2 2ETH RS - Privilege Escalation
Cipi Control Panel 3.1.15 - Stored Cross-Site Scripting (XSS) (Authenticated)
Casdoor 1.13.0 - SQL Injection (Unauthenticated)
|
2022-03-01 05:01:37 +00:00 |
|
Offensive Security
|
d0f0ae746a
|
DB: 2022-02-25
2 changes to exploits/shellcodes
Wondershare MirrorGo 2.0.11.346 - Insecure File Permissions
|
2022-02-25 05:01:36 +00:00 |
|
Offensive Security
|
7755ac3af6
|
DB: 2022-02-24
9 changes to exploits/shellcodes
Adobe ColdFusion 11 - LDAP Java Object Deserialization Remode Code Execution (RCE)
ICL ScadaFlex II SCADA Controllers SC-1/SC-2 1.03.07 - Remote File CRUD
Simple Real Estate Portal System 1.0 - 'id' SQLi
Air Cargo Management System v1.0 - SQLi
aaPanel 6.8.21 - Directory Traversal (Authenticated)
Student Record System 1.0 - 'cid' SQLi (Authenticated)
WebHMI 4.1.1 - Remote Code Execution (RCE) (Authenticated)
WebHMI 4.1 - Stored Cross Site Scripting (XSS) (Authenticated)
Microweber CMS 1.2.10 - Local File Inclusion (Authenticated) (Metasploit)
|
2022-02-24 05:01:36 +00:00 |
|
Offensive Security
|
8691f166f7
|
DB: 2022-02-22
12 changes to exploits/shellcodes
HMA VPN 5.3 - Unquoted Service Path
Cyclades Serial Console Server 3.3.0 - Local Privilege Escalation
Microsoft Gaming Services 2.52.13001.0 - Unquoted Service Path
WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
Cab Management System 1.0 - 'id' SQLi (Authenticated)
Microweber 1.2.11 - Remote Code Execution (RCE) (Authenticated)
Cab Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
Thinfinity VirtualUI 2.5.41.0 - IFRAME Injection
Thinfinity VirtualUI 2.5.26.2 - Information Disclosure
WordPress Plugin WP User Frontend 3.5.25 - SQLi (Authenticated)
FileCloud 21.2 - Cross-Site Request Forgery (CSRF)
Dbltek GoIP - Local File Inclusion
|
2022-02-22 05:01:37 +00:00 |
|
Offensive Security
|
f2d7e05ad0
|
DB: 2022-02-19
17 changes to exploits/shellcodes
Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path
Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path
Wondershare FamiSafe 1.0 - 'FSService' Unquoted Service Path
Wondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service Path
TOSHIBA DVD PLAYER Navi Support Service - 'TNaviSrv' Unquoted Service Path
Bluetooth Application 5.4.277 - 'BlueSoleilCS' Unquoted Service Path
Intel(R) Management Engine Components 6.0.0.1189 - 'LMS' Unquoted Service Path
File Sanitizer for HP ProtectTools 5.0.1.3 - 'HPFSService' Unquoted Service Path
Connectify Hotspot 2018 'ConnectifyService' - Unquoted Service Path
WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
WordPress Plugin dzs-zoomsounds 6.60 - Remote Code Execution (RCE) (Unauthenticated)
Hotel Druid 3.0.3 - Remote Code Execution (RCE)
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
Solaris/SPARC - setuid(0) + chmod (/bin/ksh) + exit(0) Shellcode
Solaris/SPARC - chmod(./me) Shellcode
Solaris/SPARC - setuid(0) + execve (/bin/ksh) Shellcode
Linux/MIPS - N32 MSB Reverse Shell Shellcode
|
2022-02-19 05:01:36 +00:00 |
|
Offensive Security
|
a300bd948f
|
DB: 2022-02-17
8 changes to exploits/shellcodes
TeamSpeak 3.5.6 - Insecure File Permissions
Emerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path
H3C SSL VPN - Username Enumeration
Multi-Vendor Online Groceries Management System 1.0 - 'id' Blind SQL Injection
Simple Student Quarterly Result/Grade System 1.0 - SQLi Authentication Bypass
ServiceNow - Username Enumeration
Network Video Recorder NVR304-16EP - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
|
2022-02-17 05:01:36 +00:00 |
|
Offensive Security
|
07b4b32301
|
DB: 2022-02-12
4 changes to exploits/shellcodes
Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated)
Accounting Journal Management System 1.0 - 'id' SQLi (Authenticated)
Subrion CMS 4.2.1 - Cross Site Request Forgery (CSRF) (Add Amin)
|
2022-02-12 05:02:07 +00:00 |
|
Offensive Security
|
a6102b7922
|
DB: 2022-02-11
8 changes to exploits/shellcodes
Cain & Abel 4.9.56 - Unquoted Service Path
Hospital Management Startup 1.0 - 'Multiple' SQLi
Home Owners Collection Management System 1.0 - Account Takeover (Unauthenticated)
Home Owners Collection Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
Home Owners Collection Management System 1.0 - 'id' Blind SQL Injection
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
WordPress Plugin Contact Form Builder 1.6.1 - Cross-Site Scripting (XSS)
WordPress Plugin Jetpack 9.1 - Cross Site Scripting (XSS)
|
2022-02-11 05:02:01 +00:00 |
|
Offensive Security
|
41553c4004
|
DB: 2022-02-09
11 changes to exploits/shellcodes
Wing FTP Server 4.3.8 - Remote Code Execution (RCE) (Authenticated)
Hotel Reservation System 1.0 - SQLi (Unauthenticated)
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
Hospital Management System 4.0 - 'multiple' SQL Injection
WordPress Plugin International Sms For Contact Form 7 Integration V1.2 - Cross Site Scripting (XSS)
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
Windows/x86 - Locate kernel32 base address / Stack Crack method NullFree Shellcode (171 bytes)
|
2022-02-09 05:02:00 +00:00 |
|
Offensive Security
|
30be173453
|
DB: 2022-02-05
8 changes to exploits/shellcodes
FLAME II MODEM USB - Unquoted Service Path
WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)
WordPress Plugin IP2Location Country Blocker 2.26.7 - Stored Cross Site Scripting (XSS) (Authenticated)
Servisnet Tessa - Privilege Escalation (Metasploit)
Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit)
Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit)
Windows/x86 - Download File and Execute / Dynamic PEB & EDT method Shellcode (458 bytes)
Windows/x86 - Locate kernel32 base address / Memory Sieve method Shellcode (133 bytes)
|
2022-02-05 05:01:59 +00:00 |
|
Offensive Security
|
ad453a2c73
|
DB: 2022-02-03
17 changes to exploits/shellcodes
CONTPAQi(R) AdminPAQ 14.0.0 - Unquoted Service Path
Mozilla Firefox 67 - Array.pop JIT Type Confusion
Fetch Softworks Fetch FTP Client 5.8 - Remote CPU Consumption (Denial of Service)
Ametys CMS v4.4.1 - Cross Site Scripting (XSS)
uBidAuction v2.0.1 - 'Multiple' Cross Site Scripting (XSS)
Chamilo LMS 1.11.14 - Account Takeover
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
PHP Restaurants 1.0 - SQLi (Unauthenticated)
Moodle 3.11.4 - SQL Injection
Huawei DG8045 Router 1.0 - Credential Disclosure
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
|
2022-02-03 05:01:57 +00:00 |
|
Offensive Security
|
4dfb7acc62
|
DB: 2022-01-29
5 changes to exploits/shellcodes
|
2022-01-29 05:02:01 +00:00 |
|
Offensive Security
|
d3b7d652cc
|
DB: 2022-01-28
5 changes to exploits/shellcodes
PolicyKit-1 0.105-31 - Privilege Escalation
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)
WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
|
2022-01-28 05:01:59 +00:00 |
|
Offensive Security
|
eb2b6f5cfd
|
DB: 2022-01-19
12 changes to exploits/shellcodes
WorkTime 10.20 Build 4967 - Unquoted Service Path
Archeevo 5.0 - Local File Inclusion
Online Resort Management System 1.0 - SQLi (Authenticated)
OpenBMCS 2.4 - Cross Site Request Forgery (CSRF)
OpenBMCS 2.4 - SQLi (Authenticated)
OpenBMCS 2.4 - Create Admin / Remote Privilege Escalation
OpenBMCS 2.4 - Server Side Request Forgery (SSRF) (Unauthenticated)
OpenBMCS 2.4 - Information Disclosure
Simple Chatbot Application 1.0 - Remote Code Execution (RCE)
Simple Chatbot Application 1.0 - 'message' Blind SQLi
Nyron 1.0 - SQLi (Unauthenticated)
Creston Web Interface 1.0.0.2159 - Credential Disclosure
|
2022-01-19 05:01:58 +00:00 |
|
Offensive Security
|
00e20a3a1c
|
DB: 2022-01-13
3 changes to exploits/shellcodes
Microsoft Windows .Reg File - Dialog Spoof / Mitigation Bypass
Microsoft Windows Defender - Detections Bypass
WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)
|
2022-01-13 05:01:58 +00:00 |
|
Offensive Security
|
6a94460ed6
|
DB: 2022-01-11
8 changes to exploits/shellcodes
VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
CoreFTP Server build 725 - Directory Traversal (Authenticated)
HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS)
Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated)
Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated)
Online Railway Reservation System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS) (Unauthenticated)
Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated)
|
2022-01-11 05:01:55 +00:00 |
|
Offensive Security
|
1472d8e723
|
DB: 2022-01-06
32 changes to exploits/shellcodes
Siemens S7 Layer 2 - Denial of Service (DoS)
TRIGONE Remote System Monitor 3.61 - Unquoted Service Path
Automox Agent 32 - Local Privilege Escalation
ConnectWise Control 19.2.24707 - Username Enumeration
Accu-Time Systems MAXIMUS 1.0 - Telnet Remote Buffer Overflow (DoS)
AWebServer GhostBuilding 18 - Denial of Service (DoS)
TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
Dixell XWEB 500 - Arbitrary File Write
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
CMSimple 5.4 - Cross Site Scripting (XSS)
RiteCMS 3.1.0 - Arbitrary File Overwrite (Authenticated)
RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated)
RiteCMS 3.1.0 - Remote Code Execution (RCE) (Authenticated)
WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated)
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
Movie Rating System 1.0 - Broken Access Control (Admin Account Creation) (Unauthenticated)
Movie Rating System 1.0 - SQLi to RCE (Unauthenticated)
Online Admission System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
Library System in PHP 1.0 - 'publisher name' Stored Cross-Site Scripting (XSS)
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
Nettmp NNT 5.1 - SQLi Authentication Bypass
Hostel Management System 2.1 - Cross Site Scripting (XSS)
Hospitals Patient Records Management System 1.0 - 'id' SQL Injection (Authenticated)
BeyondTrust Remote Support 6.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
Hospitals Patient Records Management System 1.0 - Account TakeOver
Virtual Airlines Manager 2.6.2 - 'multiple' SQL Injection
Terramaster TOS 4.2.15 - Remote Code Execution (RCE) (Unauthenticated)
Vodafone H-500-s 3.5.10 - WiFi Password Disclosure
openSIS Student Information System 8.0 - 'multiple' SQL Injection
Projeqtor v9.3.1 - Stored Cross Site Scripting (XSS)
WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated)
|
2022-01-06 05:01:54 +00:00 |
|