Offensive Security
c385c8068c
DB: 2021-07-20
...
6 changes to exploits/shellcodes
WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated)
WordPress Plugin LearnPress 3.2.6.8 - Privilege Escalation
WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher ID field' Stored Cross-Site Scripting (XSS)
Dolibarr ERP/CRM 10.0.6 - Login Brute Force
PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection
Linux/x86 - Egghunter Reverse TCP Shell dynamic IP and port Shellcode
2021-07-20 05:01:52 +00:00
Offensive Security
29558b9c84
DB: 2021-07-17
...
6 changes to exploits/shellcodes
Argus Surveillance DVR 4.0 - Weak Password Encryption
Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation
Aruba Instant 8.7.1.0 - Arbitrary File Modification
Aruba Instant (IAP) - Remote Code Execution
ForgeRock Access Manager/OpenAM 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection
2021-07-17 05:01:54 +00:00
Offensive Security
680397ce33
DB: 2021-07-16
...
4 changes to exploits/shellcodes
Webmin 1.973 - Cross-Site Request Forgery (CSRF)
osCommerce 2.3.4.1 - Remote Code Execution (2)
WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated)
2021-07-16 05:01:53 +00:00
Offensive Security
42322e3bcd
DB: 2021-07-15
...
2 changes to exploits/shellcodes
Webmin 1.973 - Cross-Site Request Forgery (CSRF)
WordPress Plugin Current Book 1.0.1 - 'Book Title and Author field' Stored Cross-Site Scripting (XSS)
2021-07-15 05:01:54 +00:00
Offensive Security
906bbc4943
DB: 2021-07-14
...
8 changes to exploits/shellcodes
Apache Tomcat 9.0.0.M1 - Open Redirect
WordPress Plugin WPFront Notification Bar 1.9.1.04012 - Stored Cross-Site Scripting (XSS)
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
Invoice System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2)
Garbage Collection Management System 1.0 - SQL Injection + Arbitrary File Upload
Linux/x86 - Bind (User Specified Port) Shell (/bin/sh) Shellcode (102 bytes)
Linux/x86 - Reverse (dynamic IP and port/TCP) Shell (/bin/sh) Shellcode (86 bytes)
2021-07-14 05:01:54 +00:00
Offensive Security
efd4a69880
DB: 2021-07-10
...
3 changes to exploits/shellcodes
Church Management System 1.0 - SQL Injection (Authentication Bypass) + Arbitrary File Upload + RCE
Zoo Management System 1.0 - 'Multiple' Stored Cross-Site-Scripting (XSS)
2021-07-10 05:01:53 +00:00
Offensive Security
57766a2587
DB: 2021-07-09
...
5 changes to exploits/shellcodes
Exam Hall Management System 1.0 - Unrestricted File Upload + RCE (Unauthenticated)
Employee Record Management System 1.2 - Stored Cross-Site Scripting (XSS)
Wyomind Help Desk 1.3.6 - Remote Code Execution (RCE)
Online Covid Vaccination Scheduler System 1.0 - Arbitrary File Upload to Remote Code Execution (Unauthenticated)
Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated)
2021-07-09 05:01:53 +00:00
Offensive Security
c19f7edfef
DB: 2021-07-08
...
4 changes to exploits/shellcodes
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
Online Covid Vaccination Scheduler System 1.0 - 'username' time-based blind SQL Injection
WordPress Plugin Plainview Activity Monitor 20161228 - Remote Code Execution (RCE) (Authenticated) (2)
2021-07-08 05:01:54 +00:00
Offensive Security
1514ca02a7
DB: 2021-07-07
...
13 changes to exploits/shellcodes
Huawei dg8045 - Authentication Bypass
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal
perfexcrm 1.10 - 'State' Stored Cross-site scripting (XSS)
Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated)
Netgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated)
Black Box Kvm Extender 3.4.31307 - Local File Inclusion
Pallets Werkzeug 0.15.4 - Path Traversal
Billing System Project 1.0 - Remote Code Execution (RCE) (Unauthenticated)
Exam Hall Management System 1.0 - Unrestricted File Upload (Unauthenticated)
Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation
Phone Shop Sales Managements System 1.0 - Authentication Bypass (SQLi)
Phone Shop Sales Managements System 1.0 - 'Multiple' Arbitrary File Upload to Remote Code Execution
2021-07-07 05:02:02 +00:00
Offensive Security
540825f140
DB: 2021-07-06
...
11 changes to exploits/shellcodes
WordPress Plugin WP Learn Manager 1.1.2 - Stored Cross-Site Scripting (XSS)
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2)
Online Voting System 1.0 - SQLi (Authentication Bypass) + Remote Code Execution (RCE)
Online Birth Certificate System 1.1 - 'Multiple' Stored Cross-Site Scripting (XSS)
Church Management System 1.0 - Unrestricted File Upload to Remote Code Execution (Authenticated)
Church Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
Church Management System 1.0 - 'password' SQL Injection (Authentication Bypass)
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
Simple Client Management System 1.0 - Remote Code Execution (RCE)
TextPattern CMS 4.9.0-dev - Remote Command Execution (RCE) (Authenticated)
Ricon Industrial Cellular Router S9922XL - Remote Command Execution (RCE)
2021-07-06 05:02:03 +00:00
Offensive Security
5bd61e68a2
DB: 2021-07-03
...
7 changes to exploits/shellcodes
WinWaste.NET 1.0.6183.16475 - Privilege Escalation due Incorrect Access Control
Scratch Desktop 3.17 - Cross-Site Scripting/Remote Code Execution (XSS/RCE)
AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)
b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF)
Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated)
Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated)
Garbage Collection Management System 1.0 - SQL Injection (Unauthenticated)
2021-07-03 05:01:54 +00:00
Offensive Security
4f3cf46cbf
DB: 2021-07-02
...
4 changes to exploits/shellcodes
Online Voting System 1.0 - Authentication Bypass (SQLi)
Online Voting System 1.0 - Remote Code Execution (Authenticated)
Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated)
Vianeos OctoPUS 5 - 'login_user' SQLi
2021-07-02 05:01:54 +00:00
Offensive Security
293ca2aadb
DB: 2021-07-01
...
6 changes to exploits/shellcodes
SAS Environment Manager 2.5 - 'name' Stored Cross-Site Scripting (XSS)
Doctors Patients Management System 1.0 - SQL Injection (Authentication Bypass)
phpAbook 0.9i - SQL Injection
Apache Superset 1.1.0 - Time-Based Account Enumeration
Simple Traffic Offense System 1.0 - Stored Cross Site Scripting (XSS)
2021-07-01 05:01:57 +00:00
Offensive Security
e79da91025
DB: 2021-06-30
...
1 changes to exploits/shellcodes
ES File Explorer 4.1.9.7.4 - Arbitrary File Read
2021-06-30 05:02:04 +00:00
Offensive Security
9008c67d8b
DB: 2021-06-29
...
5 changes to exploits/shellcodes
WordPress Plugin YOP Polls 6.2.7 - Stored Cross Site Scripting (XSS)
SAS Environment Manager 2.5 - 'name' Stored Cross-Site Scripting (XSS)
Atlassian Jira Server/Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
Netgear WNAP320 2.0.3 - 'macAddress' Remote Code Execution (RCE) (Unauthenticated)
2021-06-29 05:01:55 +00:00
Offensive Security
4fbb1eb22a
DB: 2021-06-26
...
5 changes to exploits/shellcodes
SAPSprint 7.60 - 'SAPSprint' Unquoted Service Path
Seeddms 5.1.10 - Remote Command Execution (RCE) (Authenticated)
Simple Client Management System 1.0 - 'uemail' SQL Injection (Unauthenticated)
Lightweight facebook-styled blog 1.3 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
2021-06-26 05:01:55 +00:00
Offensive Security
135e56dda8
DB: 2021-06-25
...
16 changes to exploits/shellcodes
BasicNote 1.1.9 - Denial of Service (PoC)
ColorNote 4.1.9 - Denial of Service (PoC)
Notepad notes 2.6.7 - Denial of Service (PoC)
Blacknote 2.2.1 - Denial of Service (PoC)
Inkpad Notepad & To do list 4.3.61 - Denial of Service (PoC)
GeoGebra 3D Calculator 5.0.511.0 - Denial of Service (PoC)
VMware vCenter Server RCE 6.5 / 6.7 / 7.0 - Remote Code Execution (RCE) (Unauthenticated)
Adobe ColdFusion 8 - Remote Command Execution (RCE)
TP-Link TL-WR841N - Command Injection
Huawei dg8045 - Authentication Bypass
2021-06-25 05:01:52 +00:00
Offensive Security
8e25002b7c
DB: 2021-06-24
...
6 changes to exploits/shellcodes
WordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS)
WordPress Plugin Poll_ Survey_ Questionnaire and Voting system 1.5.2 - 'date_answers' Blind SQL Injection
Online Library Management System 1.0 - 'Search' SQL Injection
Online Library Management System 1.0 - Arbitrary File Upload Remote Code Execution (Unauthenticated)
Simple CRM 3.0 - 'email' SQL injection (Authentication Bypass)
2021-06-24 05:02:06 +00:00
Offensive Security
d318d8a2c7
DB: 2021-06-23
...
4 changes to exploits/shellcodes
ASUS DisplayWidget Software 3.4.0.036 - 'ASUSDisplayWidgetService' Unquoted Service Path
Responsive Tourism Website 3.1 - Remote Code Execution (RCE) (Unauthenticated)
Phone Shop Sales Managements System 1.0 - Insecure Direct Object Reference (IDOR)
2021-06-23 05:01:58 +00:00
Offensive Security
033645d201
DB: 2021-06-22
...
10 changes to exploits/shellcodes
Wise Care 365 5.6.7.568 - 'WiseBootAssistant' Unquoted Service Path
iFunbox 4.2 - 'Apple Mobile Device Service' Unquoted Service Path
Lexmark Printer Software G2 Installation Package 1.8.0.0 - 'LM__bdsvc' Unquoted Service Path
Remote Mouse GUI 3.008 - Local Privilege Escalation
Solaris SunSSH 11.0 x86 - libpam Remote Root (3)
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated)
Simple CRM 3.0 - 'Change user information' Cross-Site Request Forgery (CSRF)
Simple CRM 3.0 - 'name' Stored Cross site scripting (XSS)
Websvn 2.6.0 - Remote Code Execution (Unauthenticated)
Customer Relationship Management System (CRM) 1.0 - Remote Code Execution
2021-06-22 05:01:54 +00:00
Offensive Security
eb316547aa
DB: 2021-06-19
...
5 changes to exploits/shellcodes
Dlink DSL2750U - 'Reboot' Command Injection
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Scripting and Session Fixation
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF)
ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS)
Node.JS - 'node-serialize' Remote Code Execution (3)
2021-06-19 05:01:57 +00:00
Offensive Security
db4eeaac41
DB: 2021-06-18
...
9 changes to exploits/shellcodes
Sync Breeze 13.6.18 - 'Multiple' Unquoted Service Path
Disk Savvy 13.6.14 - 'Multiple' Unquoted Service Path
Dup Scout 13.5.28 - 'Multiple' Unquoted Service Path
VX Search 13.5.28 - 'Multiple' Unquoted Service Path
Workspace ONE Intelligent Hub 20.3.8.0 - 'VMware Hub Health Monitoring Service' Unquoted Service Path
Unified Office Total Connect Now 1.0 - 'data' SQL Injection
Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration
Online Shopping Portal 3.1 - Remote Code Execution (Unauthenticated)
2021-06-18 05:01:58 +00:00
Offensive Security
3a3618bb18
DB: 2021-06-17
...
7 changes to exploits/shellcodes
DiskPulse 13.6.14 - 'Multiple' Unquoted Service Path
Disk Sorter Server 13.6.12 - 'Disk Sorter Server' Unquoted Service Path
Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting
OpenEMR 5.0.1.3 - '/portal/account/register.php' Authentication Bypass
Teachers Record Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
Teachers Record Management System 1.0 - 'email' Stored Cross-site Scripting (XSS)
CKEditor 3 - Server-Side Request Forgery (SSRF)
2021-06-17 05:01:58 +00:00
Offensive Security
6406244acc
DB: 2021-06-16
...
6 changes to exploits/shellcodes
Brother BRPrint Auditor - 'Multiple' Unquoted Service Path
SysGauge 7.9.18 - ' SysGauge Server' Unquoted Service Path
Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path
Polkit 0.105-26 0.117-2 - Local Privilege Escalation
Client Management System 1.1 - 'username' Stored Cross-Site Scripting (XSS)
Client Management System 1.1 - 'Search' SQL Injection
2021-06-16 05:01:56 +00:00
Offensive Security
fe5d7c9048
DB: 2021-06-15
...
16 changes to exploits/shellcodes
Secure Notepad Private Notes 3.0.3 - Denial of Service (PoC)
Post-it 5.0.1 - Denial of Service (PoC)
Notex the best notes 6.4 - Denial of Service (PoC)
Spy Emergency 25.0.650 - 'Multiple' Unquoted Service Path
WibuKey Runtime 6.51 - 'WkSvW32.exe' Unquoted Service Path
Tftpd64 4.64 - 'Tftpd32_svc' Unquoted Service Path
Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS)
Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR)
GLPI 9.4.5 - Remote Code Execution (RCE)
COVID19 Testing Management System 1.0 - 'State' Stored Cross-Site-Scripting (XSS)
Stock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated)
Small CRM 3.0 - 'Authentication Bypass' SQL Injection
TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated)
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated)
2021-06-15 05:01:55 +00:00
Offensive Security
680a0b6cea
DB: 2021-06-12
...
12 changes to exploits/shellcodes
WordPress Plugin WP Statistics 13.0.7 - Time-Based Blind SQL Injection (Unauthenticated)
Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS)
Cerberus FTP Web Service 11 - 'svg' Stored Cross-Site Scripting (XSS)
Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forgery (SSRF)
OpenEMR 5.0.0 - Remote Code Execution (Authenticated)
WordPress Plugin Database Backups 1.2.2.6 - 'Database Backup Download' CSRF
Grocery crud 1.6.4 - 'order_by' SQL Injection
Solar-Log 500 2.8.2 - Incorrect Access Control
Solar-Log 500 2.8.2 - Unprotected Storage of Credentials
Zenario CMS 8.8.52729 - 'cID' Blind & Error based SQL injection (Authenticated)
WoWonder Social Network Platform 3.1 - Authentication Bypass
2021-06-12 05:01:55 +00:00
Offensive Security
eaff7043e2
DB: 2021-06-11
...
6 changes to exploits/shellcodes
Sticky Notes Widget Version 3.0.6 - Denial of Service (PoC)
n+otes 1.6.2 - Denial of Service (PoC)
memono Notepad Version 4.2 - Denial of Service (PoC)
Student Result Management System 1.0 - 'class' SQL Injection
TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS)
Linux/x86 - execve /bin/sh Shellcode (fstenv eip GetPC technique) (70 bytes_ xor encoded)
2021-06-11 05:01:56 +00:00
Offensive Security
83051cc8db
DB: 2021-06-10
...
5 changes to exploits/shellcodes
Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF)
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS)
GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
2021-06-10 05:01:53 +00:00
Offensive Security
a32743b8b4
DB: 2021-06-09
...
4 changes to exploits/shellcodes
NBMonitor 1.6.8 - Denial of Service (PoC)
Nsauditor 3.2.3 - Denial of Service (PoC)
Backup Key Recovery 2.2.7 - Denial of Service (PoC)
WordPress Plugin wpDiscuz 7.0.4 - Remote Code Execution (Unauthenticated)
2021-06-09 05:01:55 +00:00
Offensive Security
d6a44bd00b
DB: 2021-06-08
...
11 changes to exploits/shellcodes
Sticky Notes & Color Widgets 1.4.2 - Denial of Service (PoC)
IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
GitLab Community Edition (CE) 13.10.3 - 'Sign_Up' User Enumeration
OptiLink ONT1GEW GPON 2.1.11_X101 Build 1127.190306 - Remote Code Execution (Authenticated)
WordPress Plugin Smart Slider-3 3.5.0.8 - 'name' Stored Cross-Site Scripting (XSS)
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated)
Grav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated)
Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)
2021-06-08 05:02:03 +00:00
Offensive Security
1dc98b3b8e
DB: 2021-06-05
...
6 changes to exploits/shellcodes
Inkpad Notepad & To do list 4.3.61 - Denial of Service (PoC)
Color Notes 1.4 - Denial of Service (PoC)
Macaron Notes great notebook 5.5 - Denial of Service (PoC)
My Notes Safe 5.3 - Denial of Service (PoC)
Monstra CMS 3.0.4 - Remote Code Execution (Authenticated)
Gitlab 13.10.2 - Remote Code Execution (Authenticated)
2021-06-05 05:01:54 +00:00
Offensive Security
a9fa314bbf
DB: 2021-06-04
...
14 changes to exploits/shellcodes
BasicNote 1.1.9 - Denial of Service (PoC)
ColorNote 4.1.9 - Denial of Service (PoC)
Notepad notes 2.6.7 - Denial of Service (PoC)
Blacknote 2.2.1 - Denial of Service (PoC)
CHIYU IoT Devices - 'Telnet' Authentication Bypass
PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution
Seo Panel 4.8.0 - 'from_time' Reflected XSS
CHIYU IoT Devices - Denial of Service (DoS)
FUDForum 3.1.0 - 'srch' Reflected XSS
FUDForum 3.1.0 - 'author' Reflected XSS
Gitlab 13.9.3 - Remote Code Execution (Authenticated)
4Images 1.8 - 'redirect' Reflected XSS
2021-06-04 05:01:54 +00:00
Offensive Security
b7bdc3f375
DB: 2021-06-03
...
7 changes to exploits/shellcodes
Intel(R) Audio Service x64 01.00.1080.0 - 'IntelAudioService' Unquoted Service Path
Thecus N4800Eco Nas Server Control Panel - Comand Injection
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
GetSimple CMS 3.3.4 - Information Disclosure
Products.PluggableAuthService 2.6.0 - Open Redirect
Seo Panel 4.8.0 - 'search_name' Reflected XSS
Seo Panel 4.8.0 - 'category' Reflected XSS
2021-06-03 05:01:55 +00:00
Offensive Security
44903d83c7
DB: 2021-06-02
...
9 changes to exploits/shellcodes
DupTerminator 1.4.5639.37199 - Denial of Service (PoC)
Veyon 4.4.1 - 'VeyonService' Unquoted Service Path
LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)
ProjeQtOr Project Management 9.1.4 - Remote Code Execution
Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)
WordPress Plugin WP Prayer version 1.6.1 - 'prayer_messages' Stored Cross-Site Scripting (XSS) (Authenticated)
CHIYU IoT devices - 'Multiple' Cross-Site Scripting (XSS)
CHIYU TCP/IP Converter devices - CRLF injection
Atlassian Jira 8.15.0 - Information Disclosure (Username Enumeration)
2021-06-02 05:02:06 +00:00
Offensive Security
26cc1d3fc3
DB: 2021-05-29
...
5 changes to exploits/shellcodes
PHPFusion 9.03.50 - Remote Code Execution
WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated)
Trixbox 2.8.0.4 - 'lang' Path Traversal
Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver)
2021-05-29 05:01:54 +00:00
Offensive Security
b1cf12c4ea
DB: 2021-05-28
...
2 changes to exploits/shellcodes
Postbird 0.8.4 - Javascript Injection
2021-05-28 05:01:57 +00:00
Offensive Security
aa3c54402b
DB: 2021-05-27
...
4 changes to exploits/shellcodes
RarmaRadio 2.72.8 - Denial of Service (PoC)
ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
Codiad 2.8.4 - Remote Code Execution (Authenticated) (3)
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
2021-05-27 05:01:52 +00:00
Offensive Security
8ceb48a8ee
DB: 2021-05-26
...
2 changes to exploits/shellcodes
Gadget Works Online Ordering System 1.0 - 'Category' Persistent Cross-Site Scripting (XSS)
WordPress Plugin Cookie Law Bar 1.2.1 - 'clb_bar_msg' Stored Cross-Site Scripting (XSS)
2021-05-26 05:01:53 +00:00
Offensive Security
bd9f3cd966
DB: 2021-05-25
...
9 changes to exploits/shellcodes
iDailyDiary 4.30 - Denial of Service (PoC)
DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path
ePowerSvc 6.0.3008.0 - 'ePowerSvc.exe' Unquoted Service Path
WordPress Plugin WP Statistics 13.0.7 - Time-Based Blind SQL Injection (Unauthenticated)
Schlix CMS 2.2.6-6 - Arbitary File Upload And Directory Traversal Leads To RCE (Authenticated)
Shopizer 2.16.0 - 'Multiple' Cross-Site Scripting (XSS)
Codiad 2.8.4 - Remote Code Execution (Authenticated) (2)
WordPress Plugin ReDi Restaurant Reservation 21.0307 - 'Comment' Stored Cross-Site Scripting (XSS)
2021-05-25 05:01:58 +00:00
Offensive Security
fae217f419
DB: 2021-05-22
...
6 changes to exploits/shellcodes
Mozilla Firefox 88.0.1 - File Extension Execution of Arbitrary Code
DELL dbutil_2_3.sys 2.3 - Arbitrary Write to Local Privilege Escalation (LPE)
Solaris SunSSH 11.0 x86 - libpam Remote Root (2)
Spotweb 1.4.9 - DOM Based Cross-Site Scripting (XSS)
WordPress Plugin WP Statistics 13.0.7 - Time-Based Blind SQL Injection (Unauthenticated)
Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit)
2021-05-22 05:01:54 +00:00
Offensive Security
eeec67ddf9
DB: 2021-05-21
...
3 changes to exploits/shellcodes
ASUS HID Access Service 1.0.94.0 - 'AsHidSrv.exe' Unquoted Service Path
Backup Manager Module 3.0.0.99 - 'IScheduleSvc.exe' Unquoted Service Path
Acer Updater Service 1.2.3500.0 - 'UpdaterService.exe' Unquoted Service Path
2021-05-21 05:01:54 +00:00
Offensive Security
2f8f6dffbd
DB: 2021-05-20
...
8 changes to exploits/shellcodes
WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service (PoC)
Visual Studio Code 1.47.1 - Denial of Service (PoC)
WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS)
In4Suit ERP 3.2.74.1370 - 'txtLoginId' SQL injection
ManageEngine ADSelfService Plus 6.1 - CSV Injection
COVID19 Testing Management System 1.0 - SQL Injection (Auth Bypass)
COVID19 Testing Management System 1.0 - 'Admin name' Cross-Site Scripting (XSS)
2021-05-20 05:02:04 +00:00
Offensive Security
c2ae9df113
DB: 2021-05-19
...
2 changes to exploits/shellcodes
EgavilanMedia PHPCRUD 1.0 - 'First Name' SQL Injection
Microsoft Exchange 2019 - Unauthenticated Email Download
2021-05-19 05:01:55 +00:00
Offensive Security
1b1c47b0a8
DB: 2021-05-18
...
11 changes to exploits/shellcodes
Microsoft Internet Explorer 8 - 'SetMouseCapture ' Use After Free
OpenEMR < 5.0.1 - (Authenticated) Remote Code Execution
OpenEMR 5.0.1.3 - Remote Code Execution (Authenticated)
Customer Relationship Management (CRM) System 1.0 - 'Category' Persistent Cross site Scripting
IPFire 2.25 - Remote Code Execution (Authenticated)
Dental Clinic Appointment Reservation System 1.0 - 'Firstname' Persistent Cross Site Scripting (Authenticated)
Dental Clinic Appointment Reservation System 1.0 - Cross Site Request Forgery (Add Admin)
Simple Chatbot Application 1.0 - 'Category' Stored Cross site Scripting
Billing Management System 2.0 - Union based SQL injection (Authenticated)
Advanced Guestbook 2.4.4 - 'Smilies' Persistent Cross-Site Scripting (XSS)
Subrion CMS 4.2.1 - File Upload Bypass to RCE (Authenticated)
Printable Staff ID Card Creator System 1.0 - SQLi & RCE via Arbitrary File Upload
2021-05-18 05:01:53 +00:00
Offensive Security
8845e341e4
DB: 2021-05-15
...
3 changes to exploits/shellcodes
Student Management System 1.0 - 'message' Persistent Cross-Site Scripting (Authenticated)
Podcast Generator 3.1 - 'Long Description' Persistent Cross-Site Scripting (XSS)
Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)
2021-05-15 05:01:51 +00:00
Offensive Security
18260aa372
DB: 2021-05-14
...
5 changes to exploits/shellcodes
Microsoft Internet Explorer 8/11 and WPAD service 'Jscript.dll' - Use-After-Free
Firefox 72 IonMonkey - JIT Type Confusion
Dental Clinic Appointment Reservation System 1.0 - Authentication Bypass (SQLi)
Dental Clinic Appointment Reservation System 1.0 - 'date' UNION based SQL Injection (Authenticated)
ZeroShell 3.9.0 - Remote Command Execution
2021-05-14 05:01:57 +00:00
Offensive Security
46c569f0e4
DB: 2021-05-13
...
2 changes to exploits/shellcodes
Splinterware System Scheduler Professional 5.30 - Privilege Escalation
Chevereto 3.17.1 - Cross Site Scripting (Stored)
2021-05-13 05:01:53 +00:00
Offensive Security
c3ea8f97de
DB: 2021-05-12
...
1 changes to exploits/shellcodes
Odoo 12.0.20190101 - 'nssm.exe' Unquoted Service Path
2021-05-12 05:01:57 +00:00
Offensive Security
599b380301
DB: 2021-05-11
...
7 changes to exploits/shellcodes
DHCP Broadband 4.1.0.1503 - 'dhcpt.exe' Unquoted Service Path
BOOTP Turbo 2.0.0.1253 - 'bootpt.exe' Unquoted Service Path
TFTP Broadband 4.3.0.1465 - 'tftpt.exe' Unquoted Service Path
Exploit Title: Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution
Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution
PHP Timeclock 1.04 - Time and Boolean Based Blind SQL Injection # Date: May 3rd 2021
PHP Timeclock 1.04 - Time and Boolean Based Blind SQL Injection
PHP Timeclock 1.04 - 'Multiple' Cross Site Scripting (XSS)
Human Resource Information System 0.1 - 'First Name' Persistent Cross-Site Scripting (Authenticated)
Microweber CMS 1.1.20 - Remote Code Execution (Authenticated)
Linux/x86 - setreuid(0) + execve(_/bin/sh_) Shellcode (29 bytes)
2021-05-11 05:01:57 +00:00
Offensive Security
e4f4680368
DB: 2021-05-08
...
10 changes to exploits/shellcodes
Sandboxie 5.49.7 - Denial of Service (PoC)
Epic Games Easy Anti-Cheat 4.0 - Local Privilege Escalation
Sandboxie Plus 0.7.4 - 'SbieSvc' Unquoted Service Path
WifiHotSpot 1.0.0.0 - 'WifiHotSpotService.exe' Unquoted Service Path
Epic Games Rocket League 1.95 - Stack Buffer Overrun
Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated)
Voting System 1.0 - Authentication Bypass (SQLI)
Voting System 1.0 - Remote Code Execution (Unauthenticated)
Human Resource Information System 0.1 - Remote Code Execution (Unauthenticated)
PHP Timeclock 1.04 - Time and Boolean Based Blind SQL Injection # Date: May 3rd 2021
2021-05-08 05:01:52 +00:00