Exploit-DB
3711d1e88d
DB: 2023-11-07
...
1 changes to exploits/shellcodes/ghdb
2023-11-07 00:16:47 +00:00
Exploit-DB
5b9acfe03d
DB: 2023-11-03
...
1 changes to exploits/shellcodes/ghdb
2023-11-03 00:17:00 +00:00
Exploit-DB
ea7fd161a3
DB: 2023-11-02
...
1 changes to exploits/shellcodes/ghdb
2023-11-02 00:16:33 +00:00
Exploit-DB
e369c91366
DB: 2023-11-01
...
1 changes to exploits/shellcodes/ghdb
2023-11-01 00:16:42 +00:00
Exploit-DB
75cbb282d9
DB: 2023-10-31
...
12 changes to exploits/shellcodes/ghdb
systemd 246 - Local Privilege Escalation
ChurchCRM v4.5.3 - Authenticated SQL Injection
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) via subprocess_execute
Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
Request-Baskets v1.2.1 - Server-side request forgery (SSRF)
2023-10-31 00:17:05 +00:00
Exploit-DB
45020d9cc3
DB: 2023-10-26
...
1 changes to exploits/shellcodes/ghdb
2023-10-26 00:16:49 +00:00
Exploit-DB
3c68644b7f
DB: 2023-10-24
...
1 changes to exploits/shellcodes/ghdb
2023-10-24 00:16:26 +00:00
Exploit-DB
28233c60a9
DB: 2023-10-21
...
1 changes to exploits/shellcodes/ghdb
2023-10-21 00:17:11 +00:00
Exploit-DB
8e469af5e4
DB: 2023-10-20
...
1 changes to exploits/shellcodes/ghdb
2023-10-20 00:16:34 +00:00
Exploit-DB
d769738a1b
DB: 2023-10-19
...
1 changes to exploits/shellcodes/ghdb
2023-10-19 00:16:34 +00:00
Exploit-DB
888e6c1d4c
DB: 2023-10-17
...
1 changes to exploits/shellcodes/ghdb
2023-10-17 00:16:34 +00:00
Exploit-DB
53fc63f69b
DB: 2023-10-14
...
1 changes to exploits/shellcodes/ghdb
2023-10-14 00:16:29 +00:00
Exploit-DB
f3649a641f
DB: 2023-10-10
...
24 changes to exploits/shellcodes/ghdb
Minio 2022-07-29T19-40-48Z - Path traversal
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service
Atcom 2.7.x.x - Authenticated Command Injection
Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction
OpenPLC WebServer 3 - Denial of Service
Splunk 9.0.5 - admin account take over
BoidCMS v2.0.0 - authenticated file upload vulnerability
Cacti 1.2.24 - Authenticated command injection when using SNMP options
Chitor-CMS v1.1.2 - Pre-Auth SQL Injection
Clcknshop 1.0.0 - SQL Injection
Coppermine Gallery 1.6.25 - RCE
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
GLPI GZIP(Py3) 9.4.5 - RCE
Limo Booking Software v1.0 - CORS
Media Library Assistant Wordpress Plugin - RCE and LFI
Online ID Generator 1.0 - Remote Code Execution (RCE)
Shuttle-Booking-Software v1.0 - Multiple-SQLi
Webedition CMS v2.9.8.8 - Blind SSRF
WEBIGniter v28.7.23 File Upload - Remote Code Execution
Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
Wordpress Sonaar Music Plugin 4.7 - Stored XSS
Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)
2023-10-10 00:16:32 +00:00
Exploit-DB
e5f7757184
DB: 2023-10-03
...
1 changes to exploits/shellcodes/ghdb
2023-10-03 00:16:26 +00:00
g0t mi1k
f88561adfb
Merge branch 'nmap-version-parsing' into 'main'
...
Fix: searchsploit Nmap XML parsing loses software version data.
See merge request exploit-database/exploitdb!3
2023-09-25 16:46:54 +00:00
Michael Monsivais
8298b27c9c
Fix: searchsploit Nmap parsing loses version data.
...
Modified searchsploit's Nmap XML parsing to correctly extract software
versions. Also, these versions are no longer split on '.'.
2023-09-15 20:29:25 -04:00
Exploit-DB
3cde8c39d6
DB: 2023-09-13
...
1 changes to exploits/shellcodes/ghdb
2023-09-13 00:16:29 +00:00
Exploit-DB
db6fc602bf
DB: 2023-09-12
...
1 changes to exploits/shellcodes/ghdb
2023-09-12 00:16:26 +00:00
Exploit-DB
cbe784b087
DB: 2023-09-09
...
16 changes to exploits/shellcodes/ghdb
Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
Drupal 10.1.2 - web-cache-poisoning-External-service-interaction
Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
soosyze 2.0.0 - File Upload
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
Wp2Fac - OS Command Injection
Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
SyncBreeze 15.2.24 - 'login' Denial of Service
GOM Player 2.3.90.5360 - Buffer Overflow (PoC)
GOM Player 2.3.90.5360 - Remote Code Execution (RCE)
Windows/x64 - PIC Null-Free TCP Reverse Shell Shellcode (476 Bytes)
2023-09-09 00:16:33 +00:00
Exploit-DB
54971d143b
DB: 2023-09-08
...
1 changes to exploits/shellcodes/ghdb
2023-09-08 00:16:30 +00:00
Exploit-DB
fdcaa2b976
DB: 2023-09-07
...
1 changes to exploits/shellcodes/ghdb
Blood Donor Management System v1.0 - Stored XSS
2023-09-07 00:16:27 +00:00
Exploit-DB
4e246a01fb
DB: 2023-09-05
...
18 changes to exploits/shellcodes/ghdb
DLINK DPH-400SE - Exposure of Sensitive Information
FileMage Gateway 1.10.9 - Local File Inclusion
Academy LMS 6.1 - Arbitrary File Upload
AdminLTE PiHole 5.18 - Broken Access Control
Blood Donor Management System v1.0 - Stored XSS
Bus Reservation System 1.1 - Multiple-SQLi
Credit Lite 1.5.4 - SQL Injection
CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')
Hyip Rio 2.1 - Arbitrary File Upload
Member Login Script 3.3 - Client-side desync
SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)
Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow
Kingo ROOT 1.5.8 - Unquoted Service Path
NVClient v5.0 - Stack Buffer Overflow (DoS)
Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
2023-09-05 00:16:27 +00:00
Exploit-DB
4c8ac36b6c
DB: 2023-08-30
...
1 changes to exploits/shellcodes/ghdb
Online Clinic Management System 2.2 - HTML Injection
Online Clinic Management System 2.2 - Multiple Stored Cross-Site Scripting (XSS)
Online Clinic Management System 2.2 - HTML Injection
Online Clinic Management System 2.2 - Multiple Stored Cross-Site Scripting (XSS)
Purchase Order Management System 1.0 - Remote File Upload
Purchase Order Management-1.0 - Local File Inclusion
Purchase Order Management System 1.0 - Remote File Upload
Purchase Order Management-1.0 - Local File Inclusion
Restaurant Management System 1.0 - SQL Injection
2023-08-30 00:16:32 +00:00
Exploit-DB
fe2c42ff0e
DB: 2023-08-25
...
4 changes to exploits/shellcodes/ghdb
User Registration & Login and User Management System v3.0 - SQL Injection (Unauthenticated)
User Registration & Login and User Management System v3.0 - Stored Cross-Site Scripting (XSS)
Uvdesk 1.1.4 - Stored XSS (Authenticated)
2023-08-25 00:16:28 +00:00
Exploit-DB
cb5ca4a416
DB: 2023-08-24
...
1 changes to exploits/shellcodes/ghdb
Color Prediction Game v1.0 - SQL Injection
Multi-Vendor Online Groceries Management System 1.0 - 'id' Blind SQL Injection
Online Eyewear Shop 1.0 - SQL Injection (Unauthenticated)
2023-08-24 00:16:24 +00:00
Exploit-DB
e07f33f24d
DB: 2023-08-22
...
17 changes to exploits/shellcodes/ghdb
EuroTel ETL3100 - Transmitter Authorization Bypass (IDOR)
EuroTel ETL3100 - Transmitter Default Credentials
EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download
Color Prediction Game v1.0 - SQL Injection
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
Dolibarr Version 17.0.1 - Stored XSS
Global - Multi School Management System Express v1.0- SQL Injection
OVOO Movie Portal CMS v3.3.3 - SQL Injection
PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities
Taskhub CRM Tool 2.8.6 - SQL Injection
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
TSplus 16.0.0.0 - Remote Work Insecure Files and Folders
TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions
Linux/x64 - memfd_create ELF loader Shellcode (170 bytes)
2023-08-22 00:16:22 +00:00
Exploit-DB
500cf5a2e0
DB: 2023-08-20
...
1 changes to exploits/shellcodes/ghdb
Diafan CMS 6.0 - Reflected Cross-Site Scripting (XSS)
Online Art gallery project 1.0 - Arbitrary File Upload (Unauthenticated)
Online Shopping Cart System 1.0 - 'id' SQL Injection
Online Thesis Archiving System v1.0 - Multiple-SQLi
WebsiteBaker v2.13.3 - Cross-Site Scripting (XSS)
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS
WebsiteBaker v2.13.3 - Cross-Site Scripting (XSS)
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS
2023-08-20 00:16:58 +00:00
Exploit-DB
6da2bca764
DB: 2023-08-12
...
1 changes to exploits/shellcodes/ghdb
projectSend r1605 - CSV injection
projectSend r1605 - Private file download
projectSend r1605 - CSV injection
projectSend r1605 - Private file download
projectSend r1605 - Stored XSS
2023-08-12 00:16:26 +00:00
Exploit-DB
f55092b332
DB: 2023-08-11
...
6 changes to exploits/shellcodes/ghdb
TP-Link Archer AX21 - Unauthenticated Command Injection
systemd 246 - Local Privilege Escalation
Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
Request-Baskets v1.2.1 - Server-side request forgery (SSRF)
OutSystems Service Studio 11.53.30 - DLL Hijacking
2023-08-11 00:16:25 +00:00
Exploit-DB
69f3ee7722
DB: 2023-08-09
...
8 changes to exploits/shellcodes/ghdb
Lucee 5.4.2.17 - Authenticated Reflected XSS
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
Emagic Data Center Management Suite v6.0 - OS Command Injection
mooSocial 3.1.8 - Reflected XSS
PHPJabbers Vacation Rental Script 4.0 - CSRF
Social-Commerce 3.1.6 - Reflected XSS
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
2023-08-09 00:16:24 +00:00
Exploit-DB
010e679abe
DB: 2023-08-05
...
25 changes to exploits/shellcodes/ghdb
ReyeeOS 1.204.1614 - MITM Remote Code Execution (RCE)
Shelly PRO 4PM v0.11.0 - Authentication Bypass
Ozeki SMS Gateway 10.3.208 - Arbitrary File Read (Unauthenticated)
Academy LMS 6.0 - Reflected XSS
Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting
Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
JLex GuestBook 1.6.4 - Reflected XSS
Joomla JLex Review 6.0.1 - Reflected XSS
News Portal v4.0 - SQL Injection (Unauthorized)
PHPJabbers Cleaning Business 1.0 - Reflected XSS
PHPJabbers Night Club Booking 1.0 - Reflected XSS
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
PHPJabbers Service Booking Script 1.0 - Reflected XSS
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
PHPJabbers Taxi Booking 2.0 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
Webutler v3.2 - Remote Code Execution (RCE)
WordPress adivaha Travel Plugin 2.3 - Reflected XSS
WordPress adivaha Travel Plugin 2.3 - SQL Injection
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
WordPress Plugin Forminator 1.24.6 - Unauthenticated Remote Command Execution
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
Xlight FTP Server 3.9.3.6 - 'Stack Buffer Overflow' (DOS)
2023-08-05 00:16:32 +00:00
Exploit-DB
9229ea6f66
DB: 2023-08-03
...
1 changes to exploits/shellcodes/ghdb
Bookwyrm v0.4.3 - Authentication Bypass
Gitea 1.16.6 - Remote Code Execution (RCE) (Metasploit)
Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
WordPress Plugin Duplicator 1.4.7 - Information Disclosure
Wordpress Plugin WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS)
2023-08-03 00:16:49 +00:00
Exploit-DB
5eb89a2046
DB: 2023-08-01
...
5 changes to exploits/shellcodes/ghdb
Joomla iProperty Real Estate 4.1.1 - Reflected XSS
Joomla Solidres 2.13.3 - Reflected XSS
RosarioSIS 10.8.4 - CSV Injection
Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
WordPress Plugin AN_Gradebook 5.0.1 - SQLi
General Device Manager 2.5.2.2 - Buffer Overflow (SEH)
2023-08-01 00:16:36 +00:00
Exploit-DB
c18d9953a2
DB: 2023-07-29
...
22 changes to exploits/shellcodes/ghdb
Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 - Password Dumping
Active Super Shop CMS v2.5 - HTML Injection Vulnerabilities
Availability Booking Calendar v1.0 - Multiple Cross-site scripting (XSS)
Dooblou WiFi File Explorer 1.13.3 - Multiple Vulnerabilities
Joomla HikaShop 4.7.4 - Reflected XSS
Joomla VirtueMart Shopping Cart 4.0.12 - Reflected XSS
mooDating 1.2 - Reflected Cross-site scripting (XSS)
October CMS v3.4.4 - Stored Cross-Site Scripting (XSS) (Authenticated)
PaulPrinting CMS - (Search Delivery) Cross Site Scripting
Perch v3.2 - Persistent Cross Site Scripting (XSS)
RosarioSIS 10.8.4 - CSV Injection
WordPress Plugin AN_Gradebook 5.0.1 - SQLi
Zomplog 3.9 - Cross-site scripting (XSS)
zomplog 3.9 - Remote Code Execution (RCE)
copyparty 1.8.2 - Directory Traversal
copyparty v1.8.6 - Reflected Cross Site Scripting (XSS)
GreenShot 1.2.10 - Insecure Deserialization Arbitrary Code Execution
mRemoteNG v1.77.3.1784-NB - Cleartext Storage of Sensitive Information in Memory
Windows/x64 - PIC Null-Free Calc.exe Shellcode (169 Bytes)
2023-07-29 00:16:43 +00:00
Exploit-DB
033e7ba3e0
DB: 2023-07-22
...
3 changes to exploits/shellcodes/ghdb
Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
Perch v3.2 - Remote Code Execution (RCE)
Perch v3.2 - Stored XSS
Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi
2023-07-22 00:16:25 +00:00
Exploit-DB
98cdb05106
DB: 2023-07-21
...
10 changes to exploits/shellcodes/ghdb
Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.
RWS WorldServer 11.7.3 - Session Token Enumeration
Aures Booking & POS Terminal - Local Privilege Escalation
Boom CMS v8.0.7 - Cross Site Scripting
PaulPrinting CMS - Multiple Cross Site Web Vulnerabilities
pfSense v2.7.0 - OS Command Injection
Webile v1.0.1 - Multiple Cross Site Scripting
Wifi Soft Unibox Administration 3.0 & 3.1 - SQL Injection
RaidenFTPD 2.4.4005 - Buffer Overflow (SEH)
2023-07-21 00:16:29 +00:00
Exploit-DB
3a3c03321c
DB: 2023-07-20
...
18 changes to exploits/shellcodes/ghdb
Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution
ABB FlowX v4.00 - Exposure of Sensitive Information
TP-Link TL-WR740N - Authenticated Directory Transversal
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
Backdrop Cms v1.25.1 - Stored Cross-Site Scripting (XSS)
Blackcat Cms v1.4 - Remote Code Execution (RCE)
Blackcat Cms v1.4 - Stored XSS
CmsMadeSimple v2.2.17 - Remote Code Execution (RCE)
CmsMadeSimple v2.2.17 - session hijacking via Server-Side Template Injection (SSTI)
CmsMadeSimple v2.2.17 - Stored Cross-Site Scripting (XSS)
Joomla! com_booking component 2.4.9 - Information Leak (Account enumeration)
Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
phpfm v1.7.9 - Authentication type juggling
PimpMyLog v1.7.14 - Improper access control
PMB 7.4.6 - SQL Injection
Statamic 4.7.0 - File-Inclusion
Vaidya-Mitra 1.0 - Multiple SQLi
2023-07-20 00:16:46 +00:00
Exploit-DB
20fe50e6db
DB: 2023-07-18
...
1 changes to exploits/shellcodes/ghdb
2023-07-18 00:16:21 +00:00
Exploit-DB
fd788a92e3
DB: 2023-07-16
...
9 changes to exploits/shellcodes/ghdb
Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass
Netlify CMS 2.10.192 - Stored Cross-Site Scripting (XSS)
Admidio v4.2.10 - Remote Code Execution (RCE)
Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
Bus Pass Management System 1.0 - 'viewid' SQL Injection
Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
Bus Pass Management System 1.0 - 'viewid' SQL Injection
Icinga Web 2.10 - Authenticated Remote Code Execution
News Portal v4.0 - SQL Injection (Unauthorized)
Pluck v4.7.18 - Remote Code Execution (RCE)
ProjeQtOr Project Management System v10.4.1 - Multiple XSS
WinterCMS < 1.2.3 - Persistent Cross-Site Scripting
XAMPP 8.2.4 - Unquoted Path
2023-07-16 00:16:39 +00:00
Exploit-DB
00f5021452
DB: 2023-07-12
...
10 changes to exploits/shellcodes/ghdb
Ateme TITAN File 3.9 - SSRF File Enumeration
Netlify CMS 2.10.192 - Stored Cross-Site Scripting (XSS)
Spring Cloud 3.2.2 - Remote Command Execution (RCE)
BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
Park Ticketing Management System 1.0 - 'viewid' SQL Injection
Park Ticketing Management System 1.0 - 'viewid' SQL Injection
Frappe Framework (ERPNext) 13.4.0 - Remote Code Execution (Authenticated)
AVG Anti Spyware 7.5 - Unquoted Service Path _AVG Anti-Spyware Guard_
Game Jackal Server v5 - Unquoted Service Path _GJServiceV5_
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTAgentService_
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTSchedulerService_
2023-07-12 00:16:54 +00:00
Exploit-DB
743db0e747
DB: 2023-07-08
...
4 changes to exploits/shellcodes/ghdb
Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
Bus Pass Management System 1.0 - 'Search' SQL injection
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
Bus Pass Management System 1.0 - 'Search' SQL injection
Faculty Evaluation System v1.0 - SQL Injection
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
2023-07-08 00:16:23 +00:00
Exploit-DB
e2ea5c0412
DB: 2023-07-07
...
4 changes to exploits/shellcodes/ghdb
Gila CMS 1.10.9 - Remote Code Execution (RCE) (Authenticated)
Lost and Found Information System v1.0 - SQL Injection
Piwigo v13.7.0 - Stored Cross-Site Scripting (XSS) (Authenticated)
2023-07-07 00:16:26 +00:00
Exploit-DB
9461677d02
DB: 2023-07-05
...
4 changes to exploits/shellcodes/ghdb
Beauty Salon Management System v1.0 - SQLi
Bus Pass Management System 1.0 - Stored Cross-Site Scripting (XSS)
Car Rental Script 1.8 - Stored Cross-site scripting (XSS)
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
2023-07-05 00:16:21 +00:00
Exploit-DB
ef9b4e5962
DB: 2023-07-04
...
20 changes to exploits/shellcodes/ghdb
TP-Link TL-WR940N V4 - Buffer OverFlow
D-Link DAP-1325 - Broken Access Control
Alkacon OpenCMS 15.0 - Multiple Cross-Site Scripting (XSS)
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
FuguHub 8.1 - Remote Code Execution
GZ Forum Script 1.8 - Stored Cross-Site Scripting (XSS)
PodcastGenerator 3.2.9 - Blind SSRF via XML Injection
POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
Prestashop 8.0.4 - Cross-Site Scripting (XSS)
Rukovoditel 3.4.1 - Multiple Stored XSS
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
spip v4.1.10 - Spoofing Admin account
Time Slot Booking Calendar 1.8 - Stored Cross-Site Scripting (XSS)
Vacation Rental 1.8 - Stored Cross-Site Scripting (XSS)
WBCE CMS 1.6.1 - Open Redirect & CSRF
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS
WP AutoComplete 1.0.4 - Unauthenticated SQLi
2023-07-04 00:16:26 +00:00
Exploit-DB
7807e6f266
DB: 2023-06-27
...
7 changes to exploits/shellcodes/ghdb
Azure Apache Ambari 2302250400 - Spoofing
Microsoft SharePoint Enterprise Server 2016 - Spoofing
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
Xenforo Version 2.2.13 - Authenticated Stored XSS
Windows 11 22h2 - Kernel Privilege Elevation
2023-06-27 00:17:09 +00:00
Exploit-DB
c79c4813de
DB: 2023-06-24
...
4 changes to exploits/shellcodes/ghdb
MCL-Net 4.3.5.8788 - Information Disclosure
Abantecart v1.3.2 - Authenticated Remote Code Execution
Bludit < 3.13.1 Backup Plugin - Arbitrary File Download (Authenticated)
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
NCH Express Invoice - Clear Text Password Storage and Account Takeover
2023-06-24 00:16:23 +00:00
Exploit-DB
ea194c414f
DB: 2023-06-23
...
3 changes to exploits/shellcodes/ghdb
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
Microsoft OneNote (Version 2305 Build 16.0.16501.20074) 64-bit - Spoofing
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
Super Socializer 7.13.52 - Reflected XSS
2023-06-23 00:16:26 +00:00
Exploit-DB
00f6b3e7ed
DB: 2023-06-22
...
2 changes to exploits/shellcodes/ghdb
HiSecOS 04.0.01 - Privilege Escalation
SPIP v4.2.1 - Remote Code Execution (Unauthenticated)
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
2023-06-22 00:16:26 +00:00
Exploit-DB
cc495bca11
DB: 2023-06-21
...
8 changes to exploits/shellcodes/ghdb
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
SPIP v4.2.1 - Remote Code Execution (Unauthenticated)
Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
Super Socializer 7.13.52 - Reflected XSS
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
2023-06-21 00:16:34 +00:00
Exploit-DB
147824bdba
DB: 2023-06-20
...
8 changes to exploits/shellcodes/ghdb
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
Diafan CMS 6.0 - Reflected Cross-Site Scripting (XSS)
Groomify v1.0 - SQL Injection
Jobpilot v2.61 - SQL Injection
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
The Shop v2.5 - SQL Injection
WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
2023-06-20 00:16:29 +00:00