Offensive Security
0e3474b2ca
DB: 2019-12-22
...
1 changes to exploits/shellcodes
Wordpress FooGallery 1.8.12 - Persistent Cross-Site Scripting
Wordpress Soliloquy Lite 2.5.6 - Persistent Cross-Site Scripting
Wordpress Popup Builder 3.49 - Persistent Cross-Site Scripting
WordPress Plugin FooGallery 1.8.12 - Persistent Cross-Site Scripting
WordPress Plugin Soliloquy Lite 2.5.6 - Persistent Cross-Site Scripting
WordPress Plugin Popup Builder 3.49 - Persistent Cross-Site Scripting
Wordpress Sliced Invoices 3.8.2 - 'post' SQL Injection
WordPress Plugin Sliced Invoices 3.8.2 - 'post' SQL Injection
Wordpress 5.2.4 - Cross-Origin Resource Sharing
WordPress Core 5.2.4 - Cross-Origin Resource Sharing
Wordpress Plugin Google Review Slider 6.1 - 'tid' SQL Injection
WordPress Plugin Google Review Slider 6.1 - 'tid' SQL Injection
Wordpress 5.3 - User Disclosure
WordPress Core 5.3 - User Disclosure
WordPress Core < 5.3.x - 'xmlrpc.php' Denial of Service
2019-12-22 05:01:56 +00:00
Offensive Security
e3e102da5b
DB: 2019-12-21
...
4 changes to exploits/shellcodes
Microsoft Windows 10 BasicRender.sys - Denial of Service (PoC)
FreeSWITCH 1.10.1 - Command Execution
phpMyChat-Plus 1.98 - 'pmc_username' Reflected Cross-Site Scripting
2019-12-21 05:01:57 +00:00
Offensive Security
176ff0c251
DB: 2019-12-13
...
3 changes to exploits/shellcodes
Lenovo Power Management Driver 1.67.17.48 - 'pmdrvs.sys' Denial of Service (PoC)
OpenNetAdmin 18.1.1 - Command Injection Exploit (Metasploit)
Bullwark Momentum Series JAWS 1.0 - Directory Traversal
2019-12-13 05:01:56 +00:00
Offensive Security
44b163c8d1
DB: 2019-12-10
...
11 changes to exploits/shellcodes
Omron PLC 1.0.0 - Denial of Service (PoC)
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
Microsoft Windows - Multiple UAC Protection Bypasses
Microsoft Windows - 'WSReset' UAC Protection Bypass (Registry)
Microsoft Windows 10 - 'WSReset' UAC Protection Bypass (propsys.dll)
SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)
Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting
PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass
Yachtcontrol Webapplication 1.0 - Unauthenticated Remote Code Execution
Alcatel-Lucent Omnivista 8770 - Remote Code Execution
Oracle Siebel Sales 8.1 - Persistent Cross-Site Scripting
2019-12-10 05:01:48 +00:00
Offensive Security
30a6a01b6c
DB: 2019-12-07
...
3 changes to exploits/shellcodes
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
Integard Pro NoJs 2.2.0.9026 - Remote Buffer Overflow
Verot 2.0.3 - Remote Code Execution
2019-12-07 05:02:08 +00:00
Offensive Security
6308ce9aab
DB: 2019-12-05
...
5 changes to exploits/shellcodes
Microsoft Visual Basic 2010 Express - XML External Entity Injection
Online Clinic Management System 2.2 - HTML Injection
SSDWLAB 6.1 - Authentication Bypass
Cisco WLC 2504 8.9 - Denial of Service (PoC)
OwnCloud 8.1.8 - Username Disclosure
2019-12-05 05:01:46 +00:00
Offensive Security
ecbca9d505
DB: 2019-12-04
...
6 changes to exploits/shellcodes
Microsoft Windows Media Center 2002 - XML External Entity MotW Bypass
Online Invoicing System 2.6 - 'description' Persistent Cross-Site Scripting
Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
Revive Adserver 4.2 - Remote Code Execution
2019-12-04 05:01:42 +00:00
Offensive Security
0f56f2f38c
DB: 2019-12-03
...
8 changes to exploits/shellcodes
Nsauditor 3.1.8.0 - 'Name' Denial of Service (PoC)
Nsauditor 3.1.8.0 - 'Key' Denial of Service (PoC)
Visual Studio 2008 - XML External Entity Injection
Max Secure Anti Virus Plus 19.0.4.020 - Insecure File Permissions
Anviz CrossChex 4.3.12 - Local Buffer Overflow
Microsoft Excel 2016 1901 - XML External Entity Injection
SmartHouse Webapp 6.5.33 - Cross-Site Request Forgery
Dokuwiki 2018-04-22b - Username Enumeration
2019-12-03 05:01:42 +00:00
Offensive Security
8ae8522082
DB: 2019-11-30
...
8 changes to exploits/shellcodes
SpotAuditor 5.3.2 - 'Key' Denial of Service
SpotAuditor 5.3.2 - 'Name' Denial of Service
TexasSoft CyberPlanet 6.4.131 - 'CCSrvProxy' Unquoted Service Path
Bash 5.0 Patch 11 - SUID Priv Drop Exploit
Mersive Solstice 2.8.0 - Remote Code Execution
Online Inventory Manager 3.2 - Persistent Cross-Site Scripting
2019-11-30 05:01:42 +00:00
Offensive Security
7921f1a523
DB: 2019-11-29
...
4 changes to exploits/shellcodes
GHIA CamIP 1.2 for iOS - 'Password' Denial of Service (PoC)
Wordpress 5.3 - User Disclosure
Mersive Solstice 2.8.0 - Remote Code Execution
2019-11-29 05:01:48 +00:00
Offensive Security
cacee46726
DB: 2019-11-21
...
11 changes to exploits/shellcodes
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
iOS 12.4 - Sandbox Escape due to Integer Overflow in mediaserverd
Windows - Escalate UAC Protection Bypass (Via dot net profiler) (Metasploit)
Windows - Escalate UAC Protection Bypass (Via Shell Open Registry Key) (Metasploit)
Xorg X11 Server - Local Privilege Escalation (Metasploit)
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
FreeSWITCH - Event Socket Command Execution (Metasploit)
Bludit - Directory Traversal Image File Upload (Metasploit)
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
OpenNetAdmin 18.1.1 - Remote Code Execution
2019-11-21 05:01:49 +00:00
Offensive Security
3e9ff5a927
DB: 2019-11-19
...
13 changes to exploits/shellcodes
iSmartViewPro 1.3.34 - Denial of Service (PoC)
Open Proficy HMI-SCADA 5.0.0.25920 - 'Password' Denial of Service (PoC)
Foscam Video Management System 1.1.4.9 - 'Username' Denial of Service (PoC)
Emerson PAC Machine Edition 9.70 Build 8595 - 'FxControlRuntime' Unquoted Service Path
ASUS HM Com Service 1.00.31 - 'asHMComSvc' Unquoted Service Path
MobileGo 8.5.0 - Insecure File Permissions
NCP_Secure_Entry_Client 9.2 - Unquoted Service Paths
nipper-ng 0.11.10 - Remote Buffer Overflow (PoC)
Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal
Crystal Live HTTP Server 6.01 - Directory Traversal
Centova Cast 3.2.11 - Arbitrary File Download
TemaTres 3.0 - Cross-Site Request Forgery (Add Admin)
TemaTres 3.0 - 'value' Persistent Cross-site Scripting
2019-11-19 05:01:40 +00:00
Offensive Security
a981df031a
DB: 2019-11-15
...
3 changes to exploits/shellcodes
Siemens Desigo PX 6.00 - Denial of Service (PoC)
oXygen XML Editor 21.1.1 - XML External Entity Injection
Xfilesharing 2.5.1 - Arbitrary File Upload
2019-11-15 05:01:42 +00:00
Offensive Security
e84e1285da
DB: 2019-11-14
...
7 changes to exploits/shellcodes
ScanGuard Antivirus 2020 - Insecure Folder Permissions
Linear eMerge E3 1.00-06 - Remote Code Execution
FUDForum 3.0.9 - Remote Code Execution
Technicolor TD5130.2 - Remote Command Execution
Technicolor TC7300.B0 - 'hostname' Persistent Cross-Site Scripting
gSOAP 2.8 - Directory Traversal
Fastweb Fastgate 0.00.81 - Remote Code Execution
2019-11-14 05:01:41 +00:00
Offensive Security
c8181201fd
DB: 2019-11-13
...
38 changes to exploits/shellcodes
Acronis True Image OEM 19.0.5128 - 'afcdpsrv' Unquoted Service Path
Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path
Alps Pointing-device Controller 8.1202.1711.04 - 'ApHidMonitorService' Unquoted Service Path
RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path
Control Center PRO 6.2.9 - Local Stack Based Buffer Overflow (SEH)
Wondershare Application Framework Service - _WsAppService_ Unquote Service Path
eMerge E3 Access Controller 4.6.07 - Remote Code Execution
eMerge E3 Access Controller 4.6.07 - Remote Code Execution (Metasploit)
CBAS-Web 19.0.0 - Information Disclosure
Prima FlexAir Access Control 2.3.38 - Remote Code Execution
Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
eMerge E3 1.00-06 - Privilege Escalation
eMerge E3 1.00-06 - Remote Code Execution
eMerge E3 1.00-06 - Cross-Site Request Forgery
Atlassian Confluence 6.15.1 - Directory Traversal
eMerge E3 1.00-06 - Arbitrary File Upload
eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
eMerge50P 5000P 4.6.07 - Remote Code Execution
CBAS-Web 19.0.0 - Remote Code Execution
CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
CBAS-Web 19.0.0 - Username Enumeration
CBAS-Web 19.0.0 - 'id' Boolean-based Blind SQL Injection
Joomla 3.9.13 - 'Host' Header Injection
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
Prima Access Control 2.3.35 - Arbitrary File Upload
Atlassian Confluence 6.15.1 - Directory Traversal (Metasploit)
Optergy 2.3.0a - Remote Code Execution
FlexAir Access Control 2.4.9api3 - Remote Code Execution
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
Optergy 2.3.0a - Username Disclosure
Optergy 2.3.0a - Remote Code Execution (Backdoor)
Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
FlexAir Access Control 2.3.35 - Authentication Bypass
Bematech Printer MP-4200 - Denial of Service
2019-11-13 05:01:43 +00:00
Offensive Security
b6ed2c7176
DB: 2019-11-09
...
6 changes to exploits/shellcodes
SolarWinds Kiwi Syslog Server 8.3.52 - 'Kiwi Syslog Server' Unquoted Service Path
Android Janus - APK Signature Bypass (Metasploit)
rConfig - install Command Execution (Metasploit)
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
Adive Framework 2.0.7 - Privilege Escalation
Nextcloud 17 - Cross-Site Request Forgery
2019-11-09 05:01:40 +00:00
Offensive Security
52ab59aad8
DB: 2019-11-06
...
12 changes to exploits/shellcodes
FileOptimizer 14.00.2524 - Denial of Service (PoC)
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
WebKit - Universal XSS in JSObject::putInlineSlow and JSValue::putToPrimitive
macOS XNU - Missing Locking in checkdirs_callback() Enables Race with fchdir_common()
Blue Stacks App Player 2.4.44.62.57 - _BstHdLogRotatorSvc_ Unquote Service Path
Network Inventory Advisor 5.0.26.0 - 'niaservice' Unquoted Service Path
thejshen Globitek CMS 1.4 - 'id' SQL Injection
thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting
rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection
html5_snmp 1.11 - 'Remark' Persistent Cross-Site Scripting
html5_snmp 1.11 - 'Router_ID' SQL Injection
SD.NET RIM 4.7.3c - 'idtyp' SQL Injection
2019-11-06 05:01:40 +00:00
Offensive Security
47d2a76f4f
DB: 2019-11-02
...
7 changes to exploits/shellcodes
OpenVPN Private Tunnel 2.8.4 - 'ovpnagent' Unquoted Service Path
Nostromo - Directory Traversal Remote Command Execution (Metasploit)
TheJshen contentManagementSystem 1.04 - 'id' SQL Injection
ownCloud 10.3.0 stable - Cross-Site Request Forgery
Apache Solr 8.2.0 - Remote Code Execution
2019-11-02 05:01:41 +00:00
Offensive Security
c99b957a9f
DB: 2019-11-01
...
3 changes to exploits/shellcodes
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlow (SEH)
MikroTik RouterOS 6.45.6 - DNS Cache Poisoning
CommSy 8.6.5 - SQL injection
Wordpress Plugin Google Review Slider 6.1 - 'tid' SQL Injection
2019-11-01 05:01:39 +00:00
Offensive Security
595ac97a33
DB: 2019-10-30
...
6 changes to exploits/shellcodes
Intelligent Security System SecurOS Enterprise 10.2 - 'SecurosCtrlService' Unquoted Service Path
Win10 MailCarrier 2.51 - 'POP3 User' Remote Buffer Overflow
Microsoft Windows Server 2012 - 'Group Policy' Remote Code Execution
Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass
rConfig 3.9.2 - Remote Code Execution
Wordpress 5.2.4 - Cross-Origin Resource Sharing
2019-10-30 05:01:40 +00:00
Offensive Security
d4a236d578
DB: 2019-10-29
...
9 changes to exploits/shellcodes
WebKit - Universal XSS in HTMLFrameElementBase::isURLAllowed
JumpStart 0.6.0.0 - 'jswpbapi' Unquoted Service Path
ChaosPro 2.0 - Buffer Overflow (SEH)
Intelbras Router WRN150 1.0.18 - Cross-Site Request Forgery
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'start' SQL Injection
Part-DB 0.4 - Authentication Bypass
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'description' Cross-Site Scripting
delpino73 Blue-Smiley-Organizer 1.32 - 'datetime' SQL Injection
PHP-FPM + Nginx - Remote Code Execution
2019-10-29 05:01:40 +00:00
Offensive Security
bc814a8404
DB: 2019-10-26
...
1 changes to exploits/shellcodes
ClonOs WEB UI 19.09 - Improper Access Control
2019-10-26 05:01:41 +00:00
Offensive Security
52e6461f47
DB: 2019-10-25
...
4 changes to exploits/shellcodes
Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)
Wordpress Sliced Invoices 3.8.2 - 'post' SQL Injection
AUO SunVeillance Monitoring System 1.1.9e - Incorrect Access Control
AUO SunVeillance Monitoring System 1.1.9e - 'MailAdd' SQL Injection
2019-10-25 05:01:41 +00:00
Offensive Security
afafb6c641
DB: 2019-10-24
...
3 changes to exploits/shellcodes
IObit Uninstaller 9.1.0.8 - 'IObitUnSvr' Unquoted Service Path
Rocket.Chat 2.1.0 - Cross-Site Scripting
Joomla! 3.4.6 - Remote Code Execution (Metasploit)
2019-10-24 05:01:42 +00:00
Offensive Security
9601f70535
DB: 2019-10-19
...
3 changes to exploits/shellcodes
WorkgroupMail 7.5.1 - 'WorkgroupMail' Unquoted Serive Path
WorkgroupMail 7.5.1 - 'WorkgroupMail' Unquoted Service Path
Joomla! 3.4.6 - Remote Code Execution
2019-10-19 05:01:45 +00:00
Offensive Security
6d83c21135
DB: 2019-10-18
...
8 changes to exploits/shellcodes
BlackMoon FTP Server 3.1.2.1731 - 'BMFTP-RELEASE' Unquoted Serive Path
Web Companion versions 5.1.1035.1047 - 'WCAssistantService' Unquoted Service Path
WorkgroupMail 7.5.1 - 'WorkgroupMail' Unquoted Serive Path
ThinVNC 1.0b1 - Authentication Bypass
Wordpress FooGallery 1.8.12 - Persistent Cross-Site Scripting
Wordpress Soliloquy Lite 2.5.6 - Persistent Cross-Site Scripting
Wordpress Popup Builder 3.49 - Persistent Cross-Site Scripting
Restaurant Management System 1.0 - Remote Code Execution
2019-10-18 05:01:45 +00:00
Offensive Security
588067072a
DB: 2019-10-17
...
15 changes to exploits/shellcodes
sudo 1.8.28 - Security Bypass
sudo 1.2.27 - Security Bypass
Lavasoft 2.3.4.7 - 'LavasoftTcpService' Unquoted Service Path
Zilab Remote Console Server 3.2.9 - 'zrcs' Unquoted Service Path
X.Org X Server 1.20.4 - Local Stack Overflow
LiteManager 4.5.0 - 'romservice' Unquoted Serive Path
Solaris xscreensaver 11.4 - Privilege Escalation
Mikogo 5.2.2.150317 - 'Mikogo-Service' Unquoted Serive Path
Whatsapp 2.19.216 - Remote Code Execution
Accounts Accounting 7.02 - Persistent Cross-Site Scripting
CyberArk Password Vault 10.6 - Authentication Bypass
Linux/x86 - Add User to /etc/passwd Shellcode (59 bytes)
Linux/x86 - adduser (User) to /etc/passwd Shellcode (74 bytes)
Linux/x86 - execve /bin/sh Shellcode (25 bytes)
Linux/x86 - Reverse Shell NULL free 127.0.0.1:4444 Shellcode (91 bytes)
2019-10-17 05:01:44 +00:00
Offensive Security
bae704d681
DB: 2019-10-16
...
4 changes to exploits/shellcodes
sudo 1.8.28 - Security Bypass
ActiveFax Server 6.92 Build 0316 - 'ActiveFaxServiceNT' Unquoted Service Path
Podman & Varlink 1.5.1 - Remote Code Execution
Bolt CMS 3.6.10 - Cross-Site Request Forgery
2019-10-16 05:01:45 +00:00
Offensive Security
7c5ad20e72
DB: 2019-10-15
...
6 changes to exploits/shellcodes
SpotAuditor 5.3.1.0 - Denial of Service
ActiveFax Server 6.92 Build 0316 - 'POP3 Server' Denial of Service
Uplay 92.0.0.6280 - Local Privilege Escalation
Express Invoice 7.12 - 'Customer' Persistent Cross-Site Scripting
Ajenti 2.1.31 - Remote Code Execution
Kirona-DRS 5.5.3.5 - Information Disclosure
2019-10-15 05:01:47 +00:00
Offensive Security
2b52915f75
DB: 2019-10-12
...
3 changes to exploits/shellcodes
National Instruments Circuit Design Suite 14.0 - Local Privilege Escalation
Intelbras Router WRN150 1.0.18 - Persistent Cross-Site Scripting
WordPress Arforms 3.7.1 - Directory Traversal
2019-10-12 05:01:49 +00:00
Offensive Security
54bc76dcfd
DB: 2019-10-09
...
3 changes to exploits/shellcodes
vBulletin 5.0 < 5.5.4 - Unauthenticated Remote Code Execution
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution
Zabbix 4.4 - Authentication Bypass
vBulletin 5.0 < 5.5.4 - 'updateAvatar' Authenticated Remote Code Execution
Linux/ARM - Fork Bomb Shellcode (20 bytes)
2019-10-09 05:01:45 +00:00
Offensive Security
bfcf0daec9
DB: 2019-10-08
...
8 changes to exploits/shellcodes
logrotten 3.15.1 - Privilege Escalation
ASX to MP3 converter 3.1.3.7 - '.asx' Local Stack Overflow (DEP)
CheckPoint Endpoint Security Client/ZoneAlarm 15.4.062.17802 - Privilege Escalation
freeFTP 1.0.8 - Remote Buffer Overflow
Joomla 3.4.6 - 'configuration.php' Remote Code Execution
Zabbix 4.2 - Authentication Bypass
Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting
IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload
2019-10-08 05:01:48 +00:00
Offensive Security
0486c1c8ad
DB: 2019-10-05
...
4 changes to exploits/shellcodes
Android - Binder Driver Use-After-Free
PHP 7.1 < 7.3 - disable_functions Bypass
PHP 7.1 < 7.3 - 'json serializer' Disable Functions Bypass
LabCollector 5.423 - SQL Injection
PHP 7.0 < 7.3 (Unix) - 'gc' Disable Functions Bypass
Linux/x86 - NOT + XOR-N + Random Encoded /bin/sh Shellcode (132 bytes)
2019-10-05 05:01:46 +00:00
Offensive Security
ee1067a45b
DB: 2019-10-03
...
3 changes to exploits/shellcodes
Counter-Strike Global Offensive 1.37.1.1 - 'vphysics.dll' Denial of Service (PoC)
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
Detrix EDMS 1.2.3.1505 - SQL Injection
2019-10-03 05:01:46 +00:00
Offensive Security
4eaf273757
DB: 2019-10-02
...
9 changes to exploits/shellcodes
kic 2.4a - Denial of Service
WebKit - UXSS Using JavaScript: URI and Synchronous Page Loads
WebKit - Universal XSS in WebCore::command
WebKit - User-agent Shadow root Leak in WebCore::ReplacementFragment::ReplacementFragment
WebKit - Universal XSS Using Cached Pages
DameWare Remote Support 12.1.0.34 - Buffer Overflow (SEH)
vBulletin 5 - 'routestring' Remote Code Execution
vBulletin 5 - 'cacheTemplates' Remote Arbitrary File Deletion
vBulletin 5.x - 'routestring' Remote Code Execution
vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion
PHP 7.1 < 7.3 - disable_functions Bypass
vBulletin 5.0 < 5.5.4 - Unauthenticated Remote Code Execution
DotNetNuke < 9.4.0 - Cross-Site Scripting
2019-10-02 05:01:46 +00:00
Offensive Security
21c1b71372
DB: 2019-10-01
...
6 changes to exploits/shellcodes
GoAhead 2.5.0 - Host Header Injection
Cisco Small Business 220 Series - Multiple Vulnerabilities
vBulletin 5.x - Remote Command Execution (Metasploit)
phpIPAM 1.4 - SQL Injection
thesystem 1.0 - Cross-Site Scripting
TheSystem 1.0 - Command Injection
2019-10-01 05:01:46 +00:00
Offensive Security
4802945877
DB: 2019-09-28
...
10 changes to exploits/shellcodes
Mobatek MobaXterm 12.1 - Buffer Overflow (SEH)
thesystem App 1.0 - Persistent Cross-Site Scripting
InoERP 0.7.2 - Persistent Cross-Site Scripting
thesystem App 1.0 - 'server_name' SQL Injection
thesystem App 1.0 - 'username' SQL Injection
V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download
V-SOL GPON/EPON OLT Platform 2.03 - Cross-Site Request Forgery
V-SOL GPON/EPON OLT Platform 2.03 - Remote Privilege Escalation
WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting
2019-09-28 05:01:47 +00:00
Offensive Security
dc44a5e5a6
DB: 2019-09-27
...
5 changes to exploits/shellcodes
Chamillo LMS 1.11.8 - Arbitrary File Upload
Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting
all-in-one-seo-pack 3.2.7 - Persistent Cross-Site Scripting
inoERP 4.15 - 'download' SQL Injection
citecodecrashers Pic-A-Point 1.1 - 'Consignment' SQL Injection
2019-09-27 05:01:48 +00:00
Offensive Security
ba928141e7
DB: 2019-09-26
...
10 changes to exploits/shellcodes
SpotIE Internet Explorer Password Recovery 2.9.5 - 'Key' Denial of Service
Easy File Sharing Web Server 7.2 - 'New User' Local SEH Overflow
ABRT - sosreport Privilege Escalation (Metasploit)
Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting
NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
YzmCMS 5.3 - 'Host' Header Injection
2019-09-26 05:01:47 +00:00
Offensive Security
d7ea903400
DB: 2019-09-25
...
7 changes to exploits/shellcodes
DeviceViewer 3.12.0.1 - 'creating user' Denial of Service
Microsoft Windows cryptoapi - SymCrypt Modular Inverse Algorithm Denial of Service
iMessage - Decoding NSSharedKeyDictionary Can Read Object Out of Bounds
Easy File Sharing Web Server 7.2 - 'New User' Local SEH Overflow
File Sharing Wizard 1.5.0 - POST SEH Overflow
Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)
Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
2019-09-25 05:04:03 +00:00
Offensive Security
7ceaed0205
DB: 2019-09-21
...
1 changes to exploits/shellcodes
Concrete5 FlashUploader - Arbitrary '.SWF' File Upload
Concrete5 CMS FlashUploader - Arbitrary '.SWF' File Upload
Concrete5 < 8.3.0 - Username / Comments Enumeration
Concrete5 CMS < 8.3.0 - Username / Comments Enumeration
LayerBB < 1.1.4 - Cross-Site Request Forgery
2019-09-21 05:04:22 +00:00
Offensive Security
d6e0b04877
DB: 2019-09-20
...
4 changes to exploits/shellcodes
macOS 18.7.0 Kernel - Local Privilege Escalation
Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution
DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting
2019-09-20 05:02:06 +00:00
Offensive Security
401d4ea8dc
DB: 2019-09-19
...
1 changes to exploits/shellcodes
Hospital-Management 1.26 - 'fname' SQL Injection
2019-09-19 05:03:18 +00:00
Offensive Security
b6378fddcc
DB: 2019-09-17
...
6 changes to exploits/shellcodes
Windows NTFS - Privileged File Access Enumeration
AppXSvc - Privilege Escalation
docPrint Pro 8.0 - SEH Buffer Overflow
Inteno IOPSYS Gateway - Improper Access Restrictions
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
CollegeManagementSystem-CMS 1.3 - 'batch' SQL Injection
2019-09-17 05:02:21 +00:00
Offensive Security
a6db0c9d90
DB: 2019-09-15
...
2 changes to exploits/shellcodes
Ticket-Booking 1.4 - Authentication Bypass
College-Management-System 1.2 - Authentication Bypass
2019-09-15 05:02:26 +00:00
Offensive Security
d154146052
DB: 2019-09-14
...
4 changes to exploits/shellcodes
Folder Lock 7.7.9 - Denial of Service
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
LimeSurvey 3.17.13 - Cross-Site Scripting
2019-09-14 05:02:28 +00:00
Offensive Security
a3b360fc6c
DB: 2019-09-11
...
7 changes to exploits/shellcodes
Windows 10 - UAC Protection Bypass Via Windows Store (WSReset.exe) (Metasploit)
Windows 10 - UAC Protection Bypass Via Windows Store (WSReset.exe) and Registry (Metasploit)
LibreNMS - Collectd Command Injection (Metasploit)
October CMS - Upload Protection Bypass Code Execution (Metasploit)
Dolibarr ERP-CRM 10.0.1 - 'elemid' SQL Injection
Enigma NMS 65.0.0 - SQL Injection
Online Appointment - SQL Injection
Enigma NMS 65.0.0 - SQL Injection
Online Appointment - SQL Injection
WordPress Plugin Sell Downloads 1.0.86 - Cross-Site Scripting
Dolibarr ERP-CRM 10.0.1 - SQL Injection
WordPress Plugin Sell Downloads 1.0.86 - Cross-Site Scripting
Dolibarr ERP-CRM 10.0.1 - SQL Injection
WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
2019-09-11 05:02:35 +00:00
Offensive Security
fcce3705a3
DB: 2019-09-10
...
9 changes to exploits/shellcodes
WordPress 5.2.3 - Cross-Site Host Modification
Dolibarr ERP-CRM 10.0.1 - 'elemid' SQL Injection
Enigma NMS 65.0.0 - Cross-Site Request Forgery
Enigma NMS 65.0.0 - OS Command Injection
Enigma NMS 65.0.0 - SQL Injection
Online Appointment - SQL Injection
Rifatron Intelligent Digital Security System - 'animate.cgi' Stream Disclosure
WordPress Plugin Sell Downloads 1.0.86 - Cross-Site Scripting
Dolibarr ERP-CRM 10.0.1 - SQL Injection
2019-09-10 05:02:21 +00:00
Offensive Security
ad97ff4198
DB: 2019-09-07
...
3 changes to exploits/shellcodes
SCO OpenServer 5.0.7 - MMDF deliver Privilege Escalation
Linux Kernel 2.4.x/2.6.x (CentOS 4.8/5.3 / RHEL 4.8/5.3 / SuSE 10 SP2/11 / Ubuntu 8.10) (PPC) - 'sock_sendpage()' Local Privilege Escalation
Linux Kernel 2.4/2.6 (Fedora 11) - 'sock_sendpage()' Local Privilege Escalation (2)
Linux Kernel 2.4/2.6 - 'sock_sendpage()' Local Privilege Escalation (3)
SCO Multi-channel Memorandum Distribution Facility - Multiple Vulnerabilities
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Remote Code Execution
FusionPBX 4.4.8 - Remote Code Execution
Inventory Webapp - 'itemquery' SQL injection
Linux/x86 - TCP Reverse Shell 127.0.0.1 Nullbyte Free Shellcode
Linux/x86 - Reverse (127.0.0.1:4444/TCP) Shell (/bin/sh) + Null-Byte Free Shellcode (107 Bytes)
2019-09-07 05:02:21 +00:00
Offensive Security
45bddc9b1b
DB: 2019-09-05
...
2 changes to exploits/shellcodes
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
2019-09-05 05:02:54 +00:00