Offensive Security
216721f32c
DB: 2020-12-01
...
4 changes to exploits/shellcodes
YATinyWinFTP - Denial of Service (PoC)
ATX MiniCMTS200a Broadband Gateway 2.0 - Credential Disclosure
Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
Intelbras Router RF 301K 1.1.2 - Authentication Bypass
2020-12-01 05:01:56 +00:00
Offensive Security
673a45a464
DB: 2020-11-28
...
13 changes to exploits/shellcodes
libupnp 1.6.18 - Stack-based buffer overflow (DoS)
SAP Lumira 1.31 - Stored Cross-Site Scripting
Foxit Reader 9.0.1.1049 - Arbitrary Code Execution
Wordpress Theme Wibar 1.1.8 - 'Brand Component' Stored Cross Site Scripting
WonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting
Ruckus IoT Controller (Ruckus vRIoT) 1.5.1.0.21 - Remote Code Execution
Laravel Administrator 4 - Unrestricted File Upload (Authenticated)
Acronis Cyber Backup 12.5 Build 16341 - Unauthenticated SSRF
Moodle 3.8 - Unrestricted File Upload
Wordpress Theme Accesspress Social Icons 1.7.9 - SQL injection (Authenticated)
House Rental 1.0 - 'keywords' SQL Injection
ElkarBackup 1.3.3 - 'Policy[name]' and 'Policy[Description]' Stored Cross-site Scripting
Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated)
2020-11-28 05:01:59 +00:00
Offensive Security
1306b3ff5f
DB: 2020-11-27
...
2 changes to exploits/shellcodes
Pure-FTPd 1.0.48 - Remote Denial of Service
Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
2020-11-27 05:01:55 +00:00
Offensive Security
ce8af77d3e
DB: 2020-11-26
...
4 changes to exploits/shellcodes
Wondershare Driver Install Service help 10.7.1.321 - 'ElevationService' Unquote Service Path
WonderCMS 3.1.3 - 'page' Persistent Cross-Site Scripting
osCommerce 2.3.4.1 - 'title' Persistent Cross-Site Scripting
SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow
2020-11-26 05:01:56 +00:00
Offensive Security
a41b8b4637
DB: 2020-11-25
...
7 changes to exploits/shellcodes
docPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)
nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting
Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
Seowon 130-SLC router 1.0.11 - 'ipAddr' RCE (Authenticated)
OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated)
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
2020-11-25 05:01:56 +00:00
Offensive Security
35dd7185fd
DB: 2020-11-24
...
6 changes to exploits/shellcodes
Boxoft Audio Converter 2.3.0 - '.wav' Buffer Overflow (SEH)
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
VTiger v7.0 CRM - 'To' Persistent XSS
LifeRay 7.2.1 GA2 - Stored XSS
2020-11-24 05:02:01 +00:00
Offensive Security
c14496840d
DB: 2020-11-21
...
5 changes to exploits/shellcodes
Zortam Mp3 Media Studio 27.60 - Remote Code Execution (SEH)
IBM Tivoli Storage Manager Command Line Administrative Interface 5.2.0.1 - id' Field Stack Based Buffer Overflow
Free MP3 CD Ripper 2.8 - Multiple File Buffer Overflow (Metasploit)
Boxoft Convert Master 1.3.0 - 'wav' SEH Local Exploit
WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
2020-11-21 05:01:59 +00:00
Offensive Security
21fa83f241
DB: 2020-11-20
...
12 changes to exploits/shellcodes
Internet Download Manager 6.38.12 - Scheduler Downloads Scheduler Buffer Overflow (PoC)
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
Joomla! Component com_memorix - SQL Injection
Joomla! Component com_informations - SQL Injection
Joomla! Component com_memorix - SQL Injection
Joomla! Component com_informations - SQL Injection
PESCMS TEAM 2.3.2 - Multiple Reflected XSS
Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
xuucms 3 - 'keywords' SQL Injection
Gitlab 12.9.0 - Arbitrary File Read (Authenticated)
TestBox CFML Test Framework 4.1.0 - Arbitrary File Write and Remote Code Execution
TestBox CFML Test Framework 4.1.0 - Directory Traversal
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
M/Monit 3.7.4 - Privilege Escalation
M/Monit 3.7.4 - Password Disclosure
Nagios Log Server 2.1.7 - Persistent Cross-Site Scripting
2020-11-20 05:02:04 +00:00
Offensive Security
e57ba82919
DB: 2020-11-19
...
3 changes to exploits/shellcodes
ZeroLogon - Netlogon Elevation of Privilege
Wordpress Plugin WPForms 1.6.3.1 - Persistent Cross Site Scripting (Authenticated)
BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
2020-11-19 05:02:00 +00:00
Offensive Security
66d1f19fa5
DB: 2020-11-18
...
17 changes to exploits/shellcodes
Internet Explorer 11 - Use-After-Free
Microsoft Internet Explorer 11 - Use-After-Free
LCD_Service 1.0.1.0 - 'LCD_Service' Unquote Service Path
Microsoft Internet Explorer Windows 10 1809 17763.316 - Scripting Engine Memory Corruption
Aerospike Database 5.1.0.3 - OS Command Execution
Apache Struts 2.5.20 - Double OGNL evaluation
Car Rental Management System 1.0 - 'id' SQL Injection (Authenticated)
Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Injection
EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass
SugarCRM 6.5.18 - Persistent Cross-Site Scripting
WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting
Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting
2020-11-18 05:01:57 +00:00
Offensive Security
c7e37046e7
DB: 2020-11-17
...
12 changes to exploits/shellcodes
KiteService 1.2020.1113.1 - 'KiteService.exe' Unquoted Service Path
Advanced System Care Service 13 - 'AdvancedSystemCareService13' Unquoted Service Path
Logitech Solar Keyboard Service - 'L4301_Solar' Unquoted Service Path
Atheros Coex Service Application 8.0.0.255 - 'ZAtheros Bt&Wlan Coex Agent' Unquoted Service Path
Cisco 7937G - DoS/Privilege Escalation
Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
Car Rental Management System 1.0 - 'id' SQL Injection (Authenticated)
User Registration & Login and User Management System 2.1 - Login Bypass SQL Injection
PMB 5.6 - 'chemin' Local File Disclosure
Car Rental Management System 1.0 - Remote Code Execution (Authenticated)
Car Rental Management System 1.0 - 'car_id' Sql Injection
2020-11-17 05:01:57 +00:00
Offensive Security
b33d1ec015
DB: 2020-11-14
...
10 changes to exploits/shellcodes
DigitalPersona 5.1.0.656 'DpHostW' - Unquoted Service Path
SAntivirus IC 10.0.21.61 - 'SAntivirusIC' Unquoted Service Path
IDT PC Audio 1.0.6425.0 - 'STacSV' Unquoted Service Path
Bludit 3.9.2 - Authentication Bruteforce Bypass (Metasploit)
Citrix ADC NetScaler - Local File Inclusion (Metasploit)
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
Touchbase.io 1.10 - Stored Cross Site Scripting
OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
ASUS TM-AC1900 - Arbitrary Command Execution (Metasploit)
2020-11-14 05:01:59 +00:00
Offensive Security
ccc8fe2331
DB: 2020-11-13
...
7 changes to exploits/shellcodes
Nidesoft 3GP Video Converter 2.6.18 - Local Stack Buffer Overflow
WordPress Plugin Simple File List 5.4 - Arbitrary File Upload
WordPress Plugin Simple File List 4.2.2 - Arbitrary File Upload
Water Billing System 1.0 - 'username' and 'password' parameters SQL Injection
Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection
WordPress Plugin Simple File List 5.4 - Remote Code Execution
WordPress Plugin Simple File List 4.2.2 - Remote Code Execution
2020-11-13 05:01:58 +00:00
Offensive Security
e9fc264b77
DB: 2020-11-12
...
4 changes to exploits/shellcodes
Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel
Customer Support System 1.0 - Cross-Site Request Forgery
Customer Support System 1.0 - 'username' Authentication Bypass
CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated)
2020-11-12 05:01:58 +00:00
Offensive Security
3774170267
DB: 2020-11-11
...
4 changes to exploits/shellcodes
Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload
ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting
Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
2020-11-11 05:01:56 +00:00
Offensive Security
e797f5230d
DB: 2020-11-10
...
24 changes to exploits/shellcodes
HP Display Assistant x64 Edition 3.20 - 'DTSRVC' Unquoted Service Path
KMSpico 17.1.0.0 - 'Service KMSELDI' Unquoted Service Path
Winstep 18.06.0096 - 'Xtreme Service' Unquoted Service Path
OKI sPSV Port Manager 1.0.41 - 'sPSVOpLclSrv' Unquoted Service Path
IPTInstaller 4.0.9 - 'PassThru Service' Unquoted Service Path
Genexus Protection Server 9.6.4.2 - 'protsrvservice' Unquoted Service Path
DigitalPersona 4.5.0.2213 - 'DpHostW' Unquoted Service Path
Syncplify.me Server! 5.0.37 - 'SMWebRestServicev5' Unquoted Service Path
HP WMI Service 1.4.8.0 - 'HPWMISVC.exe' Unquoted Service Path
Motorola Device Manager 2.4.5 - 'ForwardDaemon.exe ' Unquoted Service Path
Motorola Device Manager 2.5.4 - 'MotoHelperService.exe' Unquoted Service Path
Motorola Device Manager 2.5.4 - 'ForwardDaemon.exe ' Unquoted Service Path
Realtek Andrea RT Filters 1.0.64.10 - 'AERTSr64.EXE' Unquoted Service Path
MEMU PLAY 3.7.0 - 'MEmusvc' Unquoted Service Path
Magic Mouse 2 utilities 2.20 - 'magicmouse2service' Unquoted Service Path
iDeskService 3.0.2.1 - 'iDeskService' Unquoted Service Path
Canon Inkjet Extended Survey Program 5.1.0.8 - 'IJPLMSVC.EXE' - Unquoted Service Path
Deep Instinct Windows Agent 1.2.24.0 - 'DeepNetworkService' Unquoted Service Path
RealTimes Desktop Service 18.1.4 - 'rpdsvc.exe' Unquoted Service Path
DiskBoss v11.7.28 - Multiple Services Unquoted Service Path
Privacy Drive v3.17.0 - 'pdsvc.exe' Unquoted Service Path
Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF
SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)
Joplin 1.2.6 - 'link' Cross Site Scripting
2020-11-10 05:02:05 +00:00
Offensive Security
690eb17718
DB: 2020-11-07
...
5 changes to exploits/shellcodes
SmartBlog 2.0.1 - 'id_post' Blind SQL injection
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated)
Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticated)
BlogEngine 3.3.8 - 'Content' Stored XSS
2020-11-07 05:01:57 +00:00
Offensive Security
6eb03eae23
DB: 2020-11-06
...
5 changes to exploits/shellcodes
Amarok 2.8.0 - Denial-of-Service
TP-Link WDR4300 - Remote Code Execution (Authenticated)
iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF)
iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass
iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege Escalation
2020-11-06 05:01:58 +00:00
Offensive Security
543f8dc781
DB: 2020-11-05
...
5 changes to exploits/shellcodes
Processwire CMS 2.4.0 - 'download' Local File Inclusion
PDW File Browser 1.3 - Remote Code Execution
School Log Management System 1.0 - 'username' SQL Injection / Remote Code Execution
Student Attendance Management System 1.0 - 'username' SQL Injection / Remote Code Execution
2020-11-05 05:01:59 +00:00
Offensive Security
302d11bcbf
DB: 2020-11-04
...
2 changes to exploits/shellcodes
Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated SQL Injection
Exploit Title: Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution
2020-11-04 05:02:02 +00:00
Offensive Security
3cad5bf9ad
DB: 2020-11-03
...
6 changes to exploits/shellcodes
Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
Quick N Easy FTP Service 3.2 - Unquoted Service Path
Apache Flink 1.9.x - File Upload RCE (Unauthenticated)
WordPress Plugin Simple File List 5.4 - Arbitrary File Upload
Monitorr 1.7.6m - Remote Code Execution (Unauthenticated)
Monitorr 1.7.6m - Authorization Bypass
2020-11-03 05:02:04 +00:00
Offensive Security
d852416732
DB: 2020-10-31
...
5 changes to exploits/shellcodes
CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting
DedeCMS v.5.8 - _keyword_ Cross-Site Scripting
Citadel WebCit < 926 - Session Hijacking Exploit
Online Job Portal 1.0 - 'userid' SQL Injection
Simple College Website 1.0 - 'username' SQL Injection / Remote Code Execution
2020-10-31 05:02:05 +00:00
Offensive Security
48bd7b3ea6
DB: 2020-10-30
...
4 changes to exploits/shellcodes
Online Examination System 1.0 - 'name' Stored Cross Site Scripting
Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)
WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE via GET request
Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot
2020-10-30 05:02:03 +00:00
Offensive Security
e178c80d85
DB: 2020-10-29
...
10 changes to exploits/shellcodes
PackageKit < 1.1.13 - File Existence Disclosure
aptdaemon < 1.1.1 - File Existence Disclosure
Blueman < 2.1.4 - Local Privilege Escalation
Exploit - EPSON 1.124 - 'seksmdb.exe' Unquoted Service Path
Program Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service Path
Prey 1.9.6 - _CronService_ Unquoted Service Path
IP Watcher v3.0.0.30 - 'PACService.exe' Unquoted Service Path
Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
CSE Bookstore 1.0 - Authentication Bypass
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
2020-10-29 05:02:08 +00:00
Offensive Security
17bbfdaf38
DB: 2020-10-28
...
6 changes to exploits/shellcodes
TDM Digital Signage PC Player 4.1 - Insecure File Permissions
Adtec Digital Multiple Products - Default Hardcoded Credentials Remote Root
GoAhead Web Server 5.1.1 - Digest Authentication Capture Replay Nonce Reuse
InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
Client Management System 1.0 - 'searchdata' SQL injection
Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated)
2020-10-28 05:02:08 +00:00
Offensive Security
7ce71393bb
DB: 2020-10-27
...
9 changes to exploits/shellcodes
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS)
Genexis Platinum-4410 - 'SSID' Persistent XSS
ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure
ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthenticated)
2020-10-27 05:02:17 +00:00
Offensive Security
99b2cc4c13
DB: 2020-10-24
...
17 changes to exploits/shellcodes
Online Library Management System 1.0 - Arbitrary File Upload
Ajenti 2.1.36 - Remote Code Execution (Authenticated)
Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
Car Rental Management System 1.0 - Arbitrary File Upload
User Registration & Login and User Management System 2.1 - SQL Injection
Point of Sales 1.0 - 'id' SQL Injection
Lot Reservation Management System 1.0 - Authentication Bypass
Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
Gym Management System 1.0 - 'id' SQL Injection
Point of Sales 1.0 - 'username' SQL Injection
School Faculty Scheduling System 1.0 - 'id' SQL Injection
School Faculty Scheduling System 1.0 - 'username' SQL Injection
Gym Management System 1.0 - Authentication Bypass
Gym Management System 1.0 - Stored Cross Site Scripting
Bludit 3.9.2 - Auth Bruteforce Bypass
TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
2020-10-24 05:02:08 +00:00
Offensive Security
1539c20e48
DB: 2020-10-22
...
8 changes to exploits/shellcodes
Hrsale 2.0.0 - Local File Inclusion
School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
School Faculty Scheduling System 1.0 - Authentication Bypass POC
GOautodial 4.0 - Authenticated Shell Upload
Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting
Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting
Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
2020-10-22 05:02:10 +00:00
Offensive Security
5aa3bfc759
DB: 2020-10-21
...
12 changes to exploits/shellcodes
Comtrend AR-5387un router - Persistent XSS (Authenticated)
Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated)
WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
Mobile Shop System v1.0 - SQL Injection Authentication Bypass
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated)
2020-10-21 05:02:11 +00:00
Offensive Security
ae14b71248
DB: 2020-10-20
...
16 changes to exploits/shellcodes
Tourism Management System 1.0 - Arbitrary File Upload
Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
Online Student's Management System 1.0 - Remote Code Execution (Authenticated)
Online Discussion Forum Site 1.0 - XSS in Messaging System
Online Job Portal 1.0 - Cross Site Scripting (Stored)
HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
HiSilicon Video Encoders - RCE via unauthenticated command injection
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
HiSilicon Video Encoders - Full admin access via backdoor password
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
Textpattern CMS 4.6.2 - Cross-site Request Forgery
2020-10-20 05:02:13 +00:00
Offensive Security
97ece9d27b
DB: 2020-10-17
...
11 changes to exploits/shellcodes
Employee Management System 1.0 - Cross Site Scripting (Stored)
Employee Management System 1.0 - Authentication Bypass
Alumni Management System 1.0 - Authentication Bypass
Company Visitor Management System (CVMS) 1.0 - Authentication Bypass
Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated)
aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated)
Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
Hotel Management System 1.0 - Remote Code Execution (Authenticated)
Seat Reservation System 1.0 - Unauthenticated SQL Injection
CS-Cart 1.3.3 - 'classes_dir' LFI
CS-Cart 1.3.3 - authenticated RCE
2020-10-17 05:02:09 +00:00
Offensive Security
cbf3e02444
DB: 2020-10-16
...
4 changes to exploits/shellcodes
Vehicle Parking Management System 1.0 - Authentication Bypass
rConfig 3.9.5 - Remote Code Execution (Unauthenticated)
Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass
Zoo Management System 1.0 - Authentication Bypass
2020-10-16 05:02:09 +00:00
Offensive Security
a3aad6c41a
DB: 2020-10-15
...
3 changes to exploits/shellcodes
Guild Wars 2 - Insecure Folder Permissions
TimeClock Software 0.995 - Multiple SQL Injections
TimeClock Software 0.995 - (Authenticated ) Multiple SQL Injections
TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection
NodeBB Forum 1.12.2-1.14.2 - Account Takeover
2020-10-15 05:02:06 +00:00
Offensive Security
973a669c08
DB: 2020-10-14
...
2 changes to exploits/shellcodes
Battle.Net 1.27.1.12428 - Insecure File Permissions
berliCRM 1.0.24 - 'src_record' SQL Injection
2020-10-14 05:02:04 +00:00
Offensive Security
14fcd4863f
DB: 2020-10-13
...
5 changes to exploits/shellcodes
Small CRM 2.0 - 'email' SQL Injection
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated)
Liman 0.7 - Cross-Site Request Forgery (Change Password)
Online Students Management System 1.0 - 'username' SQL Injections
Cisco ASA and FTD 9.6.4.42 - Path Traversal
2020-10-13 05:02:09 +00:00
Offensive Security
0aa8d538e2
DB: 2020-10-10
...
3 changes to exploits/shellcodes
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated)
openMAINT 1.1-2.4.2 - Arbitrary File Upload
2020-10-10 05:02:11 +00:00
Offensive Security
b45931e440
DB: 2020-10-09
...
2 changes to exploits/shellcodes
SEO Panel 4.6.0 - Remote Code Execution
D-Link DSR-250N 3.12 - Denial of Service (PoC)
2020-10-09 05:02:05 +00:00
Offensive Security
1fbf4d267e
DB: 2020-10-08
...
2 changes to exploits/shellcodes
BACnet Test Server 1.01 - Remote Denial of Service (PoC)
Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting
2020-10-08 05:02:12 +00:00
Offensive Security
7be5963105
DB: 2020-10-07
...
3 changes to exploits/shellcodes
Qmail SMTP 1.03 - Bash Environment Variable Injection
Karel IP Phone IP1211 Web Management Panel - Directory Traversal
EasyPMS 1.0.0 - Authentication Bypass
2020-10-07 05:02:06 +00:00
Offensive Security
1569af9b59
DB: 2020-10-06
...
2 changes to exploits/shellcodes
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
SpamTitan 7.07 - Unauthenticated Remote Code Execution
2020-10-06 05:02:05 +00:00
Offensive Security
9772f1e7c0
DB: 2020-10-03
...
2 changes to exploits/shellcodes
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
Photo Share Website 1.0 - Persistent Cross-Site Scripting
2020-10-03 05:02:10 +00:00
Offensive Security
f697a81a18
DB: 2020-10-02
...
12 changes to exploits/shellcodes
Sony IPELA Network Camera 1.82.01 - 'ftpclient.cgi' Remote Stack Buffer Overflow
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Request Forgery (Unauthenticated)
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path Traversal
SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure
SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Admin)
SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration
MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated)
WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated)
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated)
CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
Exhibitor Web UI 1.7.1 - Remote Code Execution
2020-10-02 05:02:08 +00:00
Offensive Security
fdab02c0ff
DB: 2020-09-30
...
3 changes to exploits/shellcodes
BearShare Lite 5.2.5 - 'Advanced Search'Buffer Overflow in (PoC)
CloudMe 1.11.2 - Buffer Overflow ROP (DEP_ASLR)
WebsiteBaker 2.12.2 - Remote Code Execution
2020-09-30 05:02:05 +00:00
Offensive Security
345eb88be8
DB: 2020-09-29
...
3 changes to exploits/shellcodes
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
Mida eFramework 2.8.9 - Remote Code Execution
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
2020-09-29 05:02:03 +00:00
Offensive Security
18829b7a22
DB: 2020-09-26
...
4 changes to exploits/shellcodes
BigTree CMS 4.4.10 - Remote Code Execution
Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated)
B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Maintenance Admin)
B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure
2020-09-26 05:02:04 +00:00
Offensive Security
72506f63c2
DB: 2020-09-25
...
2 changes to exploits/shellcodes
Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticated)
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
2020-09-25 05:02:10 +00:00
Offensive Security
00b27610c8
DB: 2020-09-24
...
2 changes to exploits/shellcodes
Online Food Ordering System 1.0 - Remote Code Execution
2020-09-24 05:02:05 +00:00
Offensive Security
1a8b74a305
DB: 2020-09-23
...
2 changes to exploits/shellcodes
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
2020-09-23 05:02:05 +00:00
Offensive Security
87f49d4427
DB: 2020-09-22
...
6 changes to exploits/shellcodes
ForensiTAppxService 2.2.0.4 - 'ForensiTAppxService.exe' Unquoted Service Path
Online Shop Project 1.0 - 'p' SQL Injection
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
Seat Reservation System 1.0 - 'id' SQL Injection
Mida eFramework 2.9.0 - Back Door Access
B-swiss 3 Digital Signage System 3.6.5 - Remote Code Execution
2020-09-22 05:02:05 +00:00
Offensive Security
0d8101f1a1
DB: 2020-09-19
...
2 changes to exploits/shellcodes
SpamTitan 7.07 - Remote Code Execution (Authenticated)
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
2020-09-19 05:02:05 +00:00