70472131cc
Merge remote-tracking branch 'exploitdb/main'
2025-04-12 00:01:16 +00:00
Exploit-DB
9d3e200bec
DB: 2025-04-11
...
12 changes to exploits/shellcodes/ghdb
Cosy+ firmware 21.2s7 - Command Injection
K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
Centron 19.04 - Remote Code Execution (RCE)
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
Feng Office 3.11.1.2 - SQL Injection
flatCore 1.5.5 - Arbitrary File Upload
PandoraFMS 7.0NG.772 - SQL Injection
Typecho 1.3.0 - Race Condition
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
2025-04-11 00:17:01 +00:00
1dbb33ef37
Merge remote-tracking branch 'exploitdb/main'
2025-04-11 00:01:15 +00:00
Exploit-DB
762197db08
DB: 2025-04-10
...
10 changes to exploits/shellcodes/ghdb
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
Artica Proxy 4.50 - Remote Code Execution (RCE)
ChurchCRM 5.9.1 - SQL Injection
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
DocsGPT 0.12.0 - Remote Code Execution
2025-04-10 00:16:32 +00:00
6a8464a842
Merge remote-tracking branch 'exploitdb/main'
2025-04-10 00:01:14 +00:00
Exploit-DB
2bc15f74f8
DB: 2025-04-09
...
9 changes to exploits/shellcodes/ghdb
InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE)
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
Jasmin Ransomware - Arbitrary File Download (Authenticated)
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
UNA CMS 14.0.0-RC - PHP Object Injection
WordPress User Registration & Membership Plugin 4.1.1 - Unauthenticated Privilege Escalation
2025-04-09 00:16:23 +00:00
3dd3814744
Merge remote-tracking branch 'exploitdb/main'
2025-04-09 00:01:14 +00:00
Exploit-DB
a8420434d2
DB: 2025-04-08
...
4 changes to exploits/shellcodes/ghdb
Apache Tomcat 11.0.3 - Remote Code Execution
XWiki Platform 15.10.10 - Remote Code Execution
YesWiki 4.5.1 - Unauthenticated Path Traversal
2025-04-08 00:16:25 +00:00
e89b67f424
Merge remote-tracking branch 'exploitdb/main'
2025-04-08 00:01:16 +00:00
Exploit-DB
881542919e
DB: 2025-04-07
...
7 changes to exploits/shellcodes/ghdb
DataEase 2.4.0 - Database Configuration Information Exposure
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
Watcharr 1.43.0 - Remote Code Execution (RCE)
WBCE CMS 1.6.3 - Authenticated Remote Code Execution (RCE)
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
2025-04-07 00:16:26 +00:00
b779de90fb
Merge remote-tracking branch 'exploitdb/main'
2025-04-07 00:01:26 +00:00
Exploit-DB
2bd993a7c3
DB: 2025-04-06
...
7 changes to exploits/shellcodes/ghdb
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
Exclusive Addons for Elementor 2.6.9 - Stored Cross-Site Scripting (XSS)
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
Next.js Middleware 15.2.2 - Authorization Bypass
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
Apache mod_proxy_cluster - Stored XSS
Apache mod_proxy_cluster 1.2.6 - Stored XSS
2025-04-06 00:16:39 +00:00
c617f78321
Merge remote-tracking branch 'exploitdb/main'
2025-04-06 00:01:31 +00:00
Exploit-DB
f8c80e2b5d
DB: 2025-04-05
...
4 changes to exploits/shellcodes/ghdb
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
2025-04-05 00:16:29 +00:00
9d894f7173
Merge remote-tracking branch 'exploitdb/main'
2025-04-05 00:01:12 +00:00
Exploit-DB
989122095f
DB: 2025-04-04
...
11 changes to exploits/shellcodes/ghdb
AppSmith 1.47 - Remote Code Execution (RCE)
ollama 0.6.4 - Server Side Request Forgery (SSRF)
Vite 6.2.2 - Arbitrary File Read
ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)
Nagios Log Server 2024R1.3.1 - Stored XSS
Webmin Usermin 2.100 - Username Enumeration
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
openSIS 9.1 - SQLi (Authenticated)
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
ProSSHD 1.2 - Denial of Service (DOS)
2025-04-04 00:16:25 +00:00
4a46a3ba95
Merge remote-tracking branch 'exploitdb/main'
2025-04-04 00:01:15 +00:00
Exploit-DB
c773b14d1c
DB: 2025-04-03
...
6 changes to exploits/shellcodes/ghdb
Mitel mitel-cs018 - Call Data Information Disclosure
SAP NetWeaver - 7.53 - HTTP Request Smuggling
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
ProSSHD 1.2 - Denial of Service (DOS)
2025-04-03 00:16:28 +00:00
b737bc0a14
Merge remote-tracking branch 'exploitdb/main'
2025-03-31 00:01:10 +00:00
Exploit-DB
6805102b8a
DB: 2025-03-30
...
3 changes to exploits/shellcodes/ghdb
XWiki Standard 14.10 - Remote Code Execution (RCE)
Solstice Pod 6.2 - API Session Key Extraction via API Endpoint
2025-03-30 00:16:28 +00:00
14e33639d5
Merge remote-tracking branch 'exploitdb/main'
2025-03-30 00:01:12 +00:00
Exploit-DB
353059c64d
DB: 2025-03-29
...
6 changes to exploits/shellcodes/ghdb
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
CodeCanyon RISE CRM 3.7.0 - SQL Injection
Litespeed Cache 6.5.0.1 - Authentication Bypass
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
2025-03-29 00:16:38 +00:00
535b1933b6
Merge remote-tracking branch 'exploitdb/main'
2025-03-28 18:47:11 +00:00
01eaff0244
modify get merge and set git config of job
2025-03-28 13:46:20 -05:00
dc6bc24dd7
change url of exploitdb to use their gitlab
2025-03-28 13:43:31 -05:00
189c9f77cf
add node container
2025-03-28 13:42:00 -05:00
e3c6b62579
store exploit-db-pull-and-sync.yaml action file
2025-03-28 13:40:21 -05:00
Exploit-DB
15b516383f
DB: 2025-03-28
...
4 changes to exploits/shellcodes/ghdb
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
MoziloCMS 3.0 - Remote Code Execution (RCE)
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
2025-03-28 00:16:32 +00:00
Exploit-DB
f33b83aeea
DB: 2025-03-27
...
2 changes to exploits/shellcodes/ghdb
NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
2025-03-27 00:16:28 +00:00
Exploit-DB
51ef1693d4
DB: 2025-03-23
...
4 changes to exploits/shellcodes/ghdb
Aztech DSL5005EN Router - 'sysAccess.asp' Admin Password Change (Unauthenticated)
TeamPass 3.0.0.21 - SQL Injection
Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
2025-03-23 00:16:32 +00:00
Exploit-DB
c185b4853b
DB: 2025-03-22
...
2 changes to exploits/shellcodes/ghdb
Jasmin Ransomware - SQL Injection Login Bypass
2025-03-22 00:16:33 +00:00
Exploit-DB
40ceb13974
DB: 2025-03-21
...
3 changes to exploits/shellcodes/ghdb
FluxBB 1.5.11 - Stored Cross-Site Scripting (XSS)
JUX Real Estate 3.4.0 - SQL Injection
2025-03-21 00:16:35 +00:00
Exploit-DB
04fa5ba95d
DB: 2025-03-20
...
6 changes to exploits/shellcodes/ghdb
Gitea 1.24.0 - HTML Injection
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
Loaded Commerce 6.6 - Client-Side Template Injection(CSTI)
TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)
VeeVPN 1.6.1 - Unquoted Service Path
2025-03-20 00:16:32 +00:00
Exploit-DB
b42ec1de46
DB: 2025-03-19
...
2 changes to exploits/shellcodes/ghdb
Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
2025-03-19 00:16:27 +00:00
Exploit-DB
731ce583a5
DB: 2024-11-26
...
3 changes to exploits/shellcodes/ghdb
AEGON LIFE v1.0 Life Insurance Management System - Unauthenticated Remote Code Execution (RCE)
2024-11-26 00:16:28 +00:00
Exploit-DB
773f5f480c
DB: 2024-11-16
...
2 changes to exploits/shellcodes/ghdb
SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)
2024-11-16 00:16:32 +00:00
Exploit-DB
b86fb6e1b7
DB: 2024-10-02
...
4 changes to exploits/shellcodes/ghdb
dizqueTV 1.5.3 - Remote Code Execution (RCE)
reNgine 2.2.0 - Command Injection (Authenticated)
openSIS 9.1 - SQLi (Authenticated)
2024-10-02 00:16:50 +00:00
Exploit-DB
32e0cc5e7f
DB: 2024-08-29
...
5 changes to exploits/shellcodes/ghdb
Gitea 1.22.0 - Stored XSS
NoteMark < 0.13.0 - Stored XSS
Invesalius3 - Remote Code Execution
Windows TCP/IP - RCE Checker and Denial of Service
2024-08-29 00:16:41 +00:00
Exploit-DB
76d99ff06e
DB: 2024-08-25
...
7 changes to exploits/shellcodes/ghdb
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Device Config
Elber Wayber Analog/Digital Audio STL 4.00 - Authentication Bypass
Elber Wayber Analog/Digital Audio STL 4.00 - Device Config Disclosure
HughesNet HT2000W Satellite Modem - Password Reset
Aurba 501 - Authenticated RCE
2024-08-25 00:16:25 +00:00
Exploit-DB
809d81619e
DB: 2024-08-24
...
4 changes to exploits/shellcodes/ghdb
Calibre-web 0.6.21 - Stored XSS
Helpdeskz v2.0.2 - Stored XSS
2024-08-24 00:16:35 +00:00
Exploit-DB
507bd26e3e
DB: 2024-08-05
...
6 changes to exploits/shellcodes/ghdb
Ivanti vADC 9.9 - Authentication Bypass
Devika v1 - Path Traversal via 'snapshot_path'
Genexus Protection Server 9.7.2.10 - 'protsrvservice' Unquoted Service Path
Oracle Database 12c Release 1 - Unquoted Service Path
SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
2024-08-05 00:16:24 +00:00
Exploit-DB
74ee6f57c7
DB: 2024-07-27
...
2 changes to exploits/shellcodes/ghdb
Monstra CMS 3.0.4 - Remote Code Execution (RCE)
2024-07-27 00:16:34 +00:00
Exploit-DB
c27f5a1741
DB: 2024-07-17
...
2 changes to exploits/shellcodes/ghdb
Bonjour Service 'mDNSResponder.exe' - Unquoted Service Path Privilege Escalation
2024-07-17 00:16:34 +00:00
Exploit-DB
388e822220
DB: 2024-07-05
...
1 changes to exploits/shellcodes/ghdb
2024-07-05 00:16:26 +00:00
Exploit-DB
859e322e5c
DB: 2024-07-03
...
13 changes to exploits/shellcodes/ghdb
ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) & SSH Access
Zyxel IKE Packet Decoder - Unauthenticated Remote Code Execution (Metasploit)
Rebar3 3.13.2 - Command Injection
Craft CMS Logs Plugin 3.0.3 - Path Traversal (Authenticated)
ZwiiCMS 12.2.04 - Remote Code Execution (Authenticated)
Wipro Holmes Orchestrator 20.4.1 - Log File Disclosure
2024-07-03 00:16:27 +00:00
Exploit-DB
ec14967376
DB: 2024-07-02
...
5 changes to exploits/shellcodes/ghdb
Azon Dominator Affiliate Marketing Script - SQL Injection
Customer Support System 1.0 - Stored XSS
Microweber 2.0.15 - Stored XSS
Xhibiter NFT Marketplace 1.10.2 - SQL Injection
2024-07-02 00:16:21 +00:00
Exploit-DB
2680e71d44
DB: 2024-06-27
...
5 changes to exploits/shellcodes/ghdb
SolarWinds Platform 2024.1 SR1 - Race Condition
Automad 2.0.0-alpha.4 - Stored Cross-Site Scripting (XSS)
Flatboard 3.2 - Stored Cross-Site Scripting (XSS) (Authenticated)
Poultry Farm Management System v1.0 - Remote Code Execution (RCE)
2024-06-27 00:16:25 +00:00
Exploit-DB
1064b5c455
DB: 2024-06-15
...
12 changes to exploits/shellcodes/ghdb
Zyxel IKE Packet Decoder - Unauthenticated Remote Code Execution (Metasploit)
Rebar3 3.13.2 - Command Injection
AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability.
AEGON LIFE v1.0 Life Insurance Management System - Stored cross-site scripting (XSS)
AEGON LIFE v1.0 Life Insurance Management System - Unauthenticated Remote Code Execution (RCE)
Boelter Blue System Management 1.3 - SQL Injection
Carbon Forum 5.9.0 - Stored XSS
PHP < 8.3.8 - Remote Code Execution (Unauthenticated) (Windows)
WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS) (Authenticated)
XMB 1.9.12.06 - Stored XSS
ZwiiCMS 12.2.04 - Remote Code Execution (Authenticated)
2024-06-15 00:16:21 +00:00
Exploit-DB
a99f08beda
DB: 2024-06-08
...
2 changes to exploits/shellcodes/ghdb
Backdrop CMS 1.27.1 - Remote Command Execution (RCE)
Backdrop CMS 1.27.1 - Authenticated Remote Command Execution (RCE)
2024-06-08 00:16:25 +00:00
Exploit-DB
8a32e340d5
DB: 2024-06-04
...
8 changes to exploits/shellcodes/ghdb
Sitefinity 15.0 - Cross-Site Scripting (XSS)
appRain CMF 4.0.5 - Remote Code Execution (RCE) (Authenticated)
CMSimple 5.15 - Remote Code Execution (RCE) (Authenticated)
Dotclear 2.29 - Remote Code Execution (RCE)
Monstra CMS 3.0.4 - Remote Code Execution (RCE)
Serendipity 2.5.0 - Remote Code Execution (RCE)
WBCE CMS v1.6.2 - Remote Code Execution (RCE)
2024-06-04 00:16:25 +00:00