Offensive Security
62c4c0421c
DB: 2022-03-22
...
3 changes to exploits/shellcodes
Hikvision IP Camera - Backdoor
Wordpress Plugin iQ Block Country 1.2.13 - Arbitrary File Deletion via Zip Slip (Authenticated)
2022-03-22 05:01:37 +00:00
Offensive Security
12a90d7198
DB: 2022-03-17
...
5 changes to exploits/shellcodes
Hikvision IP Camera - Backdoor
Apache APISIX 2.12.1 - Remote Code Execution (RCE)
Moodle 3.11.5 - SQLi (Authenticated)
Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated)
Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
2022-03-17 05:01:38 +00:00
Offensive Security
2ad6c86451
DB: 2022-03-15
...
4 changes to exploits/shellcodes
VIVE Runtime Service - 'ViveAgentService' Unquoted Service Path
Siemens S7-1200 - Unauthenticated Start/Stop Command
Baixar GLPI Project 9.4.6 - SQLi
2022-03-15 05:01:36 +00:00
Offensive Security
653f886e0b
DB: 2022-03-12
...
2 changes to exploits/shellcodes
Seowon SLR-120 Router - Remote Code Execution (Unauthenticated)
Tdarr 2.00.15 - Command Injection
2022-03-12 05:01:35 +00:00
Offensive Security
88a02fb8d8
DB: 2022-03-11
...
8 changes to exploits/shellcodes
Sony playmemories home - 'PMBDeviceInfoProvider' Unquoted Service Path
McAfee(R) Safe Connect VPN - Unquoted Service Path Elevation Of Privilege
BattlEye 0.9 - 'BEService' Unquoted Service Path
WOW21 5.0.1.9 - 'Service WOW21_Service' Unquoted Service Path
Sandboxie-Plus 5.50.2 - 'Service SbieSvc' Unquoted Service Path
Siemens S7-1200 - Unauthenticated Start/Stop Command
Zabbix 5.0.17 - Remote Code Execution (RCE) (Authenticated)
2022-03-11 05:01:39 +00:00
Offensive Security
280b8f430a
DB: 2022-03-10
...
5 changes to exploits/shellcodes
Cobian Backup 0.9 - Unquoted Service Path
Audio Conversion Wizard v2.01 - Buffer Overflow
Printix Client 1.3.1106.0 - Privilege Escalation
Wondershare Dr.Fone 12.0.18 - 'Wondershare InstallAssist' Unquoted Service Path
Webmin 1.984 - Remote Code Execution (Authenticated)
2022-03-10 05:01:37 +00:00
Offensive Security
188f217da1
DB: 2022-03-09
...
1 changes to exploits/shellcodes
Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)
2022-03-09 05:01:38 +00:00
Offensive Security
e8863e001f
DB: 2022-03-08
...
9 changes to exploits/shellcodes
Private Internet Access 3.3 - 'pia-service' Unquoted Service Path
Cloudflare WARP 1.4 - Unquoted Service Path
Malwarebytes 4.5 - Unquoted Service Path
Foxit PDF Reader 11.0 - Unquoted Service Path
Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
part-db 0.5.11 - Remote Code Execution (RCE)
Attendance and Payroll System v1.0 - Remote Code Execution (RCE)
Attendance and Payroll System v1.0 - SQLi Authentication Bypass
Hasura GraphQL 2.2.0 - Information Disclosure
2022-03-08 05:01:37 +00:00
Offensive Security
00bdb64074
DB: 2022-03-03
...
5 changes to exploits/shellcodes
Prowise Reflect v1.0.9 - Remote Keystroke Injection
Printix Client 1.3.1106.0 - Remote Code Execution (RCE)
Xerte 3.10.3 - Directory Traversal (Authenticated)
Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
2022-03-03 05:01:37 +00:00
Offensive Security
bba496461e
DB: 2022-03-01
...
6 changes to exploits/shellcodes
Cobian Reflector 0.9.93 RC1 - 'Password' Denial of Service (PoC)
Cobian Backup 11 Gravity 11.2.0.582 - 'Password' Denial of Service (PoC)
Cobian Backup Gravity 11.2.0.582 - 'CobianBackup11' Unquoted Service Path
WAGO 750-8212 PFC200 G2 2ETH RS - Privilege Escalation
Cipi Control Panel 3.1.15 - Stored Cross-Site Scripting (XSS) (Authenticated)
Casdoor 1.13.0 - SQL Injection (Unauthenticated)
2022-03-01 05:01:37 +00:00
Offensive Security
d0f0ae746a
DB: 2022-02-25
...
2 changes to exploits/shellcodes
Wondershare MirrorGo 2.0.11.346 - Insecure File Permissions
2022-02-25 05:01:36 +00:00
Offensive Security
7755ac3af6
DB: 2022-02-24
...
9 changes to exploits/shellcodes
Adobe ColdFusion 11 - LDAP Java Object Deserialization Remode Code Execution (RCE)
ICL ScadaFlex II SCADA Controllers SC-1/SC-2 1.03.07 - Remote File CRUD
Simple Real Estate Portal System 1.0 - 'id' SQLi
Air Cargo Management System v1.0 - SQLi
aaPanel 6.8.21 - Directory Traversal (Authenticated)
Student Record System 1.0 - 'cid' SQLi (Authenticated)
WebHMI 4.1.1 - Remote Code Execution (RCE) (Authenticated)
WebHMI 4.1 - Stored Cross Site Scripting (XSS) (Authenticated)
Microweber CMS 1.2.10 - Local File Inclusion (Authenticated) (Metasploit)
2022-02-24 05:01:36 +00:00
Offensive Security
7ebb89ceab
DB: 2022-02-23
...
1 changes to exploits/shellcodes
Adobe Flash Player - Integer Overflow
2022-02-23 05:01:36 +00:00
Offensive Security
8691f166f7
DB: 2022-02-22
...
12 changes to exploits/shellcodes
HMA VPN 5.3 - Unquoted Service Path
Cyclades Serial Console Server 3.3.0 - Local Privilege Escalation
Microsoft Gaming Services 2.52.13001.0 - Unquoted Service Path
WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
Cab Management System 1.0 - 'id' SQLi (Authenticated)
Microweber 1.2.11 - Remote Code Execution (RCE) (Authenticated)
Cab Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
Thinfinity VirtualUI 2.5.41.0 - IFRAME Injection
Thinfinity VirtualUI 2.5.26.2 - Information Disclosure
WordPress Plugin WP User Frontend 3.5.25 - SQLi (Authenticated)
FileCloud 21.2 - Cross-Site Request Forgery (CSRF)
Dbltek GoIP - Local File Inclusion
2022-02-22 05:01:37 +00:00
Offensive Security
f2d7e05ad0
DB: 2022-02-19
...
17 changes to exploits/shellcodes
Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path
Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path
Wondershare FamiSafe 1.0 - 'FSService' Unquoted Service Path
Wondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service Path
TOSHIBA DVD PLAYER Navi Support Service - 'TNaviSrv' Unquoted Service Path
Bluetooth Application 5.4.277 - 'BlueSoleilCS' Unquoted Service Path
Intel(R) Management Engine Components 6.0.0.1189 - 'LMS' Unquoted Service Path
File Sanitizer for HP ProtectTools 5.0.1.3 - 'HPFSService' Unquoted Service Path
Connectify Hotspot 2018 'ConnectifyService' - Unquoted Service Path
WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
WordPress Plugin dzs-zoomsounds 6.60 - Remote Code Execution (RCE) (Unauthenticated)
Hotel Druid 3.0.3 - Remote Code Execution (RCE)
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
Solaris/SPARC - setuid(0) + chmod (/bin/ksh) + exit(0) Shellcode
Solaris/SPARC - chmod(./me) Shellcode
Solaris/SPARC - setuid(0) + execve (/bin/ksh) Shellcode
Linux/MIPS - N32 MSB Reverse Shell Shellcode
2022-02-19 05:01:36 +00:00
Offensive Security
a300bd948f
DB: 2022-02-17
...
8 changes to exploits/shellcodes
TeamSpeak 3.5.6 - Insecure File Permissions
Emerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path
H3C SSL VPN - Username Enumeration
Multi-Vendor Online Groceries Management System 1.0 - 'id' Blind SQL Injection
Simple Student Quarterly Result/Grade System 1.0 - SQLi Authentication Bypass
ServiceNow - Username Enumeration
Network Video Recorder NVR304-16EP - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
2022-02-17 05:01:36 +00:00
Offensive Security
07b4b32301
DB: 2022-02-12
...
4 changes to exploits/shellcodes
Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated)
Accounting Journal Management System 1.0 - 'id' SQLi (Authenticated)
Subrion CMS 4.2.1 - Cross Site Request Forgery (CSRF) (Add Amin)
2022-02-12 05:02:07 +00:00
Offensive Security
a6102b7922
DB: 2022-02-11
...
8 changes to exploits/shellcodes
Cain & Abel 4.9.56 - Unquoted Service Path
Hospital Management Startup 1.0 - 'Multiple' SQLi
Home Owners Collection Management System 1.0 - Account Takeover (Unauthenticated)
Home Owners Collection Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
Home Owners Collection Management System 1.0 - 'id' Blind SQL Injection
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
WordPress Plugin Contact Form Builder 1.6.1 - Cross-Site Scripting (XSS)
WordPress Plugin Jetpack 9.1 - Cross Site Scripting (XSS)
2022-02-11 05:02:01 +00:00
Offensive Security
c86e2ee727
DB: 2022-02-10
...
3 changes to exploits/shellcodes
Exam Reviewer Management System 1.0 - ‘id’ SQL Injection
Exam Reviewer Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
AtomCMS v2.0 - SQLi
2022-02-10 05:02:00 +00:00
Offensive Security
41553c4004
DB: 2022-02-09
...
11 changes to exploits/shellcodes
Wing FTP Server 4.3.8 - Remote Code Execution (RCE) (Authenticated)
Hotel Reservation System 1.0 - SQLi (Unauthenticated)
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
Hospital Management System 4.0 - 'multiple' SQL Injection
WordPress Plugin International Sms For Contact Form 7 Integration V1.2 - Cross Site Scripting (XSS)
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
Windows/x86 - Locate kernel32 base address / Stack Crack method NullFree Shellcode (171 bytes)
2022-02-09 05:02:00 +00:00
Offensive Security
30be173453
DB: 2022-02-05
...
8 changes to exploits/shellcodes
FLAME II MODEM USB - Unquoted Service Path
WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)
WordPress Plugin IP2Location Country Blocker 2.26.7 - Stored Cross Site Scripting (XSS) (Authenticated)
Servisnet Tessa - Privilege Escalation (Metasploit)
Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit)
Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit)
Windows/x86 - Download File and Execute / Dynamic PEB & EDT method Shellcode (458 bytes)
Windows/x86 - Locate kernel32 base address / Memory Sieve method Shellcode (133 bytes)
2022-02-05 05:01:59 +00:00
Offensive Security
ad453a2c73
DB: 2022-02-03
...
17 changes to exploits/shellcodes
CONTPAQi(R) AdminPAQ 14.0.0 - Unquoted Service Path
Mozilla Firefox 67 - Array.pop JIT Type Confusion
Fetch Softworks Fetch FTP Client 5.8 - Remote CPU Consumption (Denial of Service)
Ametys CMS v4.4.1 - Cross Site Scripting (XSS)
uBidAuction v2.0.1 - 'Multiple' Cross Site Scripting (XSS)
Chamilo LMS 1.11.14 - Account Takeover
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
PHP Restaurants 1.0 - SQLi (Unauthenticated)
Moodle 3.11.4 - SQL Injection
Huawei DG8045 Router 1.0 - Credential Disclosure
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
2022-02-03 05:01:57 +00:00
Offensive Security
4dfb7acc62
DB: 2022-01-29
...
5 changes to exploits/shellcodes
2022-01-29 05:02:01 +00:00
Offensive Security
d3b7d652cc
DB: 2022-01-28
...
5 changes to exploits/shellcodes
PolicyKit-1 0.105-31 - Privilege Escalation
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)
WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
2022-01-28 05:01:59 +00:00
Offensive Security
f6940281e8
DB: 2022-01-26
...
3 changes to exploits/shellcodes
Online Project Time Management System 1.0 - SQLi (Authenticated)
Online Project Time Management System 1.0 - Multiple Stored Cross Site Scripting (XSS) (Authenticated)
PHPIPAM 1.4.4 - SQLi (Authenticated)
2022-01-26 05:02:00 +00:00
Offensive Security
852da66bed
DB: 2022-01-25
...
1 changes to exploits/shellcodes
Landa Driving School Management System 2.0.1 - Arbitrary File Upload
2022-01-25 05:02:04 +00:00
Offensive Security
034f9fe70c
DB: 2022-01-20
...
3 changes to exploits/shellcodes
uDoctorAppointment v2.1.1 - 'Multiple' Cross Site Scripting (XSS)
Rocket LMS 1.1 - Persistent Cross Site Scripting (XSS)
Affiliate Pro 1.7 - 'Multiple' Cross Site Scripting (XSS)
2022-01-20 05:02:05 +00:00
Offensive Security
eb2b6f5cfd
DB: 2022-01-19
...
12 changes to exploits/shellcodes
WorkTime 10.20 Build 4967 - Unquoted Service Path
Archeevo 5.0 - Local File Inclusion
Online Resort Management System 1.0 - SQLi (Authenticated)
OpenBMCS 2.4 - Cross Site Request Forgery (CSRF)
OpenBMCS 2.4 - SQLi (Authenticated)
OpenBMCS 2.4 - Create Admin / Remote Privilege Escalation
OpenBMCS 2.4 - Server Side Request Forgery (SSRF) (Unauthenticated)
OpenBMCS 2.4 - Information Disclosure
Simple Chatbot Application 1.0 - Remote Code Execution (RCE)
Simple Chatbot Application 1.0 - 'message' Blind SQLi
Nyron 1.0 - SQLi (Unauthenticated)
Creston Web Interface 1.0.0.2159 - Credential Disclosure
2022-01-19 05:01:58 +00:00
Offensive Security
77bb25c902
DB: 2022-01-14
...
8 changes to exploits/shellcodes
Hospitals Patient Records Management System 1.0 - 'room_types' Stored Cross Site Scripting (XSS)
Hospitals Patient Records Management System 1.0 - 'room_list' Stored Cross Site Scripting (XSS)
Hospitals Patient Records Management System 1.0 - 'doctors' Stored Cross Site Scripting (XSS)
SalonERP 3.0.1 - 'sql' SQL Injection (Authenticated)
Online Diagnostic Lab Management System 1.0 - Account Takeover (Unauthenticated)
Online Diagnostic Lab Management System 1.0 - Stored Cross Site Scripting (XSS)
Online Diagnostic Lab Management System 1.0 - SQL Injection (Unauthenticated)
WordPress Core 5.8.2 - 'WP_Query' SQL Injection
2022-01-14 05:01:58 +00:00
Offensive Security
00e20a3a1c
DB: 2022-01-13
...
3 changes to exploits/shellcodes
Microsoft Windows .Reg File - Dialog Spoof / Mitigation Bypass
Microsoft Windows Defender - Detections Bypass
WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)
2022-01-13 05:01:58 +00:00
Offensive Security
6a94460ed6
DB: 2022-01-11
...
8 changes to exploits/shellcodes
VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
CoreFTP Server build 725 - Directory Traversal (Authenticated)
HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS)
Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated)
Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated)
Online Railway Reservation System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS) (Unauthenticated)
Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated)
2022-01-11 05:01:55 +00:00
Offensive Security
76c02f99c3
DB: 2022-01-08
...
1 changes to exploits/shellcodes
Online Veterinary Appointment System 1.0 - 'Multiple' SQL Injection
2022-01-08 05:01:55 +00:00
Offensive Security
1472d8e723
DB: 2022-01-06
...
32 changes to exploits/shellcodes
Siemens S7 Layer 2 - Denial of Service (DoS)
TRIGONE Remote System Monitor 3.61 - Unquoted Service Path
Automox Agent 32 - Local Privilege Escalation
ConnectWise Control 19.2.24707 - Username Enumeration
Accu-Time Systems MAXIMUS 1.0 - Telnet Remote Buffer Overflow (DoS)
AWebServer GhostBuilding 18 - Denial of Service (DoS)
TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
Dixell XWEB 500 - Arbitrary File Write
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
CMSimple 5.4 - Cross Site Scripting (XSS)
RiteCMS 3.1.0 - Arbitrary File Overwrite (Authenticated)
RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated)
RiteCMS 3.1.0 - Remote Code Execution (RCE) (Authenticated)
WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated)
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
Movie Rating System 1.0 - Broken Access Control (Admin Account Creation) (Unauthenticated)
Movie Rating System 1.0 - SQLi to RCE (Unauthenticated)
Online Admission System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
Library System in PHP 1.0 - 'publisher name' Stored Cross-Site Scripting (XSS)
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
Nettmp NNT 5.1 - SQLi Authentication Bypass
Hostel Management System 2.1 - Cross Site Scripting (XSS)
Hospitals Patient Records Management System 1.0 - 'id' SQL Injection (Authenticated)
BeyondTrust Remote Support 6.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
Hospitals Patient Records Management System 1.0 - Account TakeOver
Virtual Airlines Manager 2.6.2 - 'multiple' SQL Injection
Terramaster TOS 4.2.15 - Remote Code Execution (RCE) (Unauthenticated)
Vodafone H-500-s 3.5.10 - WiFi Password Disclosure
openSIS Student Information System 8.0 - 'multiple' SQL Injection
Projeqtor v9.3.1 - Stored Cross Site Scripting (XSS)
WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated)
2022-01-06 05:01:54 +00:00
Offensive Security
00cc9f489e
DB: 2021-12-21
...
3 changes to exploits/shellcodes
WBCE CMS 1.5.1 - Admin Password Reset
phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated)
Exponent CMS 2.6 - Multiple Vulnerabilities
2021-12-21 05:01:55 +00:00
Offensive Security
b9164fdd7e
DB: 2021-12-18
...
1 changes to exploits/shellcodes
2021-12-18 05:01:56 +00:00
Offensive Security
929e254945
DB: 2021-12-17
...
4 changes to exploits/shellcodes
Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
Croogo 3.0.2 - Unrestricted File Upload
Croogo 3.0.2 - 'Multiple' Stored Cross-Site Scripting (XSS)
Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
2021-12-17 05:01:54 +00:00
Offensive Security
3d06837f80
DB: 2021-12-16
...
2 changes to exploits/shellcodes
Oliver Library Server v5 - Arbitrary File Download
2021-12-16 05:01:55 +00:00
Offensive Security
90f7e494d6
DB: 2021-12-15
...
9 changes to exploits/shellcodes
Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)
Microsoft Internet Explorer / ActiveX Control - Security Bypass
Apache Log4j2 2.14.1 - Information Disclosure
Apache Log4j 2 - Remote Code Execution (RCE)
WordPress Plugin Typebot 1.4.3 - Stored Cross Site Scripting (XSS) (Authenticated)
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
Zucchetti Axess CLOKI Access Control 1.64 - Cross Site Request Forgery (CSRF)
meterN v1.2.3 - Remote Code Execution (RCE) (Authenticated)
Online Thesis Archiving System 1.0 - SQLi Authentication Bypass
2021-12-15 05:01:54 +00:00
Offensive Security
28e83a8de5
DB: 2021-12-14
...
2 changes to exploits/shellcodes
HD-Network Real-time Monitoring System 2.0 - Local File Inclusion (LFI)
WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
2021-12-14 05:02:04 +00:00
Offensive Security
55af36c59a
DB: 2021-12-11
...
3 changes to exploits/shellcodes
OpenCATS 0.9.4 - Remote Code Execution (RCE)
Free School Management Software 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
Free School Management Software 1.0 - Remote Code Execution (RCE)
2021-12-11 05:02:09 +00:00
Offensive Security
c906261f2c
DB: 2021-12-10
...
11 changes to exploits/shellcodes
MTPutty 1.0.1.21 - SSH Password Disclosure
Raspberry Pi 5.10 - Default Credentials
Chikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)
Chikitsa Patient Management System 2.0.2 - 'backup' Remote Code Execution (RCE) (Authenticated)
LimeSurvey 5.2.4 - Remote Code Execution (RCE) (Authenticated)
TestLink 1.19 - Arbitrary File Download (Unauthenticated)
Student Management System 1.0 - SQLi Authentication Bypass
Wordpress Plugin Catch Themes Demo Import 1.6.1 - Remote Code Execution (RCE) (Authenticated)
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
Employees Daily Task Management System 1.0 - 'username' SQLi Authentication Bypass
Employees Daily Task Management System 1.0 - 'multiple' Cross Site Scripting (XSS)
2021-12-10 05:02:03 +00:00
Offensive Security
0990eb4d38
DB: 2021-12-07
...
8 changes to exploits/shellcodes
HCL Lotus Notes V12 - Unquoted Service Path
Auerswald COMfortel 2.8F - Authentication Bypass
Auerswald COMpact 8.0B - Privilege Escalation
Auerswald COMpact 8.0B - Arbitrary File Disclosure
Auerswald COMpact 8.0B - Multiple Backdoors
Advanced Comment System 1.0 - Remote Command Execution (RCE)
Croogo 3.0.2 - Remote Code Execution (Authenticated)
2021-12-07 05:02:00 +00:00
Offensive Security
34c9d56d78
DB: 2021-12-04
...
5 changes to exploits/shellcodes
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
Online Magazine Management System 1.0 - SQLi Authentication Bypass
WordPress Plugin All-in-One Video Gallery plugin 2.4.9 - Local File Inclusion (LFI)
WordPress Plugin Slider by Soliloquy 2.6.2 - 'title' Stored Cross Site Scripting (XSS) (Authenticated)
WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated)
2021-12-04 05:02:12 +00:00
Offensive Security
1abdd81300
DB: 2021-12-02
...
4 changes to exploits/shellcodes
MilleGPG5 5.7.2 Luglio 2021 - Local Privilege Escalation
Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
Advanced Comment System 1.0 - Remote Command Execution (RCE)
2021-12-02 05:02:09 +00:00
Offensive Security
ebf638ee1a
DB: 2021-12-01
...
1 changes to exploits/shellcodes
Laundry Booking Management System 1.0 - Remote Code Execution (RCE)
2021-12-01 05:02:07 +00:00
Offensive Security
897c47e020
DB: 2021-11-30
...
7 changes to exploits/shellcodes
Joomla! 3.9.13 - 'Host' Header Injection
orangescrum 1.8.0 - Privilege escalation (Authenticated)
orangescrum 1.8.0 - 'Multiple' SQL Injection (Authenticated)
orangescrum 1.8.0 - 'Multiple' Cross-Site Scripting (XSS) (Authenticated)
opencart 3.0.3.8 - Sessjion Injection
2021-11-30 05:02:04 +00:00
Offensive Security
c60e7e2012
DB: 2021-11-27
...
1 changes to exploits/shellcodes
Bagisto 1.3.3 - Client-Side Template Injection
2021-11-27 05:02:13 +00:00
Offensive Security
268efc5072
DB: 2021-11-25
...
3 changes to exploits/shellcodes
HTTPDebuggerPro 9.11 - Unquoted Service Path
CMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated)
2021-11-25 05:02:12 +00:00
Offensive Security
e774c1d169
DB: 2021-11-24
...
6 changes to exploits/shellcodes
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
GNU gdbserver 9.2 - Remote Command Execution (RCE)
Wordpress Plugin WP Guppy 1.1 - WP-JSON API Sensitive Information Disclosure
Webrun 3.6.0.42 - 'P_0' SQL Injection
Bus Pass Management System 1.0 - 'Search' SQL injection
FLEX 1085 Web 1.6.0 - HTML Injection
2021-11-24 05:02:19 +00:00
Offensive Security
942d2d4f25
DB: 2021-11-23
...
3 changes to exploits/shellcodes
Pinkie 2.15 - TFTP Remote Buffer Overflow (PoC)
Modbus Slave 7.3.1 - Buffer Overflow (DoS)
Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection
2021-11-23 05:02:19 +00:00