Exploit-DB
9044a602bb
DB: 2025-05-10
...
6 changes to exploits/shellcodes/ghdb
Apache ActiveMQ 6.1.6 - Denial of Service (DOS)
SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation
WordPress Depicter Plugin 3.6.1 - SQL Injection
Microsoft Windows 11 Pro 23H2 - Ancillary Function Driver for WinSock Privilege Escalation
VirtualBox 7.0.16 - Privilege Escalation
2025-05-10 00:16:28 +00:00
Exploit-DB
71bfc9b6c5
DB: 2025-04-20
...
3 changes to exploits/shellcodes/ghdb
FoxCMS 1.2.5 - Remote Code Execution (RCE)
Drupal 11.x-dev - Full Path Disclosure
2025-04-20 00:16:27 +00:00
Exploit-DB
8ce497b2c8
DB: 2025-04-19
...
8 changes to exploits/shellcodes/ghdb
Langflow 1.3.0 - Remote Code Execution (RCE)
Apache Commons Text 1.10.0 - Remote Code Execution
Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation
UJCMS 9.6.3 - User Enumeration via IDOR
Inventio Lite 4 - SQL Injection
KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated SQL Injection
Tatsu 3.3.11 - Unauthenticated RCE
2025-04-19 00:16:29 +00:00
Exploit-DB
9ddf81331a
DB: 2025-04-18
...
10 changes to exploits/shellcodes/ghdb
TP-Link VN020 F3v(T) TT_V6.2.1021 - Buffer Overflow Memory Corruption
TP-Link VN020 F3v(T) TT_V6.2.1021 - Denial Of Service (DOS)
Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE)
Blood Bank & Donor Management System 2.4 - CSRF Improper Input Validation
compop.ca 3.5.3 - Arbitrary code Execution
Usermin 2.100 - Username Enumeration
ABB Cylon Aspect 3.08.02 (deployStart.php) - Unauthenticated Command Execution
ABB Cylon Aspect 3.08.02 (ethernetUpdate.php) - Authenticated Path Traversal
AnyDesk 9.0.1 - Unquoted Service Path
2025-04-18 00:16:31 +00:00
Exploit-DB
7ebfc36557
DB: 2025-04-17
...
24 changes to exploits/shellcodes/ghdb
ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE)
Ruckus IoT Controller 1.7.1.0 - Undocumented Backdoor Account
Dell EMC iDRAC7/iDRAC8 2.52.52.52 - Remote Code Execution (RCE)
FLIR AX8 1.46.16 - Remote Command Injection
ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF)
Ethercreative Logs 3.0.3 - Path Traversal
Garage Management System 1.0 (categoriesName) - Stored XSS
Nagios Log Server 2024R1.3.1 - Stored XSS
ProConf 6.0 - Insecure Direct Object Reference (IDOR)
Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection
ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) - File Write DoS
ABB Cylon Aspect 4.00.00 (factorySaved.php) - Unauthenticated XSS
ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution
Car Rental Project 1.0 - Remote Code Execution
KodExplorer 4.52 - Open Redirect
NagVis 1.9.33 - Arbitrary File Read
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
phpMyFAQ 3.2.10 - Unintended File Download Triggered by Embedded Frames
Smart Manager 8.27.0 - Post-Authenticated SQL Injection
Zabbix 7.0.0 - SQL Injection
Hugging Face Transformers MobileViTV2 4.41.1 - Remote Code Execution (RCE)
Fortinet FortiOS_ FortiProxy_ and FortiSwitchManager 7.2.0 - Authentication bypass
WebMethods Integration Server 10.15.0.0000-0092 - Improper Access on Login Page
2025-04-17 00:16:29 +00:00
Exploit-DB
b905517ca9
DB: 2025-04-16
...
22 changes to exploits/shellcodes/ghdb
Spring Boot common-user-management 0.1 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.07.02 (userManagement.php) - Weak Password Policy
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) - Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (licenseUpload.php) - Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 - Cookie User Password Disclosure
ABB Cylon Aspect 3.08.03 (CookieDB) - SQL Injection
Ivanti Connect Secure 22.7R2.5 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.08.03 (MapServicesHandler) - Authenticated Reflected XSS
ABB Cylon Aspect 3.08.03 - Hard-coded Secrets
Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE)
IBMi Navigator 7.5 - HTTP Security Token Bypass
IBMi Navigator 7.5 - Server Side Request Forgery (SSRF)
Plane 0.23.1 - Server side request forgery (SSRF)
ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) - Denial of Service (DOS)
ABB Cylon Aspect 3.08.02 (webServerUpdate.php) - Input Validation Config Poisoning
Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
OpenCMS 17.0 - Stored Cross Site Scripting (XSS)
Really Simple Security 9.1.1.1 - Authentication Bypass
Pymatgen 2024.1 - Remote Code Execution (RCE)
2025-04-16 00:16:24 +00:00
Exploit-DB
0f3d104e83
DB: 2025-04-15
...
15 changes to exploits/shellcodes/ghdb
ZTE ZXHN H168N 3.1 - Remote Code Execution (RCE) via authentication bypass
GestioIP 3.5.7 - Cross-Site Request Forgery (CSRF)
GestioIP 3.5.7 - Cross-Site Scripting (XSS)
GestioIP 3.5.7 - Reflected Cross-Site Scripting (Reflected XSS)
GestioIP 3.5.7 - Remote Command Execution (RCE)
GestioIP 3.5.7 - Stored Cross-Site Scripting (Stored XSS)
OpenPanel 0.3.4 - Directory Traversal
OpenPanel 0.3.4 - Incorrect Access Control
OpenPanel 0.3.4 - OS Command Injection
OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal
Pimcore 11.4.2 - Stored cross site scripting
Pimcore customer-data-framework 4.2.0 - SQL injection
SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated)
Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
2025-04-15 00:16:26 +00:00
Exploit-DB
60175c9963
DB: 2025-04-14
...
52 changes to exploits/shellcodes/ghdb
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
DataEase 2.4.0 - Database Configuration Information Exposure
Cosy+ firmware 21.2s7 - Command Injection
Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.07.02 - File Disclosure
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
CyberPanel 2.3.6 - Remote Code Execution (RCE)
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
MagnusSolution magnusbilling 7.3.0 - Command Injection
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
Watcharr 1.43.0 - Remote Code Execution (RCE)
Webmin Usermin 2.100 - Username Enumeration
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
Artica Proxy 4.50 - Remote Code Execution (RCE)
Centron 19.04 - Remote Code Execution (RCE)
ChurchCRM 5.9.1 - SQL Injection
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
CodeCanyon RISE CRM 3.7.0 - SQL Injection
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
Feng Office 3.11.1.2 - SQL Injection
flatCore 1.5 - Cross Site Request Forgery (CSRF)
flatCore 1.5.5 - Arbitrary File Upload
flatCore 1.5 - Cross Site Request Forgery (CSRF)
flatCore 1.5.5 - Arbitrary File Upload
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
Gnuboard5 5.3.2.8 - SQL Injection
LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
Litespeed Cache 6.5.0.1 - Authentication Bypass
MiniCMS 1.1 - Cross Site Scripting (XSS)
MoziloCMS 3.0 - Remote Code Execution (RCE)
NEWS-BUZZ News Management System 1.0 - SQL Injection
PandoraFMS 7.0NG.772 - SQL Injection
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
RosarioSIS 7.6 - SQL Injection
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
Typecho 1.3.0 - Race Condition
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
Typecho 1.3.0 - Race Condition
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
2025-04-14 00:16:26 +00:00
Exploit-DB
b165516b1b
DB: 2025-04-12
...
26 changes to exploits/shellcodes/ghdb
ABB Cylon Aspect 3.08.02 - PHP Session Fixation
ABB Cylon FLXeon 9.3.4 - Cross-Site Request Forgery
ABB Cylon FLXeon 9.3.4 - Default Credentials
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning
Netman 204 - Remote command without authentication
qBittorrent 5.0.1 - MITM RCE
CMU CERT/CC VINCE 2.0.6 - Stored XSS
CyberPanel 2.3.6 - Remote Code Execution (RCE)
GeoVision GV-ASManager 6.1.0.0 - Broken Access Control
GeoVision GV-ASManager 6.1.1.0 - CSRF
MagnusSolution magnusbilling 7.3.0 - Command Injection
Nagios Log Server 2024R1.3.1 - API Key Exposure
WebFileSys 2.31.0 - Directory Path Traversal
flatCore 1.5 - Cross Site Request Forgery (CSRF)
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
Gnuboard5 5.3.2.8 - SQL Injection
LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
MiniCMS 1.1 - Cross Site Scripting (XSS)
NEWS-BUZZ News Management System 1.0 - SQL Injection
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
RosarioSIS 7.6 - SQL Injection
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
2025-04-12 00:16:31 +00:00
Exploit-DB
9d3e200bec
DB: 2025-04-11
...
12 changes to exploits/shellcodes/ghdb
Cosy+ firmware 21.2s7 - Command Injection
K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
Centron 19.04 - Remote Code Execution (RCE)
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
Feng Office 3.11.1.2 - SQL Injection
flatCore 1.5.5 - Arbitrary File Upload
PandoraFMS 7.0NG.772 - SQL Injection
Typecho 1.3.0 - Race Condition
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
2025-04-11 00:17:01 +00:00
Exploit-DB
762197db08
DB: 2025-04-10
...
10 changes to exploits/shellcodes/ghdb
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
Artica Proxy 4.50 - Remote Code Execution (RCE)
ChurchCRM 5.9.1 - SQL Injection
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
DocsGPT 0.12.0 - Remote Code Execution
2025-04-10 00:16:32 +00:00
Exploit-DB
2bc15f74f8
DB: 2025-04-09
...
9 changes to exploits/shellcodes/ghdb
InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE)
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
Jasmin Ransomware - Arbitrary File Download (Authenticated)
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
UNA CMS 14.0.0-RC - PHP Object Injection
WordPress User Registration & Membership Plugin 4.1.1 - Unauthenticated Privilege Escalation
2025-04-09 00:16:23 +00:00
Exploit-DB
a8420434d2
DB: 2025-04-08
...
4 changes to exploits/shellcodes/ghdb
Apache Tomcat 11.0.3 - Remote Code Execution
XWiki Platform 15.10.10 - Remote Code Execution
YesWiki 4.5.1 - Unauthenticated Path Traversal
2025-04-08 00:16:25 +00:00
Exploit-DB
881542919e
DB: 2025-04-07
...
7 changes to exploits/shellcodes/ghdb
DataEase 2.4.0 - Database Configuration Information Exposure
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
Watcharr 1.43.0 - Remote Code Execution (RCE)
WBCE CMS 1.6.3 - Authenticated Remote Code Execution (RCE)
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
2025-04-07 00:16:26 +00:00
Exploit-DB
2bd993a7c3
DB: 2025-04-06
...
7 changes to exploits/shellcodes/ghdb
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
Exclusive Addons for Elementor 2.6.9 - Stored Cross-Site Scripting (XSS)
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
Next.js Middleware 15.2.2 - Authorization Bypass
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
Apache mod_proxy_cluster - Stored XSS
Apache mod_proxy_cluster 1.2.6 - Stored XSS
2025-04-06 00:16:39 +00:00
Exploit-DB
989122095f
DB: 2025-04-04
...
11 changes to exploits/shellcodes/ghdb
AppSmith 1.47 - Remote Code Execution (RCE)
ollama 0.6.4 - Server Side Request Forgery (SSRF)
Vite 6.2.2 - Arbitrary File Read
ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)
Nagios Log Server 2024R1.3.1 - Stored XSS
Webmin Usermin 2.100 - Username Enumeration
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
openSIS 9.1 - SQLi (Authenticated)
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
ProSSHD 1.2 - Denial of Service (DOS)
2025-04-04 00:16:25 +00:00
Exploit-DB
c773b14d1c
DB: 2025-04-03
...
6 changes to exploits/shellcodes/ghdb
Mitel mitel-cs018 - Call Data Information Disclosure
SAP NetWeaver - 7.53 - HTTP Request Smuggling
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
ProSSHD 1.2 - Denial of Service (DOS)
2025-04-03 00:16:28 +00:00
Exploit-DB
353059c64d
DB: 2025-03-29
...
6 changes to exploits/shellcodes/ghdb
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
CodeCanyon RISE CRM 3.7.0 - SQL Injection
Litespeed Cache 6.5.0.1 - Authentication Bypass
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
2025-03-29 00:16:38 +00:00
Exploit-DB
15b516383f
DB: 2025-03-28
...
4 changes to exploits/shellcodes/ghdb
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
MoziloCMS 3.0 - Remote Code Execution (RCE)
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
2025-03-28 00:16:32 +00:00
Exploit-DB
04fa5ba95d
DB: 2025-03-20
...
6 changes to exploits/shellcodes/ghdb
Gitea 1.24.0 - HTML Injection
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
Loaded Commerce 6.6 - Client-Side Template Injection(CSTI)
TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)
VeeVPN 1.6.1 - Unquoted Service Path
2025-03-20 00:16:32 +00:00
Exploit-DB
b86fb6e1b7
DB: 2024-10-02
...
4 changes to exploits/shellcodes/ghdb
dizqueTV 1.5.3 - Remote Code Execution (RCE)
reNgine 2.2.0 - Command Injection (Authenticated)
openSIS 9.1 - SQLi (Authenticated)
2024-10-02 00:16:50 +00:00
Exploit-DB
32e0cc5e7f
DB: 2024-08-29
...
5 changes to exploits/shellcodes/ghdb
Gitea 1.22.0 - Stored XSS
NoteMark < 0.13.0 - Stored XSS
Invesalius3 - Remote Code Execution
Windows TCP/IP - RCE Checker and Denial of Service
2024-08-29 00:16:41 +00:00
Exploit-DB
809d81619e
DB: 2024-08-24
...
4 changes to exploits/shellcodes/ghdb
Calibre-web 0.6.21 - Stored XSS
Helpdeskz v2.0.2 - Stored XSS
2024-08-24 00:16:35 +00:00
Exploit-DB
507bd26e3e
DB: 2024-08-05
...
6 changes to exploits/shellcodes/ghdb
Ivanti vADC 9.9 - Authentication Bypass
Devika v1 - Path Traversal via 'snapshot_path'
Genexus Protection Server 9.7.2.10 - 'protsrvservice' Unquoted Service Path
Oracle Database 12c Release 1 - Unquoted Service Path
SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
2024-08-05 00:16:24 +00:00
Exploit-DB
859e322e5c
DB: 2024-07-03
...
13 changes to exploits/shellcodes/ghdb
ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) & SSH Access
Zyxel IKE Packet Decoder - Unauthenticated Remote Code Execution (Metasploit)
Rebar3 3.13.2 - Command Injection
Craft CMS Logs Plugin 3.0.3 - Path Traversal (Authenticated)
ZwiiCMS 12.2.04 - Remote Code Execution (Authenticated)
Wipro Holmes Orchestrator 20.4.1 - Log File Disclosure
2024-07-03 00:16:27 +00:00
Exploit-DB
2680e71d44
DB: 2024-06-27
...
5 changes to exploits/shellcodes/ghdb
SolarWinds Platform 2024.1 SR1 - Race Condition
Automad 2.0.0-alpha.4 - Stored Cross-Site Scripting (XSS)
Flatboard 3.2 - Stored Cross-Site Scripting (XSS) (Authenticated)
Poultry Farm Management System v1.0 - Remote Code Execution (RCE)
2024-06-27 00:16:25 +00:00
Exploit-DB
1064b5c455
DB: 2024-06-15
...
12 changes to exploits/shellcodes/ghdb
Zyxel IKE Packet Decoder - Unauthenticated Remote Code Execution (Metasploit)
Rebar3 3.13.2 - Command Injection
AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability.
AEGON LIFE v1.0 Life Insurance Management System - Stored cross-site scripting (XSS)
AEGON LIFE v1.0 Life Insurance Management System - Unauthenticated Remote Code Execution (RCE)
Boelter Blue System Management 1.3 - SQL Injection
Carbon Forum 5.9.0 - Stored XSS
PHP < 8.3.8 - Remote Code Execution (Unauthenticated) (Windows)
WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS) (Authenticated)
XMB 1.9.12.06 - Stored XSS
ZwiiCMS 12.2.04 - Remote Code Execution (Authenticated)
2024-06-15 00:16:21 +00:00
Exploit-DB
8a32e340d5
DB: 2024-06-04
...
8 changes to exploits/shellcodes/ghdb
Sitefinity 15.0 - Cross-Site Scripting (XSS)
appRain CMF 4.0.5 - Remote Code Execution (RCE) (Authenticated)
CMSimple 5.15 - Remote Code Execution (RCE) (Authenticated)
Dotclear 2.29 - Remote Code Execution (RCE)
Monstra CMS 3.0.4 - Remote Code Execution (RCE)
Serendipity 2.5.0 - Remote Code Execution (RCE)
WBCE CMS v1.6.2 - Remote Code Execution (RCE)
2024-06-04 00:16:25 +00:00
Exploit-DB
3ac07794c9
DB: 2024-06-01
...
7 changes to exploits/shellcodes/ghdb
Aquatronica Control System 5.1.6 - Information Disclosure
Check Point Security Gateway - Information Disclosure (Unauthenticated)
changedetection < 0.45.20 - Remote Code Execution (RCE)
BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL Injection
ElkArte Forum 1.1.9 - Remote Code Execution (RCE) (Authenticated)
iMLog < 1.307 - Persistent Cross Site Scripting (XSS)
2024-06-01 00:16:48 +00:00
Exploit-DB
edacab1df2
DB: 2024-05-09
...
3 changes to exploits/shellcodes/ghdb
iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS)
Clinic Queuing System 1.0 - RCE
2024-05-09 00:16:23 +00:00
Exploit-DB
e791587e41
DB: 2024-03-29
...
10 changes to exploits/shellcodes/ghdb
RouterOS 6.40.5 - 6.44 and 6.48.1 - 6.49.10 - Denial of Service
Siklu MultiHaul TG series < 2.0.0 - unauthenticated credential disclosure
Dell Security Management Server <1.9.0 - Local Privilege Escalation
Asterisk AMI - Partial File Content & Path Disclosure (Authenticated)
Broken Access Control - on NodeBB v3.6.7
liveSite Version 2019.1 - Remote Code Execution
Purei CMS 1.0 - SQL Injection
Workout Journal App 1.0 - Stored XSS
WinRAR version 6.22 - Remote Code Execution via ZIP archive
2024-03-29 00:16:30 +00:00
Exploit-DB
c9576b1787
DB: 2024-03-26
...
11 changes to exploits/shellcodes/ghdb
LBT-T300-mini1 - Remote Buffer Overflow
Nagios XI Version 2024R1.01 - SQL Injection
Craft CMS 4.4.14 - Unauthenticated Remote Code Execution
Insurance Management System PHP and MySQL 1.0 - Multiple Stored XSS
LimeSurvey Community 5.3.32 - Stored XSS
MobileShop master v1.0 - SQL Injection Vuln.
SPA-CART CMS - Stored XSS
Tourism Management System v2.0 - Arbitrary File Upload
Wallos < 1.11.2 - File Upload RCE
2024-03-26 00:16:32 +00:00
Exploit-DB
bbffa273d4
DB: 2024-03-19
...
13 changes to exploits/shellcodes/ghdb
TELSAT marKoni FM Transmitter 1.9.5 - Backdoor Account Information Disclosure
TELSAT marKoni FM Transmitter 1.9.5 - Insecure Access Control Change Password
TELSAT marKoni FM Transmitter 1.9.5 - Root Command Injection
Atlassian Confluence < 8.5.3 - Remote Code Execution
Backdrop CMS 1.23.0 - Stored XSS
Gibbon LMS < v26.0.00 - Authenticated RCE
Quick.CMS 6.7 - SQL Injection Login Bypass
TYPO3 11.5.24 - Path Traversal (Authenticated)
WEBIGniter v28.7.23 - Stored XSS
WordPress File Upload Plugin < 4.23.3 - Stored XSS
xbtitFM 4.1.18 - Multiple Vulnerabilities
ZoneMinder Snapshots < 1.37.33 - Unauthenticated RCE
2024-03-19 00:16:26 +00:00
Exploit-DB
98f7ce18e2
DB: 2024-03-13
...
8 changes to exploits/shellcodes/ghdb
Cisco Firepower Management Center < 6.6.7.1 - Authenticated RCE
VMware Cloud Director 10.5 - Bypass identity verification
OSGi v3.7.2 (and below) Console - RCE
OSGi v3.8-3.18 Console - RCE
SnipeIT 6.2.1 - Stored Cross Site Scripting
Client Details System 1.0 - SQL Injection
Human Resource Management System 1.0 - 'employeeid' SQL Injection
2024-03-13 00:16:28 +00:00
Exploit-DB
ce58678266
DB: 2024-03-12
...
7 changes to exploits/shellcodes/ghdb
Sitecore - Remote Code Execution v8.2
Hitachi NAS (HNAS) System Management Unit (SMU) Backup & Restore < 14.8.7825.01 - IDOR
Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read
WordPress Plugin Duplicator < 1.5.7.1 - Unauthenticated Sensitive Data Exposure to Account Takeover
Microsoft Windows Defender / Trojan.Win32/Powessere.G - Detection Mitigation Bypass
2024-03-12 00:16:25 +00:00
Exploit-DB
7ef8e488d8
DB: 2024-03-04
...
22 changes to exploits/shellcodes/ghdb
GL.iNet AR300M v3.216 Remote Code Execution - CVE-2023-46456 Exploit
GL.iNet AR300M v4.3.7 Arbitrary File Read - CVE-2023-46455 Exploit
GL.iNet AR300M v4.3.7 Remote Code Execution - CVE-2023-46454 Exploit
Maxima Max Pro Power - BLE Traffic Replay (Unauthenticated)
R Radio Network FM Transmitter 1.07 system.cgi - Password Disclosure
TitanNit Web Control 2.01 / Atemio 7600 - Root Remote Code Execution
TPC-110W - Missing Authentication for Critical Function
A-PDF All to MP3 Converter 2.0.0 - DEP Bypass via HeapCreate + HeapAlloc
Easywall 0.3.1 - Authenticated Remote Command Execution
Magento ver. 2.4.6 - XSLT Server Side Injection
AC Repair and Services System v1.0 - Multiple SQL Injection
Enrollment System v1.0 - SQL Injection
Petrol Pump Management Software v.1.0 - SQL Injection
Petrol Pump Management Software v.1.0 - Stored Cross Site Scripting via SVG file
Petrol Pump Management Software v1.0 - 'Address' Stored Cross Site Scripting
Petrol Pump Management Software v1.0 - Remote Code Execution via File Upload
Real Estate Management System v1.0 - Remote Code Execution via File Upload
Simple Student Attendance System v1.0 - 'classid' Time Based Blind & Union Based SQL Injection
Simple Student Attendance System v1.0 - Time Based Blind SQL Injection
Boss Mini 1.4.0 - local file inclusion
Windows PowerShell - Event Log Bypass Single Quote Code Execution
2024-03-04 00:16:34 +00:00
Exploit-DB
c1bcfc6347
DB: 2024-02-28
...
13 changes to exploits/shellcodes/ghdb
TEM Opera Plus FM Family Transmitter 35.45 - Remote Code Execution
TEM Opera Plus FM Family Transmitter 35.45 - XSRF
Executables Created with perl2exe < V30.10C - Arbitrary Code Execution
Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)
Automatic-Systems SOC FL9600 FastLine - Directory Transversal
Automatic-Systems SOC FL9600 FastLine - The device contains hardcoded login and password for super admin
dawa-pharma 1.0-2022 - Multiple-SQLi
Moodle 4.3 - Insecure Direct Object Reference
Moodle 4.3 - Reflected XSS
SuperStoreFinder - Multiple Vulnerabilities
Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)
Zoo Management System 1.0 - Unauthenticated RCE
2024-02-28 00:16:32 +00:00
Exploit-DB
ba28fce174
DB: 2024-02-20
...
9 changes to exploits/shellcodes/ghdb
SureMDM On-premise < 6.31 - CAPTCHA Bypass User Enumeration
Wondercms 4.3.2 - XSS to RCE
Employee Management System v1 - 'email' SQL Injection
JFrog Artifactory < 7.25.4 - Blind SQL Injection
phpFox < 4.8.13 - (redirect) PHP Object Injection Exploit
XAMPP - Buffer Overflow POC
Microsoft Windows Defender - VBScript Detection Bypass
Microsoft Windows Defender Bypass - Detection Mitigation Bypass
2024-02-20 00:16:25 +00:00
Exploit-DB
bdcc81a451
DB: 2024-02-16
...
4 changes to exploits/shellcodes/ghdb
DS Wireless Communication - Remote Code Execution
Metabase 0.46.6 - Pre-Auth Remote Code Execution
SISQUALWFM 7.1.319.103 - Host Header Injection
2024-02-16 00:16:25 +00:00
Exploit-DB
5c0c152cec
DB: 2024-02-14
...
6 changes to exploits/shellcodes/ghdb
VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service
Splunk 9.0.4 - Information Disclosure
Lost and Found Information System v1.0 - ( IDOR ) leads to Account Take over
ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
2024-02-14 00:16:18 +00:00
Exploit-DB
0c65b881ba
DB: 2024-02-06
...
10 changes to exploits/shellcodes/ghdb
Milesight Routers UR5X_ UR32L_ UR32_ UR35_ UR41 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption
WhatsUp Gold 2022 (22.1.0 Build 39) - XSS
Clinic's Patient Management System 1.0 - Unauthenticated RCE
Curfew e-Pass Management System 1.0 - FromDate SQL Injection
GYM MS - GYM Management System - Cross Site Scripting (Stored)
MISP 2.4.171 - Stored XSS
TASKHUB-2.8.8 - XSS-Reflected
Wordpress 'simple urls' Plugin < 115 - XSS
2024-02-06 00:16:29 +00:00
Exploit-DB
2aed99237c
DB: 2024-02-01
...
8 changes to exploits/shellcodes/ghdb
Proxmox VE - TOTP Brute Force
RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC
GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
101 News 1.0 - Multiple-SQLi
Academy LMS 6.2 - Reflected XSS
Academy LMS 6.2 - SQL Injection
Grocy <=4.0.2 - CSRF
2024-02-01 00:16:32 +00:00
Exploit-DB
f3649a641f
DB: 2023-10-10
...
24 changes to exploits/shellcodes/ghdb
Minio 2022-07-29T19-40-48Z - Path traversal
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service
Atcom 2.7.x.x - Authenticated Command Injection
Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction
OpenPLC WebServer 3 - Denial of Service
Splunk 9.0.5 - admin account take over
BoidCMS v2.0.0 - authenticated file upload vulnerability
Cacti 1.2.24 - Authenticated command injection when using SNMP options
Chitor-CMS v1.1.2 - Pre-Auth SQL Injection
Clcknshop 1.0.0 - SQL Injection
Coppermine Gallery 1.6.25 - RCE
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
GLPI GZIP(Py3) 9.4.5 - RCE
Limo Booking Software v1.0 - CORS
Media Library Assistant Wordpress Plugin - RCE and LFI
Online ID Generator 1.0 - Remote Code Execution (RCE)
Shuttle-Booking-Software v1.0 - Multiple-SQLi
Webedition CMS v2.9.8.8 - Blind SSRF
WEBIGniter v28.7.23 File Upload - Remote Code Execution
Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
Wordpress Sonaar Music Plugin 4.7 - Stored XSS
Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)
2023-10-10 00:16:32 +00:00
Exploit-DB
cbe784b087
DB: 2023-09-09
...
16 changes to exploits/shellcodes/ghdb
Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
Drupal 10.1.2 - web-cache-poisoning-External-service-interaction
Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
soosyze 2.0.0 - File Upload
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
Wp2Fac - OS Command Injection
Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
SyncBreeze 15.2.24 - 'login' Denial of Service
GOM Player 2.3.90.5360 - Buffer Overflow (PoC)
GOM Player 2.3.90.5360 - Remote Code Execution (RCE)
Windows/x64 - PIC Null-Free TCP Reverse Shell Shellcode (476 Bytes)
2023-09-09 00:16:33 +00:00
Exploit-DB
4e246a01fb
DB: 2023-09-05
...
18 changes to exploits/shellcodes/ghdb
DLINK DPH-400SE - Exposure of Sensitive Information
FileMage Gateway 1.10.9 - Local File Inclusion
Academy LMS 6.1 - Arbitrary File Upload
AdminLTE PiHole 5.18 - Broken Access Control
Blood Donor Management System v1.0 - Stored XSS
Bus Reservation System 1.1 - Multiple-SQLi
Credit Lite 1.5.4 - SQL Injection
CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')
Hyip Rio 2.1 - Arbitrary File Upload
Member Login Script 3.3 - Client-side desync
SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)
Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow
Kingo ROOT 1.5.8 - Unquoted Service Path
NVClient v5.0 - Stack Buffer Overflow (DoS)
Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
2023-09-05 00:16:27 +00:00
Exploit-DB
69f3ee7722
DB: 2023-08-09
...
8 changes to exploits/shellcodes/ghdb
Lucee 5.4.2.17 - Authenticated Reflected XSS
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
Emagic Data Center Management Suite v6.0 - OS Command Injection
mooSocial 3.1.8 - Reflected XSS
PHPJabbers Vacation Rental Script 4.0 - CSRF
Social-Commerce 3.1.6 - Reflected XSS
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
2023-08-09 00:16:24 +00:00
Exploit-DB
010e679abe
DB: 2023-08-05
...
25 changes to exploits/shellcodes/ghdb
ReyeeOS 1.204.1614 - MITM Remote Code Execution (RCE)
Shelly PRO 4PM v0.11.0 - Authentication Bypass
Ozeki SMS Gateway 10.3.208 - Arbitrary File Read (Unauthenticated)
Academy LMS 6.0 - Reflected XSS
Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting
Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
JLex GuestBook 1.6.4 - Reflected XSS
Joomla JLex Review 6.0.1 - Reflected XSS
News Portal v4.0 - SQL Injection (Unauthorized)
PHPJabbers Cleaning Business 1.0 - Reflected XSS
PHPJabbers Night Club Booking 1.0 - Reflected XSS
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
PHPJabbers Service Booking Script 1.0 - Reflected XSS
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
PHPJabbers Taxi Booking 2.0 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
Webutler v3.2 - Remote Code Execution (RCE)
WordPress adivaha Travel Plugin 2.3 - Reflected XSS
WordPress adivaha Travel Plugin 2.3 - SQL Injection
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
WordPress Plugin Forminator 1.24.6 - Unauthenticated Remote Command Execution
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
Xlight FTP Server 3.9.3.6 - 'Stack Buffer Overflow' (DOS)
2023-08-05 00:16:32 +00:00
Exploit-DB
98cdb05106
DB: 2023-07-21
...
10 changes to exploits/shellcodes/ghdb
Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.
RWS WorldServer 11.7.3 - Session Token Enumeration
Aures Booking & POS Terminal - Local Privilege Escalation
Boom CMS v8.0.7 - Cross Site Scripting
PaulPrinting CMS - Multiple Cross Site Web Vulnerabilities
pfSense v2.7.0 - OS Command Injection
Webile v1.0.1 - Multiple Cross Site Scripting
Wifi Soft Unibox Administration 3.0 & 3.1 - SQL Injection
RaidenFTPD 2.4.4005 - Buffer Overflow (SEH)
2023-07-21 00:16:29 +00:00
Exploit-DB
ef9b4e5962
DB: 2023-07-04
...
20 changes to exploits/shellcodes/ghdb
TP-Link TL-WR940N V4 - Buffer OverFlow
D-Link DAP-1325 - Broken Access Control
Alkacon OpenCMS 15.0 - Multiple Cross-Site Scripting (XSS)
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
FuguHub 8.1 - Remote Code Execution
GZ Forum Script 1.8 - Stored Cross-Site Scripting (XSS)
PodcastGenerator 3.2.9 - Blind SSRF via XML Injection
POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
Prestashop 8.0.4 - Cross-Site Scripting (XSS)
Rukovoditel 3.4.1 - Multiple Stored XSS
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
spip v4.1.10 - Spoofing Admin account
Time Slot Booking Calendar 1.8 - Stored Cross-Site Scripting (XSS)
Vacation Rental 1.8 - Stored Cross-Site Scripting (XSS)
WBCE CMS 1.6.1 - Open Redirect & CSRF
WebsiteBaker v2.13.3 - Directory Traversal
WebsiteBaker v2.13.3 - Stored XSS
WP AutoComplete 1.0.4 - Unauthenticated SQLi
2023-07-04 00:16:26 +00:00
Exploit-DB
7807e6f266
DB: 2023-06-27
...
7 changes to exploits/shellcodes/ghdb
Azure Apache Ambari 2302250400 - Spoofing
Microsoft SharePoint Enterprise Server 2016 - Spoofing
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
Xenforo Version 2.2.13 - Authenticated Stored XSS
Windows 11 22h2 - Kernel Privilege Elevation
2023-06-27 00:17:09 +00:00