Exploit-DB
a99f08beda
DB: 2024-06-08
...
2 changes to exploits/shellcodes/ghdb
Backdrop CMS 1.27.1 - Remote Command Execution (RCE)
Backdrop CMS 1.27.1 - Authenticated Remote Command Execution (RCE)
2024-06-08 00:16:25 +00:00
Exploit-DB
8a32e340d5
DB: 2024-06-04
...
8 changes to exploits/shellcodes/ghdb
Sitefinity 15.0 - Cross-Site Scripting (XSS)
appRain CMF 4.0.5 - Remote Code Execution (RCE) (Authenticated)
CMSimple 5.15 - Remote Code Execution (RCE) (Authenticated)
Dotclear 2.29 - Remote Code Execution (RCE)
Monstra CMS 3.0.4 - Remote Code Execution (RCE)
Serendipity 2.5.0 - Remote Code Execution (RCE)
WBCE CMS v1.6.2 - Remote Code Execution (RCE)
2024-06-04 00:16:25 +00:00
Exploit-DB
ea4df5672e
DB: 2024-06-02
...
6 changes to exploits/shellcodes/ghdb
ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) & SSH Access
Akaunting 3.1.8 - Server-Side Template Injection (SSTI)
Craft CMS Logs Plugin 3.0.3 - Path Traversal (Authenticated)
FreePBX 16 - Remote Code Execution (RCE) (Authenticated)
Wipro Holmes Orchestrator 20.4.1 - Log File Disclosure
2024-06-02 00:16:32 +00:00
Exploit-DB
3ac07794c9
DB: 2024-06-01
...
7 changes to exploits/shellcodes/ghdb
Aquatronica Control System 5.1.6 - Information Disclosure
Check Point Security Gateway - Information Disclosure (Unauthenticated)
changedetection < 0.45.20 - Remote Code Execution (RCE)
BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL Injection
ElkArte Forum 1.1.9 - Remote Code Execution (RCE) (Authenticated)
iMLog < 1.307 - Persistent Cross Site Scripting (XSS)
2024-06-01 00:16:48 +00:00
Exploit-DB
094f6f9304
DB: 2024-05-20
...
7 changes to exploits/shellcodes/ghdb
Apache OFBiz 18.12.12 - Directory Traversal
Backdrop CMS 1.27.1 - Remote Command Execution (RCE)
htmlLawed 1.2.5 - Remote Code Execution (RCE)
PopojiCMS 2.0.1 - Remote Command Execution (RCE)
Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
Wordpress Theme XStore 9.3.8 - SQLi
2024-05-20 00:16:24 +00:00
Exploit-DB
323c36e831
DB: 2024-05-16
...
2 changes to exploits/shellcodes/ghdb
Gibbon LMS < v26.0.00 - Authenticated RCE
2024-05-16 00:16:39 +00:00
Exploit-DB
9d17a3d6ca
DB: 2024-05-14
...
10 changes to exploits/shellcodes/ghdb
CrushFTP < 11.1.0 - Directory Traversal
Apache mod_proxy_cluster - Stored XSS
CE Phoenix Version 1.0.8.20 - Stored XSS
Chyrp 2.5.2 - Stored Cross-Site Scripting (XSS)
Leafpub 1.1.9 - Stored Cross-Site Scripting (XSS)
Prison Management System - SQL Injection Authentication Bypass
PyroCMS v3.0.1 - Stored XSS
Plantronics Hub 3.25.1 - Arbitrary File Read
2024-05-14 00:16:26 +00:00
Exploit-DB
edacab1df2
DB: 2024-05-09
...
3 changes to exploits/shellcodes/ghdb
iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS)
Clinic Queuing System 1.0 - RCE
2024-05-09 00:16:23 +00:00
Exploit-DB
b8a68091fe
DB: 2024-05-05
...
7 changes to exploits/shellcodes/ghdb
Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 - Authentication Bypass
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link - Authentication Bypass
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link - Device Config Disclosure
Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 - Authentication Bypass
Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 - Device Config Disclosure
Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 - Device Config Disclosure
2024-05-05 00:16:37 +00:00
Exploit-DB
9eb5c7b425
DB: 2024-04-22
...
7 changes to exploits/shellcodes/ghdb
Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation
FlatPress v1.3 - Remote Command Execution
Laravel Framework 11 - Credential Leakage
SofaWiki 3.9.2 - Remote Command Execution (RCE) (Authenticated)
Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution
Flowise 1.6.5 - Authentication Bypass
2024-04-22 00:16:25 +00:00
Exploit-DB
27ecd9e84b
DB: 2024-04-16
...
5 changes to exploits/shellcodes/ghdb
Jenkins 2.441 - Local File Inclusion
OpenClinic GA 5.247.01 - Information Disclosure
OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
djangorestframework-simplejwt 5.3.1 - Information Disclosure
2024-04-16 00:16:46 +00:00
Exploit-DB
b59144d74e
DB: 2024-04-14
...
6 changes to exploits/shellcodes/ghdb
BMC Compuware iStrobe Web - 20.13 - Pre-auth RCE
Online Fire Reporting System OFRS - SQL Injection Authentication Bypass
Savsoft Quiz v6.0 Enterprise - Stored XSS
Stock Management System v1.0 - Unauthenticated SQL Injection
2024-04-14 00:16:33 +00:00
Exploit-DB
aa67db6cea
DB: 2024-04-13
...
15 changes to exploits/shellcodes/ghdb
MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
PrusaSlicer 2.6.1 - Arbitrary code execution
GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
HTMLy Version v2.9.6 - Stored XSS
Moodle 3.10.1 - Authenticated Blind Time-Based SQL Injection - _sort_ parameter
PopojiCMS Version 2.0.1 - Remote Command Execution
Quick CMS v6.7 en 2023 - 'password' SQLi
Service Provider Management System v1.0 - SQL Injection
WBCE 1.6.0 - Unauthenticated SQL injection
WBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)
Wordpress Plugin Playlist for Youtube 1.32 - Stored Cross-Site Scripting (XSS)
Wordpress Plugin WP Video Playlist 1.1.1 - Stored Cross-Site Scripting (XSS)
Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
Terratec dmx_6fire USB - Unquoted Service Path
2024-04-13 00:16:27 +00:00
Exploit-DB
034fafa3fd
DB: 2024-04-09
...
8 changes to exploits/shellcodes/ghdb
Positron Broadcast Signal Processor TRA7005 v1.20 - Authentication Bypass
Best Student Result Management System v1.0 - Multiple SQLi
Daily Expense Manager 1.0 - 'term' SQLi
Human Resource Management System v1.0 - Multiple SQLi
Open Source Medicine Ordering System v1.0 - SQLi
Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload
AnyDesk 7.0.15 - Unquoted Service Path
2024-04-09 00:16:23 +00:00
Exploit-DB
a06b0db78d
DB: 2024-04-04
...
6 changes to exploits/shellcodes/ghdb
Computer Laboratory Management System v1.0 - Multiple-SQLi
Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)
Quick CMS v6.7 en 2023 - 'password' SQLi
Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XSS)
ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path
2024-04-04 00:16:33 +00:00
Exploit-DB
a44e138f78
DB: 2024-04-03
...
28 changes to exploits/shellcodes/ghdb
Casdoor < v1.331.0 - '/api/set-password' CSRF
GL-iNet MT6000 4.5.5 - Arbitrary File Download
Axigen < 10.5.7 - Persistent Cross-Site Scripting
Blood Bank v1.0 - Stored Cross Site Scripting (XSS)
CE Phoenix v1.0.8.20 - Remote Code Execution
Daily Habit Tracker 1.0 - Broken Access Control
Daily Habit Tracker 1.0 - SQL Injection
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
E-INSUARANCE v1.0 - Stored Cross Site Scripting (XSS)
Elementor Website Builder < 3.12.2 - Admin+ SQLi
Employee Management System 1.0 - _txtfullname_ and _txtphone_ SQL Injection
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
FoF Pretty Mail 1.1.2 - Local File Inclusion (LFI)
FoF Pretty Mail 1.1.2 - Server Side Template Injection (SSTI)
Gibbon LMS v26.0.00 - SSTI vulnerability
Hospital Management System v1.0 - Stored Cross Site Scripting (XSS)
LeptonCMS 7.0.0 - Remote Code Execution (RCE) (Authenticated)
Online Hotel Booking In PHP 1.0 - Blind SQL Injection (Unauthenticated)
OpenCart Core 4.0.2.3 - 'search' SQLi
Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)
Simple Backup Plugin Python Exploit 2.7.10 - Path Traversal
Smart School 6.4.1 - SQL Injection
Wordpress Plugin - Membership For WooCommerce < v2.1.7 - Arbitrary File Upload to Shell (Unauthenticated)
ASUS Control Center Express 01.06.15 - Unquoted Service Path
Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation
Microsoft Windows Defender - Detection Mitigation Bypass TrojanWin32Powessere.G
Rapid7 nexpose - 'nexposeconsole' Unquoted Service Path
2024-04-03 00:16:27 +00:00
Exploit-DB
e791587e41
DB: 2024-03-29
...
10 changes to exploits/shellcodes/ghdb
RouterOS 6.40.5 - 6.44 and 6.48.1 - 6.49.10 - Denial of Service
Siklu MultiHaul TG series < 2.0.0 - unauthenticated credential disclosure
Dell Security Management Server <1.9.0 - Local Privilege Escalation
Asterisk AMI - Partial File Content & Path Disclosure (Authenticated)
Broken Access Control - on NodeBB v3.6.7
liveSite Version 2019.1 - Remote Code Execution
Purei CMS 1.0 - SQL Injection
Workout Journal App 1.0 - Stored XSS
WinRAR version 6.22 - Remote Code Execution via ZIP archive
2024-03-29 00:16:30 +00:00
Exploit-DB
c9576b1787
DB: 2024-03-26
...
11 changes to exploits/shellcodes/ghdb
LBT-T300-mini1 - Remote Buffer Overflow
Nagios XI Version 2024R1.01 - SQL Injection
Craft CMS 4.4.14 - Unauthenticated Remote Code Execution
Insurance Management System PHP and MySQL 1.0 - Multiple Stored XSS
LimeSurvey Community 5.3.32 - Stored XSS
MobileShop master v1.0 - SQL Injection Vuln.
SPA-CART CMS - Stored XSS
Tourism Management System v2.0 - Arbitrary File Upload
Wallos < 1.11.2 - File Upload RCE
2024-03-26 00:16:32 +00:00
Exploit-DB
26a991fc28
DB: 2024-03-23
...
2 changes to exploits/shellcodes/ghdb
minaliC 2.0.0 - Denied of Service
2024-03-23 00:16:33 +00:00
Exploit-DB
a24ba3c94b
DB: 2024-03-21
...
7 changes to exploits/shellcodes/ghdb
HNAS SMU 14.8.7825 - Information Disclosure
Blood Bank 1.0 - 'bid' SQLi
CSZCMS v1.3.0 - SQL Injection (Authenticated)
Employee Management System 1.0 - 'admin_id' SQLi
Simple Task List 1.0 - 'status' SQLi
Teacher Subject Allocation Management System 1.0 - 'searchdata' SQLi
2024-03-21 00:16:27 +00:00
Exploit-DB
bbffa273d4
DB: 2024-03-19
...
13 changes to exploits/shellcodes/ghdb
TELSAT marKoni FM Transmitter 1.9.5 - Backdoor Account Information Disclosure
TELSAT marKoni FM Transmitter 1.9.5 - Insecure Access Control Change Password
TELSAT marKoni FM Transmitter 1.9.5 - Root Command Injection
Atlassian Confluence < 8.5.3 - Remote Code Execution
Backdrop CMS 1.23.0 - Stored XSS
Gibbon LMS < v26.0.00 - Authenticated RCE
Quick.CMS 6.7 - SQL Injection Login Bypass
TYPO3 11.5.24 - Path Traversal (Authenticated)
WEBIGniter v28.7.23 - Stored XSS
WordPress File Upload Plugin < 4.23.3 - Stored XSS
xbtitFM 4.1.18 - Multiple Vulnerabilities
ZoneMinder Snapshots < 1.37.33 - Unauthenticated RCE
2024-03-19 00:16:26 +00:00
Exploit-DB
8c78d80c78
DB: 2024-03-17
...
7 changes to exploits/shellcodes/ghdb
Karaf v4.4.3 Console - RCE
Nokia BMC Log Scanner - Remote Code Execution
vm2 - sandbox escape
UPS Network Management Card 4 - Path Traversal
Winter CMS 1.2.3 - Server-Side Template Injection (SSTI) (Authenticated)
LaborOfficeFree 19.10 - MySQL Root Password Calculator
2024-03-17 00:16:40 +00:00
Exploit-DB
2af1700331
DB: 2024-03-15
...
10 changes to exploits/shellcodes/ghdb
Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
Ruijie Switch PSG-5124 26293 - Remote Code Execution (RCE)
SolarView Compact 6.00 - Command Injection
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
GitLab CE/EE < 16.7.2 - Password Reset
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
KiTTY 0.76.1.13 - Command Injection
2024-03-15 00:16:19 +00:00
Exploit-DB
98f7ce18e2
DB: 2024-03-13
...
8 changes to exploits/shellcodes/ghdb
Cisco Firepower Management Center < 6.6.7.1 - Authenticated RCE
VMware Cloud Director 10.5 - Bypass identity verification
OSGi v3.7.2 (and below) Console - RCE
OSGi v3.8-3.18 Console - RCE
SnipeIT 6.2.1 - Stored Cross Site Scripting
Client Details System 1.0 - SQL Injection
Human Resource Management System 1.0 - 'employeeid' SQL Injection
2024-03-13 00:16:28 +00:00
Exploit-DB
ce58678266
DB: 2024-03-12
...
7 changes to exploits/shellcodes/ghdb
Sitecore - Remote Code Execution v8.2
Hitachi NAS (HNAS) System Management Unit (SMU) Backup & Restore < 14.8.7825.01 - IDOR
Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read
WordPress Plugin Duplicator < 1.5.7.1 - Unauthenticated Sensitive Data Exposure to Account Takeover
Microsoft Windows Defender / Trojan.Win32/Powessere.G - Detection Mitigation Bypass
2024-03-12 00:16:25 +00:00
Exploit-DB
60a90afc8d
DB: 2024-03-11
...
7 changes to exploits/shellcodes/ghdb
Ladder v0.0.21 - Server-side request forgery (SSRF)
TP-Link TL-WR740N - Buffer Overflow 'DOS'
Numbas < v7.3 - Remote Code Execution
Akaunting < 3.1.3 - RCE
DataCube3 v1.0 - Unrestricted file upload 'RCE'
Hide My WP < 6.2.9 - Unauthenticated SQLi
2024-03-11 00:16:24 +00:00
Exploit-DB
7528fc1c5b
DB: 2024-03-07
...
8 changes to exploits/shellcodes/ghdb
GLiNet - Router Authentication Bypass
CSZ CMS Version 1.3.0 - Authenticated Remote Command Execution
CVE-2023-50071 - Multiple SQL Injection
elFinder Web file manager Version - 2.1.53 Remote Command Execution
Lot Reservation Management System - Unauthenticated File Disclosure
Lot Reservation Management System - Unauthenticated File Upload and Remote Code Execution
2024-03-07 00:16:27 +00:00
Exploit-DB
42e75482b6
DB: 2024-03-06
...
4 changes to exploits/shellcodes/ghdb
Solar-Log 200 PM+ 3.6.0 Build 99 - 15.10.2019 - Stored XSS
kk Star Ratings < 5.4.6 - Rating Tampering via Race Condition
Neontext Wordpress Plugin - Stored XSS
2024-03-06 00:16:30 +00:00
Exploit-DB
7ef8e488d8
DB: 2024-03-04
...
22 changes to exploits/shellcodes/ghdb
GL.iNet AR300M v3.216 Remote Code Execution - CVE-2023-46456 Exploit
GL.iNet AR300M v4.3.7 Arbitrary File Read - CVE-2023-46455 Exploit
GL.iNet AR300M v4.3.7 Remote Code Execution - CVE-2023-46454 Exploit
Maxima Max Pro Power - BLE Traffic Replay (Unauthenticated)
R Radio Network FM Transmitter 1.07 system.cgi - Password Disclosure
TitanNit Web Control 2.01 / Atemio 7600 - Root Remote Code Execution
TPC-110W - Missing Authentication for Critical Function
A-PDF All to MP3 Converter 2.0.0 - DEP Bypass via HeapCreate + HeapAlloc
Easywall 0.3.1 - Authenticated Remote Command Execution
Magento ver. 2.4.6 - XSLT Server Side Injection
AC Repair and Services System v1.0 - Multiple SQL Injection
Enrollment System v1.0 - SQL Injection
Petrol Pump Management Software v.1.0 - SQL Injection
Petrol Pump Management Software v.1.0 - Stored Cross Site Scripting via SVG file
Petrol Pump Management Software v1.0 - 'Address' Stored Cross Site Scripting
Petrol Pump Management Software v1.0 - Remote Code Execution via File Upload
Real Estate Management System v1.0 - Remote Code Execution via File Upload
Simple Student Attendance System v1.0 - 'classid' Time Based Blind & Union Based SQL Injection
Simple Student Attendance System v1.0 - Time Based Blind SQL Injection
Boss Mini 1.4.0 - local file inclusion
Windows PowerShell - Event Log Bypass Single Quote Code Execution
2024-03-04 00:16:34 +00:00
Exploit-DB
d0ee8ba723
DB: 2024-03-01
...
5 changes to exploits/shellcodes/ghdb
mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page
Wordpress 'simple urls' Plugin < 115 - XSS
2024-03-01 00:16:37 +00:00
Exploit-DB
59f10b7f45
DB: 2024-02-29
...
13 changes to exploits/shellcodes/ghdb
Saflok - Key Derication Function Exploit
(shellcode) Linux-x64 - create a shell with execve() sending argument using XOR (/bin//sh) [55 bytes]
Academy LMS 6.2 - Reflected XSS
Blood Bank v1.0 - Multiple SQL Injection
Moodle 4.3 - Reflected XSS
TASKHUB-2.8.8 - XSS-Reflected
WordPress Plugin Admin Bar & Dashboard Access Control Version: 1.2.8 - _Dashboard Redirect_ field Stored Cross-Site Scripting (XSS)
WP Fastest Cache 1.2.2 - Unauthenticated SQL Injection
WP Rocket < 2.10.3 - Local File Inclusion (LFI)
2024-02-29 00:16:26 +00:00
Exploit-DB
c1bcfc6347
DB: 2024-02-28
...
13 changes to exploits/shellcodes/ghdb
TEM Opera Plus FM Family Transmitter 35.45 - Remote Code Execution
TEM Opera Plus FM Family Transmitter 35.45 - XSRF
Executables Created with perl2exe < V30.10C - Arbitrary Code Execution
Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)
Automatic-Systems SOC FL9600 FastLine - Directory Transversal
Automatic-Systems SOC FL9600 FastLine - The device contains hardcoded login and password for super admin
dawa-pharma 1.0-2022 - Multiple-SQLi
Moodle 4.3 - Insecure Direct Object Reference
Moodle 4.3 - Reflected XSS
SuperStoreFinder - Multiple Vulnerabilities
Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)
Zoo Management System 1.0 - Unauthenticated RCE
2024-02-28 00:16:32 +00:00
Exploit-DB
9734fcef1e
DB: 2024-02-27
...
12 changes to exploits/shellcodes/ghdb
Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'DoS'
Wyrestorm Apollo VX20 < 1.3.58 - Account Enumeration
Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'Credentials Disclosure'
FAQ Management System v1.0 - 'faq' SQL Injection
Flashcard Quiz App v1.0 - 'card' SQL Injection
Simple Inventory Management System v1.0 - 'email' SQL Injection
comments-like-dislike < 1.2.0 - Authenticated (Subscriber+) Plugin Setting Reset
Online Shopping System Advanced - Sql Injection
taskhub 2.8.7 - SQL Injection
IBM i Access Client Solutions v1.1.2 - 1.1.4_ v1.1.4.3 - 1.1.9.4 - Remote Credential Theft
2024-02-27 00:16:33 +00:00
Exploit-DB
624b24bca9
DB: 2024-02-22
...
2 changes to exploits/shellcodes/ghdb
WEBIGniter v28.7.23 - Stored Cross Site Scripting (XSS)
2024-02-22 00:16:28 +00:00
Exploit-DB
ba28fce174
DB: 2024-02-20
...
9 changes to exploits/shellcodes/ghdb
SureMDM On-premise < 6.31 - CAPTCHA Bypass User Enumeration
Wondercms 4.3.2 - XSS to RCE
Employee Management System v1 - 'email' SQL Injection
JFrog Artifactory < 7.25.4 - Blind SQL Injection
phpFox < 4.8.13 - (redirect) PHP Object Injection Exploit
XAMPP - Buffer Overflow POC
Microsoft Windows Defender - VBScript Detection Bypass
Microsoft Windows Defender Bypass - Detection Mitigation Bypass
2024-02-20 00:16:25 +00:00
Exploit-DB
bdcc81a451
DB: 2024-02-16
...
4 changes to exploits/shellcodes/ghdb
DS Wireless Communication - Remote Code Execution
Metabase 0.46.6 - Pre-Auth Remote Code Execution
SISQUALWFM 7.1.319.103 - Host Header Injection
2024-02-16 00:16:25 +00:00
Exploit-DB
5c0c152cec
DB: 2024-02-14
...
6 changes to exploits/shellcodes/ghdb
VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service
Splunk 9.0.4 - Information Disclosure
Lost and Found Information System v1.0 - ( IDOR ) leads to Account Take over
ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
2024-02-14 00:16:18 +00:00
Exploit-DB
a846c2fd3a
DB: 2024-02-10
...
8 changes to exploits/shellcodes/ghdb
Zyxel zysh - Format string
Elasticsearch - StackOverflow DoS
Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)
Online Nurse Hiring System 1.0 - Time-Based SQL Injection
Rail Pass Management System 1.0 - Time-Based SQL Injection
Wordpress Augmented-Reality - Remote Code Execution Unauthenticated
Wordpress Seotheme - Remote Code Execution Unauthenticated
2024-02-10 00:16:32 +00:00
Exploit-DB
0c65b881ba
DB: 2024-02-06
...
10 changes to exploits/shellcodes/ghdb
Milesight Routers UR5X_ UR32L_ UR32_ UR35_ UR41 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption
WhatsUp Gold 2022 (22.1.0 Build 39) - XSS
Clinic's Patient Management System 1.0 - Unauthenticated RCE
Curfew e-Pass Management System 1.0 - FromDate SQL Injection
GYM MS - GYM Management System - Cross Site Scripting (Stored)
MISP 2.4.171 - Stored XSS
TASKHUB-2.8.8 - XSS-Reflected
Wordpress 'simple urls' Plugin < 115 - XSS
2024-02-06 00:16:29 +00:00
Exploit-DB
81ae91fdae
DB: 2024-02-03
...
14 changes to exploits/shellcodes/ghdb
Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution
Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal
TP-LINK TL-WR740N - Multiple HTML Injection
TP-Link TL-WR740N - UnAuthenticated Directory Transversal
Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)
mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page
PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow
WebCatalog 48.4 - Arbitrary Protocol Execution
2024-02-03 00:16:34 +00:00
Exploit-DB
2aed99237c
DB: 2024-02-01
...
8 changes to exploits/shellcodes/ghdb
Proxmox VE - TOTP Brute Force
RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC
GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
101 News 1.0 - Multiple-SQLi
Academy LMS 6.2 - Reflected XSS
Academy LMS 6.2 - SQL Injection
Grocy <=4.0.2 - CSRF
2024-02-01 00:16:32 +00:00
Exploit-DB
a5920da7af
DB: 2024-01-30
...
10 changes to exploits/shellcodes/ghdb
Ricoh Printer - Directory and File Exposure
Blood Bank & Donor Management System using v2.2 - Stored XSS
Equipment Rental Script-1.0 - SQLi
Bank Locker Management System - SQL Injection
Fundraising Script 1.0 - SQLi
PHP Shopping Cart 4.2 - Multiple-SQLi
7 Sticky Notes v1.9 - OS Command Injection
Typora v1.7.4 - OS Command Injection
2024-01-30 00:16:26 +00:00
Exploit-DB
75cbb282d9
DB: 2023-10-31
...
12 changes to exploits/shellcodes/ghdb
systemd 246 - Local Privilege Escalation
ChurchCRM v4.5.3 - Authenticated SQL Injection
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) via subprocess_execute
Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
Request-Baskets v1.2.1 - Server-side request forgery (SSRF)
2023-10-31 00:17:05 +00:00
Exploit-DB
f3649a641f
DB: 2023-10-10
...
24 changes to exploits/shellcodes/ghdb
Minio 2022-07-29T19-40-48Z - Path traversal
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service
Atcom 2.7.x.x - Authenticated Command Injection
Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction
OpenPLC WebServer 3 - Denial of Service
Splunk 9.0.5 - admin account take over
BoidCMS v2.0.0 - authenticated file upload vulnerability
Cacti 1.2.24 - Authenticated command injection when using SNMP options
Chitor-CMS v1.1.2 - Pre-Auth SQL Injection
Clcknshop 1.0.0 - SQL Injection
Coppermine Gallery 1.6.25 - RCE
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
GLPI GZIP(Py3) 9.4.5 - RCE
Limo Booking Software v1.0 - CORS
Media Library Assistant Wordpress Plugin - RCE and LFI
Online ID Generator 1.0 - Remote Code Execution (RCE)
Shuttle-Booking-Software v1.0 - Multiple-SQLi
Webedition CMS v2.9.8.8 - Blind SSRF
WEBIGniter v28.7.23 File Upload - Remote Code Execution
Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
Wordpress Sonaar Music Plugin 4.7 - Stored XSS
Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)
2023-10-10 00:16:32 +00:00
Exploit-DB
cbe784b087
DB: 2023-09-09
...
16 changes to exploits/shellcodes/ghdb
Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
Drupal 10.1.2 - web-cache-poisoning-External-service-interaction
Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
soosyze 2.0.0 - File Upload
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
Wp2Fac - OS Command Injection
Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
SyncBreeze 15.2.24 - 'login' Denial of Service
GOM Player 2.3.90.5360 - Buffer Overflow (PoC)
GOM Player 2.3.90.5360 - Remote Code Execution (RCE)
Windows/x64 - PIC Null-Free TCP Reverse Shell Shellcode (476 Bytes)
2023-09-09 00:16:33 +00:00
Exploit-DB
4e246a01fb
DB: 2023-09-05
...
18 changes to exploits/shellcodes/ghdb
DLINK DPH-400SE - Exposure of Sensitive Information
FileMage Gateway 1.10.9 - Local File Inclusion
Academy LMS 6.1 - Arbitrary File Upload
AdminLTE PiHole 5.18 - Broken Access Control
Blood Donor Management System v1.0 - Stored XSS
Bus Reservation System 1.1 - Multiple-SQLi
Credit Lite 1.5.4 - SQL Injection
CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')
Hyip Rio 2.1 - Arbitrary File Upload
Member Login Script 3.3 - Client-side desync
SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
Webedition CMS v2.9.8.8 - Stored XSS
WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)
Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow
Kingo ROOT 1.5.8 - Unquoted Service Path
NVClient v5.0 - Stack Buffer Overflow (DoS)
Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
2023-09-05 00:16:27 +00:00
Exploit-DB
fe2c42ff0e
DB: 2023-08-25
...
4 changes to exploits/shellcodes/ghdb
User Registration & Login and User Management System v3.0 - SQL Injection (Unauthenticated)
User Registration & Login and User Management System v3.0 - Stored Cross-Site Scripting (XSS)
Uvdesk 1.1.4 - Stored XSS (Authenticated)
2023-08-25 00:16:28 +00:00
Exploit-DB
e07f33f24d
DB: 2023-08-22
...
17 changes to exploits/shellcodes/ghdb
EuroTel ETL3100 - Transmitter Authorization Bypass (IDOR)
EuroTel ETL3100 - Transmitter Default Credentials
EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download
Color Prediction Game v1.0 - SQL Injection
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
Dolibarr Version 17.0.1 - Stored XSS
Global - Multi School Management System Express v1.0- SQL Injection
OVOO Movie Portal CMS v3.3.3 - SQL Injection
PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities
Taskhub CRM Tool 2.8.6 - SQL Injection
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
TSplus 16.0.0.0 - Remote Work Insecure Files and Folders
TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions
Linux/x64 - memfd_create ELF loader Shellcode (170 bytes)
2023-08-22 00:16:22 +00:00
Exploit-DB
f55092b332
DB: 2023-08-11
...
6 changes to exploits/shellcodes/ghdb
TP-Link Archer AX21 - Unauthenticated Command Injection
systemd 246 - Local Privilege Escalation
Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
Request-Baskets v1.2.1 - Server-side request forgery (SSRF)
OutSystems Service Studio 11.53.30 - DLL Hijacking
2023-08-11 00:16:25 +00:00
Exploit-DB
69f3ee7722
DB: 2023-08-09
...
8 changes to exploits/shellcodes/ghdb
Lucee 5.4.2.17 - Authenticated Reflected XSS
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
Emagic Data Center Management Suite v6.0 - OS Command Injection
mooSocial 3.1.8 - Reflected XSS
PHPJabbers Vacation Rental Script 4.0 - CSRF
Social-Commerce 3.1.6 - Reflected XSS
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
2023-08-09 00:16:24 +00:00