Offensive Security
b84d953124
DB: 2020-03-24
...
10 changes to exploits/shellcodes
ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
CyberArk PSMP 10.9.1 - Policy Restriction Bypass
PHPMailer < 5.2.18 - Remote Code Execution (Bash)
FIBARO System Home Center 5.021 - Remote File Include
rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
Windows\x86 - Null-Free WinExec Calc.exe Shellcode (195 bytes)
Windows\x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
Windows/x86 - Null-Free WinExec Calc.exe Shellcode (195 bytes)
Windows/x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
Linux\x86 - 'reboot' polymorphic Shellcode (26 bytes)
2020-03-24 05:01:50 +00:00
Offensive Security
d3992973f1
DB: 2020-03-21
...
2 changes to exploits/shellcodes
VMware Fusion 11.5.2 - Privilege Escalation
Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
2020-03-21 05:01:49 +00:00
Offensive Security
26b38131c0
DB: 2020-03-20
...
1 changes to exploits/shellcodes
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
2020-03-20 05:01:50 +00:00
Offensive Security
85cdf30cea
DB: 2020-03-19
...
7 changes to exploits/shellcodes
NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
Microsoft VSCode Python Extension - Code Execution
VMWare Fusion - Local Privilege Escalation
Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
Netlink GPON Router 1.0.11 - Remote Code Execution
Windows\x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
2020-03-19 05:01:49 +00:00
Offensive Security
20e5ee2e94
DB: 2020-03-18
...
2 changes to exploits/shellcodes
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
ManageEngine Desktop Central - Java Deserialization (Metasploit)
2020-03-18 05:01:50 +00:00
Offensive Security
72f1d24f1a
DB: 2020-03-17
...
5 changes to exploits/shellcodes
Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
PHPKB Multi-Language 9 - Authenticated Remote Code Execution
PHPKB Multi-Language 9 - Authenticated Directory Traversal
PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
2020-03-17 05:01:49 +00:00
Offensive Security
9bacc6784a
DB: 2020-03-15
...
2 changes to exploits/shellcodes
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
2020-03-15 05:01:47 +00:00
Offensive Security
79fee2e601
DB: 2020-03-14
...
4 changes to exploits/shellcodes
AnyBurn 4.8 - Buffer Overflow (SEH)
Drobo 5N2 4.1.1 - Remote Command Injection
Centos WebPanel 7 - 'term' SQL Injection
2020-03-14 05:01:46 +00:00
Offensive Security
153c392dd9
DB: 2020-03-13
...
9 changes to exploits/shellcodes
ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
rConfig 3.9 - 'searchColumn' SQL Injection
Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
2020-03-13 05:01:50 +00:00
Offensive Security
3c74040d79
DB: 2020-03-12
...
2 changes to exploits/shellcodes
ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
Wordpress Plugin Search Meter 2.13.2 - CSV injection
2020-03-12 05:01:49 +00:00
Offensive Security
0a0ad49d15
DB: 2020-03-11
...
7 changes to exploits/shellcodes
Counter Strike: GO - '.bsp' Memory Control (PoC)
Nagios XI - Authenticated Remote Command Execution (Metasploit)
PHPStudy - Backdoor Remote Code execution (Metasploit)
Sysaid 20.1.11 b26 - Remote Command Execution
YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
Persian VIP Download Script 1.0 - 'active' SQL Injection
2020-03-11 05:01:47 +00:00
Offensive Security
4df22c7404
DB: 2020-03-10
...
13 changes to exploits/shellcodes
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
PHP-FPM - Underflow Remote Code Execution (Metasploit)
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
Google Chrome 67_ 68 and 69 - Object.create Type Confusion (Metasploit)
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
ManageEngine ServiceDesk Plus 9.3 - User Enumeration
60CycleCMS - 'news.php' SQL Injection
Sahi pro 8.x - Directory Traversal
Sentrifugo HRMS 3.2 - 'id' SQL Injection
2020-03-10 05:01:44 +00:00
Offensive Security
04881134cd
DB: 2020-03-07
...
5 changes to exploits/shellcodes
Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Service Path
SpyHunter 4 - 'SpyHunter 4 Service' Unquoted Service Path
ASUS GiftBox Desktop 1.1.1.127 - 'ASUSGiftBoxDesktop' Unquoted Service Path
Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Path
ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization / Unauthenticated Remote Code Execution
2020-03-07 05:01:49 +00:00
Offensive Security
7531fa6a21
DB: 2020-03-06
...
3 changes to exploits/shellcodes
Exchange Control Panel - Viewstate Deserialization (Metasploit)
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
netkit-telnet-0.17 telnetd (Fedora 31) - 'BraveStarr' Remote Code Execution
2020-03-06 05:01:47 +00:00
Offensive Security
fce46f25ae
DB: 2020-03-05
...
1 changes to exploits/shellcodes
UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
2020-03-05 05:01:47 +00:00
Offensive Security
d85ad29bbc
DB: 2020-03-04
...
4 changes to exploits/shellcodes
RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
Alfresco 5.2.4 - Persistent Cross-Site Scripting
GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
2020-03-04 05:01:50 +00:00
Offensive Security
afe5797b88
DB: 2020-03-03
...
12 changes to exploits/shellcodes
Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
Wing FTP Server 6.2.3 - Privilege Escalation
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
Joplin Desktop 1.0.184 - Cross-Site Scripting
Netis WF2419 2.2.36123 - Remote Code Execution
Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
Wing FTP Server 6.2.5 - Privilege Escalation
TP LINK TL-WR849N - Remote Code Execution
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
2020-03-03 05:01:48 +00:00
Offensive Security
016ad02a70
DB: 2020-02-29
...
1 changes to exploits/shellcodes
qdPM < 9.1 - Remote Code Execution
2020-02-29 05:01:46 +00:00
Offensive Security
02aee6c80e
DB: 2020-02-28
...
5 changes to exploits/shellcodes
Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
Comtrend VR-3033 - Command Injection
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
Cacti 1.2.8 - Authenticated Remote Code Execution
Cacti 1.2.8 - Unauthenticated Remote Code Execution
2020-02-28 05:01:52 +00:00
Offensive Security
2d45ff4f39
DB: 2020-02-27
...
5 changes to exploits/shellcodes
Core FTP LE 2.2 - Denial of Service (PoC)
OpenSMTPD 6.6.3 - Arbitrary File Read
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
PhpIX 2012 Professional - 'id' SQL Injection
2020-02-27 05:02:27 +00:00
Offensive Security
17bb415ff8
DB: 2020-02-26
...
5 changes to exploits/shellcodes
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
aSc TimeTables 2020.11.4 - Denial of Service (PoC)
Odin Secure FTP Expert 7.6.3 - Denial of Service (PoC)
WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
2020-02-26 05:01:51 +00:00
Offensive Security
cf92ea269e
DB: 2020-02-25
...
22 changes to exploits/shellcodes
Quick N Easy Web Server 3.3.8 - Denial of Service (PoC)
Go SSH servers 0.0.2 - Denial of Service (PoC)
Android Binder - Use-After-Free (Metasploit)
Diamorphine Rootkit - Signal Privilege Escalation (Metasploit)
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure
Real Web Pentesting Tutorial Step by Step - [Persian]
AMSS++ v 4.31 - 'id' SQL Injection
SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure
CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
AMSS++ 4.7 - Backdoor Admin Account
SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure
ATutor 2.2.4 - 'id' SQL Injection
I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
eLection 2.0 - 'id' SQL Injection
DotNetNuke 9.5 - Persistent Cross-Site Scripting
DotNetNuke 9.5 - File Upload Restrictions Bypass
Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
Cacti 1.2.8 - Remote Code Execution
Windows\x86 - Null-Free WinExec Calc.exe Shellcode (195 bytes)
2020-02-25 05:01:52 +00:00
Offensive Security
ed6caf0837
DB: 2020-02-21
...
2 changes to exploits/shellcodes
Core FTP Lite 1.3 - Denial of Service (PoC)
Easy2Pilot 7 - Cross-Site Request Forgery (Add User)
2020-02-21 05:01:53 +00:00
Offensive Security
16b45536b7
DB: 2020-02-20
...
5 changes to exploits/shellcodes
WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
Virtual Freer 1.58 - Remote Command Execution
DBPower C300 HD Camera - Remote Configuration Disclosure
Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
2020-02-20 05:01:53 +00:00
Offensive Security
e28fa0b839
DB: 2020-02-19
...
1 changes to exploits/shellcodes
WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
2020-02-19 05:01:54 +00:00
Offensive Security
228a37da9c
DB: 2020-02-18
...
15 changes to exploits/shellcodes
HP System Event 1.2.9.0 - 'HPWMISVC' Unquoted Service Path
BOOTP Turbo 2.0.1214 - 'BOOTP Turbo' Unquoted Service Path
MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation
DHCP Turbo 4.61298 - 'DHCP Turbo 4' Unquoted Service Path
TFTP Turbo 4.6.1273 - 'TFTP Turbo 4' Unquoted Service Path
Cuckoo Clock v5.0 - Buffer Overflow
Anviz CrossChex - Buffer Overflow (Metasploit)
SOPlanning 1.45 - 'by' SQL Injection
Wordpress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting
Avaya Aura Communication Manager 5.2 - Remote Code Execution
Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
SOPlanning 1.45 - Cross-Site Request Forgery (Add User)
SOPlanning 1.45 - 'users' SQL Injection
LabVantage 8.3 - Information Disclosure
2020-02-18 05:01:54 +00:00
Offensive Security
53517327e7
DB: 2020-02-15
...
21 changes to exploits/shellcodes
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / Disable Functions Bypass
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / Disable Functions Bypass
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
PHP 5.x COM - Safe Mode / Disable Functions Bypass
PHP 5.x COM - Safe Mode / disable_functions Bypass
PHP 5.2.3 imap (Debian Based) - 'imap_open' Disable Functions Bypass
PHP 5.2.3 imap (Debian Based) - 'imap_open' disable_functions Bypass
HomeGuard Pro 9.3.1 - Insecure Folder Permissions
EPSON EasyMP Network Projection 2.81 - 'EMP_NSWLSV' Unquoted Service Path
SprintWork 2.3.1 - Local Privilege Escalation
Windows Kernel - Information Disclosure
PHP 7.0 < 7.4 (Unix) - 'debug_backtrace' disable_functions Bypass
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
PHP < 5.6.2 - 'Shellshock' Safe Mode / Disable Functions Bypass / Command Injection
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
PHP 5.5.9 - 'zend_executor_globals' 'CGIMode FPM WriteProcMemFile' Disable Functions Bypass / Load Dynamic Library
PHP 5.5.9 - 'zend_executor_globals' 'CGIMode FPM WriteProcMemFile' disable_functions Bypass / Load Dynamic Library
Imagick 3.3.0 (PHP 5.4) - Disable Functions Bypass
Imagick 3.3.0 (PHP 5.4) - disable_functions Bypass
PHP 7.1 < 7.3 - 'json serializer' Disable Functions Bypass
PHP 7.1 < 7.3 - 'json serializer' disable_functions Bypass
PHP 7.0 < 7.3 (Unix) - 'gc' Disable Functions Bypass
PHP 7.0 < 7.3 (Unix) - 'gc' disable_functions Bypass
VehicleWorkshop 1.0 - 'bookingid' SQL Injection
Wordpress Plugin tutor.1.5.3 - Local File Inclusion
Wordpress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting
Wordpress Plugin wordfence.7.4.5 - Local File Disclosure
Wordpress Plugin contact-form-7 5.1.6 - Remote File Upload
phpMyChat Plus 1.98 - 'pmc_username' SQL Injection
WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion
2020-02-15 05:01:54 +00:00
Offensive Security
21abbd7054
DB: 2020-02-14
...
7 changes to exploits/shellcodes
OpenTFTP 1.66 - Local Privilege Escalation
Wordpress Plugin tutor.1.5.3 - Local File Inclusion
Wordpress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting
Wordpress Plugin wordfence.7.4.5 - Local File Disclosure
Wordpress Plugin contact-form-7 5.1.6 - Remote File Upload
PANDORAFMS 7.0 - Authenticated Remote Code Execution
WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion
2020-02-14 05:01:58 +00:00
Offensive Security
875c0a9396
DB: 2020-02-13
...
11 changes to exploits/shellcodes
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
SunOS 5.10 Generic_147148-26 - Local Privilege Escalation
MyVideoConverter Pro 3.14 - 'Movie' Buffer Overflow
MyVideoConverter Pro 3.14 - 'Output Folder' Buffer Overflow
MyVideoConverter Pro 3.14 - 'TVSeries' Buffer Overflow
HP System Event Utility - Local Privilege Escalation
2020-02-13 05:02:00 +00:00
Offensive Security
ea7a01d8fb
DB: 2020-02-12
...
18 changes to exploits/shellcodes
Sudo 1.8.25p - 'pwfeedback' Buffer Overflow (PoC)
Sudo 1.8.25p - Buffer Overflow
Torrent iPod Video Converter 1.51 - Stack Overflow
DVD Photo Slideshow Professional 8.07 - 'Key' Buffer Overflow
freeFTPd v1.0.13 - 'freeFTPdService' Unquoted Service Path
FreeSSHd 1.3.1 - 'FreeSSHDService' Unquoted Service Path
Sync Breeze Enterprise 12.4.18 - 'Sync Breeze Enterprise' Unquoted Service Path
DVD Photo Slideshow Professional 8.07 - 'Name' Buffer Overflow
Disk Sorter Enterprise 12.4.16 - 'Disk Sorter Enterprise' Unquoted Service Path
Disk Savvy Enterprise 12.3.18 - Unquoted Service Path
Wedding Slideshow Studio 1.36 - 'Name' Buffer Overflow
Sudo 1.8.25p - 'pwfeedback' Buffer Overflow
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
Microsoft SharePoint - Deserialization Remote Code Execution
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
WordPress InfiniteWP - Client Authentication Bypass (Metasploit)
2020-02-12 05:01:58 +00:00
Offensive Security
8cbf7883c1
DB: 2020-02-11
...
11 changes to exploits/shellcodes
Dota 2 7.23f - Denial of Service (PoC)
usersctp - Out-of-Bounds Reads in sctp_load_addresses_from_init
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
Wedding Slideshow Studio 1.36 - 'Key' Buffer Overflow
Ricoh Driver - Privilege Escalation (Metasploit)
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
LearnDash WordPress LMS Plugin 3.1.2 - Reflective Cross-Site Scripting
Linux/x86 - Bind Shell Generator Shellcode (114 bytes)
2020-02-11 05:02:02 +00:00
Offensive Security
54935a7883
DB: 2020-02-08
...
7 changes to exploits/shellcodes
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
QuickDate 1.3.2 - SQL Injection
VehicleWorkshop 1.0 - 'bookingid' SQL Injection
PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection
EyesOfNetwork 5.3 - Remote Code Execution
ExpertGPS 6.38 - XML External Entity Injection
Google Invisible RECAPTCHA 3 - Spoof Bypass
2020-02-08 05:01:59 +00:00
Offensive Security
923f53211e
DB: 2020-02-07
...
16 changes to exploits/shellcodes
AbsoluteTelnet 11.12 - _license name_ Denial of Service (PoC)
AbsoluteTelnet 11.12 - 'license name' Denial of Service (PoC)
VIM 8.2 - Denial of Service (PoC)
AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service (PoC)
TapinRadio 2.12.3 - 'address' Denial of Service (PoC)
TapinRadio 2.12.3 - 'username' Denial of Service (PoC)
RarmaRadio 2.72.4 - 'username' Denial of Service (PoC)
RarmaRadio 2.72.4 - 'server' Denial of Service (PoC)
ELAN Smart-Pad 11.10.15.1 - 'ETDService' Unquoted Service Path
Online Job Portal 1.0 - 'user_email' SQL Injection
Online Job Portal 1.0 - Remote Code Execution
Online Job Portal 1.0 - Cross Site Request Forgery (Add User)
Ecommerce Systempay 1.0 - Production KEY Brute Force
Cisco Data Center Network Manager 11.2 - Remote Code Execution
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
2020-02-07 05:02:01 +00:00
Offensive Security
7d757326b8
DB: 2020-02-06
...
8 changes to exploits/shellcodes
Socat 1.7.3.4 - Heap-Based Overflow (PoC)
xglance-bin 11.00 - Privilege Escalation
HiSilicon DVR/NVR hi3520d firmware - Remote Backdoor Account
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
Wago PFC200 - Authenticated Remote Code Execution (Metasploit)
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
2020-02-06 05:02:08 +00:00
Offensive Security
9a3ddbdd3a
DB: 2020-02-05
...
5 changes to exploits/shellcodes
Sudo 1.8.25p - Buffer Overflow
Centreon 19.10.5 - 'Pollers' Remote Command Execution (Metasploit)
F-Secure Internet Gatekeeper 5.40 - Heap Overflow (PoC)
2020-02-05 05:02:01 +00:00
Offensive Security
8683ee3eea
DB: 2020-02-04
...
8 changes to exploits/shellcodes
BearFTP 0.1.0 - 'PASV' Denial of Service
P2PWIFICAM2 for iOS 10.4.1 - 'Camera ID' Denial of Service (PoC)
Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
phpList 3.5.0 - Authentication Bypass
Jira 8.3.4 - Information Disclosure (Username Enumeration)
Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
2020-02-04 05:02:00 +00:00
Offensive Security
ab03a59682
DB: 2020-02-01
...
2 changes to exploits/shellcodes
Lotus Core CMS 1.0.1 - Local File Inclusion
FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)
2020-02-01 05:02:03 +00:00
Offensive Security
9f56865d3d
DB: 2020-01-31
...
3 changes to exploits/shellcodes
OpenSMTPD 6.6.2 - Remote Code Execution
rConfig 3.9.3 - Authenticated Remote Code Execution
Windows/x86 - Dynamic Bind Shell + Null-Free Shellcode (571 Bytes)
2020-01-31 05:02:01 +00:00
Offensive Security
3b5a0d91fe
DB: 2020-01-30
...
9 changes to exploits/shellcodes
XMLBlueprint 16.191112 - XML External Entity Injection
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
Kibana 6.6.1 - CSV Injection
Liferay CE Portal 6.0.2 - Remote Command Execution
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
Satellian 1.12 - Remote Code Execution
Centreon 19.10.5 - 'Pollers' Remote Command Execution
Centreon 19.10.5 - 'centreontrapd' Remote Command Execution
Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
2020-01-30 05:02:05 +00:00
Offensive Security
0cd38b15b8
DB: 2020-01-29
...
5 changes to exploits/shellcodes
macOS/iOS ImageIO - Heap Corruption when Processing Malformed TIFF Image
Pachev FTP Server 1.0 - Path Traversal
ManageEngine Network Configuration Manager 12.2 - 'apiKey' SQL Injection
Webtareas 2.0 - 'id' SQL Injection
OLK Web Store 2020 - Cross-Site Request Forgery
Webtareas 2.0 - 'id' SQL Injection
OLK Web Store 2020 - Cross-Site Request Forgery
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
Centreon 19.10.5 - Database Credentials Disclosure
Centreon 19.10.5 - Remote Command Execution
2020-01-29 05:02:04 +00:00
Offensive Security
b8d05a57a2
DB: 2020-01-28
...
1 changes to exploits/shellcodes
Torrent 3GP Converter 1.51 - Stack Overflow (SEH)
2020-01-28 05:02:03 +00:00
Offensive Security
a497fe32ec
DB: 2020-01-25
...
6 changes to exploits/shellcodes
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
Ricoh Printer Drivers - Local Privilege Escalation
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
Webtareas 2.0 - 'id' SQL Injection
OLK Web Store 2020 - Cross-Site Request Forgery
Genexis Platinum-4410 2.1 - Authentication Bypass
2020-01-25 05:02:04 +00:00
Offensive Security
a7338bf2c6
DB: 2020-01-24
...
4 changes to exploits/shellcodes
BOOTP Turbo 2.0 - Denial of Service (SEH)(PoC)
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
Pachev FTP Server 1.0 - Path Traversal
qdPM 9.1 - Remote Code Execution
2020-01-24 05:02:04 +00:00
Offensive Security
82e6691834
DB: 2020-01-23
...
4 changes to exploits/shellcodes
KeePass 2.44 - Denial of Service (PoC)
Citrix XenMobile Server 10.8 - XML External Entity Injection
Windows/7 - Screen Lock Shellcode (9 bytes)
2020-01-23 05:02:01 +00:00
Offensive Security
8128628aa6
DB: 2020-01-22
...
2 changes to exploits/shellcodes
NEOWISE CARBONFTP 1.4 - Weak Password Encryption
ManageEngine Network Configuration Manager 12.2 - 'apiKey' SQL Injection
2020-01-22 05:02:00 +00:00
Offensive Security
b8cbcf2571
DB: 2020-01-21
...
4 changes to exploits/shellcodes
Sysax Multi Server 5.50 - Denial of Service (PoC)
Easy XML Editor 1.7.8 - XML External Entity Injection
Adive Framework 2.0.8 - Persistent Cross-Site Scripting
Centreon 19.04 - Authenticated Remote Code Execution (Metasploit)
2020-01-21 05:02:10 +00:00
Offensive Security
d907c78cad
DB: 2020-01-18
...
8 changes to exploits/shellcodes
APKF Product Key Finder 2.5.8.0 - 'Name' Denial of Service (PoC)
GTalk Password Finder 2.2.1 - 'Key' Denial of Service (PoC)
Torrent FLV Converter 1.51 Build 117 - Stack Oveflow (SEH partial overwrite)
Trend Micro Maximum Security 2019 - Arbitrary Code Execution
Trend Micro Maximum Security 2019 - Privilege Escalation
Plantronics Hub 3.13.2 - SpokesUpdateService Privilege Escalation (Metasploit)
Wordpress Plugin InfiniteWP Client 1.9.4.5 - Authentication Bypass
Wordpress Time Capsule Plugin 1.21.16 - Authentication Bypass
2020-01-18 05:02:08 +00:00
Offensive Security
1a9ce31a5f
DB: 2020-01-17
...
12 changes to exploits/shellcodes
SunOS 5.10 Generic_147148-26 - Local Privilege Escalation
Microsoft Windows - CryptoAPI (Crypt32.dll) Elliptic Curve Cryptography (ECC) Spoof Code-Signing Certificate
Microsoft Windows 10 (19H1 1901 x64) - 'ws2ifsl.sys' Use After Free Local Privilege Escalation (kASLR kCFG SMEP)
Sagemcom F@ST 3890 (50_10_19-T1) Cable Modem - 'Cable Haunt' Remote Code Execution
VICIDIAL Call Center Suite 2.2.1-237 - Multiple Vulnerabilities
ManageEngine EventLog Analyzer 9.0 - Directory Traversal / Cross-Site Scripting
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
VICIDIAL Call Center Suite - Multiple SQL Injections
Online Book Store 1.0 - 'bookisbn' SQL Injection
WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
Rukovoditel Project Management CRM 2.5.2 - 'reports_id' SQL Injection
Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
Online Book Store 1.0 - Arbitrary File Upload
Tautulli 2.1.9 - Denial of Service ( Metasploit )
Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal
Rukovoditel Project Management CRM 2.5.2 - 'entities_id' SQL Injection
Rukovoditel Project Management CRM 2.5.2 - 'filters' SQL Injection
2020-01-17 05:02:10 +00:00
Offensive Security
dbb38f4b3a
DB: 2020-01-16
...
3 changes to exploits/shellcodes
Barco WePresent - file_transfer.cgi Command Injection (Metasploit)
Online Book Store 1.0 - 'bookisbn' SQL Injection
Huawei HG255 - Directory Traversal ( Metasploit )
2020-01-16 05:02:06 +00:00
Offensive Security
b73c74bb9d
DB: 2020-01-15
...
6 changes to exploits/shellcodes
Redir 3.3 - Denial of Service (PoC)
WeChat - Memory Corruption in CAudioJBM::InputAudioFrameToJBM
Android - ashmem Readonly Bypasses via remap_file_pages() and ASHMEM_UNPIN
VPN unlimited 6.1 - Unquoted Service Path
IBM RICOH InfoPrint 6500 Printer - HTML Injection
IBM RICOH 6400 Printer - HTML Injection
2020-01-15 05:01:57 +00:00