Commit graph

2809 commits

Author SHA1 Message Date
Exploit-DB
411b6755b3 DB: 2024-02-17
1 changes to exploits/shellcodes/ghdb
2024-02-17 00:16:52 +00:00
Exploit-DB
bdcc81a451 DB: 2024-02-16
4 changes to exploits/shellcodes/ghdb

DS Wireless Communication - Remote Code Execution

Metabase 0.46.6 - Pre-Auth Remote Code Execution

SISQUALWFM 7.1.319.103 - Host Header Injection
2024-02-16 00:16:25 +00:00
Exploit-DB
5c0c152cec DB: 2024-02-14
6 changes to exploits/shellcodes/ghdb

VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service

Splunk 9.0.4 - Information Disclosure

Lost and Found Information System v1.0 - ( IDOR ) leads to Account Take over

ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
2024-02-14 00:16:18 +00:00
Exploit-DB
a846c2fd3a DB: 2024-02-10
8 changes to exploits/shellcodes/ghdb

Zyxel zysh - Format string

Elasticsearch - StackOverflow DoS

Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)

Online Nurse Hiring System 1.0 - Time-Based SQL Injection

Rail Pass Management System 1.0 - Time-Based SQL Injection

Wordpress Augmented-Reality - Remote Code Execution Unauthenticated

Wordpress Seotheme - Remote Code Execution Unauthenticated
2024-02-10 00:16:32 +00:00
Exploit-DB
3876052878 DB: 2024-02-07
1 changes to exploits/shellcodes/ghdb
2024-02-07 00:16:30 +00:00
Exploit-DB
0c65b881ba DB: 2024-02-06
10 changes to exploits/shellcodes/ghdb

Milesight Routers UR5X_ UR32L_ UR32_ UR35_ UR41 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

WhatsUp Gold 2022 (22.1.0 Build 39) - XSS

Clinic's Patient Management System 1.0 - Unauthenticated RCE

Curfew e-Pass Management System 1.0 - FromDate SQL Injection

GYM MS - GYM Management System - Cross Site Scripting (Stored)

MISP 2.4.171 - Stored XSS

TASKHUB-2.8.8 - XSS-Reflected

Wordpress 'simple urls' Plugin < 115 - XSS
2024-02-06 00:16:29 +00:00
Exploit-DB
81ae91fdae DB: 2024-02-03
14 changes to exploits/shellcodes/ghdb

Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution
Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal
TP-LINK TL-WR740N - Multiple HTML Injection
TP-Link TL-WR740N - UnAuthenticated Directory Transversal

Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)

mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page

PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow

WebCatalog 48.4 - Arbitrary Protocol Execution
2024-02-03 00:16:34 +00:00
Exploit-DB
2aed99237c DB: 2024-02-01
8 changes to exploits/shellcodes/ghdb

Proxmox VE - TOTP Brute Force

RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC

GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities

101 News 1.0 - Multiple-SQLi
Academy LMS 6.2 - Reflected XSS
Academy LMS 6.2 - SQL Injection

Grocy <=4.0.2 - CSRF
2024-02-01 00:16:32 +00:00
Exploit-DB
a5920da7af DB: 2024-01-30
10 changes to exploits/shellcodes/ghdb

Ricoh Printer - Directory and File Exposure

Blood Bank & Donor Management System using v2.2 - Stored XSS

Equipment Rental Script-1.0 - SQLi

Bank Locker Management System - SQL Injection

Fundraising Script 1.0 - SQLi

PHP Shopping Cart 4.2 - Multiple-SQLi

7 Sticky Notes v1.9 - OS Command Injection

Typora v1.7.4 - OS Command Injection
2024-01-30 00:16:26 +00:00
Exploit-DB
967f9d17d6 DB: 2024-01-24
1 changes to exploits/shellcodes/ghdb
2024-01-24 00:16:25 +00:00
Exploit-DB
cb7ba0c503 DB: 2023-12-22
1 changes to exploits/shellcodes/ghdb
2023-12-22 00:16:27 +00:00
Exploit-DB
82c4f0ab51 DB: 2023-12-19
1 changes to exploits/shellcodes/ghdb
2023-12-19 00:16:22 +00:00
Exploit-DB
d6ac341475 DB: 2023-12-16
1 changes to exploits/shellcodes/ghdb
2023-12-16 00:16:30 +00:00
Exploit-DB
5ae67f58b9 DB: 2023-12-15
1 changes to exploits/shellcodes/ghdb
2023-12-15 00:16:26 +00:00
Exploit-DB
07b04761c2 DB: 2023-12-13
1 changes to exploits/shellcodes/ghdb
2023-12-13 00:16:53 +00:00
Exploit-DB
4b91641d83 DB: 2023-12-12
1 changes to exploits/shellcodes/ghdb
2023-12-12 00:16:31 +00:00
Exploit-DB
baedefe44c DB: 2023-12-07
1 changes to exploits/shellcodes/ghdb
2023-12-07 00:16:31 +00:00
Exploit-DB
3ed9fc9688 DB: 2023-12-05
1 changes to exploits/shellcodes/ghdb
2023-12-05 00:16:21 +00:00
Exploit-DB
066333e56d DB: 2023-12-02
1 changes to exploits/shellcodes/ghdb
2023-12-02 00:16:24 +00:00
Exploit-DB
7e32166ebc DB: 2023-12-01
1 changes to exploits/shellcodes/ghdb
2023-12-01 00:16:26 +00:00
Exploit-DB
057c2f886a DB: 2023-11-30
1 changes to exploits/shellcodes/ghdb
2023-11-30 00:16:31 +00:00
Exploit-DB
bde3836027 DB: 2023-11-28
1 changes to exploits/shellcodes/ghdb
2023-11-28 00:16:33 +00:00
Exploit-DB
617a6b4036 DB: 2023-11-25
1 changes to exploits/shellcodes/ghdb
2023-11-25 00:16:32 +00:00
Exploit-DB
8a972c9a3f DB: 2023-11-24
1 changes to exploits/shellcodes/ghdb
2023-11-24 00:16:42 +00:00
Exploit-DB
d66aada84d DB: 2023-11-21
1 changes to exploits/shellcodes/ghdb
2023-11-21 00:16:23 +00:00
Exploit-DB
034fa97b3e DB: 2023-11-18
1 changes to exploits/shellcodes/ghdb
2023-11-18 00:16:41 +00:00
Exploit-DB
e7b3c09fd9 DB: 2023-11-11
1 changes to exploits/shellcodes/ghdb
2023-11-11 00:16:32 +00:00
Exploit-DB
937420d384 DB: 2023-11-10
1 changes to exploits/shellcodes/ghdb
2023-11-10 00:16:27 +00:00
Exploit-DB
43a5e18260 DB: 2023-11-09
1 changes to exploits/shellcodes/ghdb
2023-11-09 00:16:27 +00:00
Exploit-DB
7b7a9c9ea4 DB: 2023-11-08
1 changes to exploits/shellcodes/ghdb
2023-11-08 00:17:10 +00:00
Exploit-DB
3711d1e88d DB: 2023-11-07
1 changes to exploits/shellcodes/ghdb
2023-11-07 00:16:47 +00:00
Exploit-DB
5b9acfe03d DB: 2023-11-03
1 changes to exploits/shellcodes/ghdb
2023-11-03 00:17:00 +00:00
Exploit-DB
ea7fd161a3 DB: 2023-11-02
1 changes to exploits/shellcodes/ghdb
2023-11-02 00:16:33 +00:00
Exploit-DB
e369c91366 DB: 2023-11-01
1 changes to exploits/shellcodes/ghdb
2023-11-01 00:16:42 +00:00
Exploit-DB
75cbb282d9 DB: 2023-10-31
12 changes to exploits/shellcodes/ghdb

systemd 246 - Local Privilege Escalation

ChurchCRM v4.5.3 - Authenticated SQL Injection

Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) via subprocess_execute

Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)

Request-Baskets v1.2.1 - Server-side request forgery (SSRF)
2023-10-31 00:17:05 +00:00
Exploit-DB
45020d9cc3 DB: 2023-10-26
1 changes to exploits/shellcodes/ghdb
2023-10-26 00:16:49 +00:00
Exploit-DB
3c68644b7f DB: 2023-10-24
1 changes to exploits/shellcodes/ghdb
2023-10-24 00:16:26 +00:00
Exploit-DB
28233c60a9 DB: 2023-10-21
1 changes to exploits/shellcodes/ghdb
2023-10-21 00:17:11 +00:00
Exploit-DB
8e469af5e4 DB: 2023-10-20
1 changes to exploits/shellcodes/ghdb
2023-10-20 00:16:34 +00:00
Exploit-DB
d769738a1b DB: 2023-10-19
1 changes to exploits/shellcodes/ghdb
2023-10-19 00:16:34 +00:00
Exploit-DB
888e6c1d4c DB: 2023-10-17
1 changes to exploits/shellcodes/ghdb
2023-10-17 00:16:34 +00:00
Exploit-DB
53fc63f69b DB: 2023-10-14
1 changes to exploits/shellcodes/ghdb
2023-10-14 00:16:29 +00:00
Exploit-DB
f3649a641f DB: 2023-10-10
24 changes to exploits/shellcodes/ghdb

Minio 2022-07-29T19-40-48Z - Path traversal

Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service

Atcom 2.7.x.x - Authenticated Command Injection

Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction

OpenPLC WebServer 3 - Denial of Service

Splunk 9.0.5 - admin account take over

BoidCMS v2.0.0 - authenticated file upload vulnerability

Cacti 1.2.24 - Authenticated command injection when using SNMP options

Chitor-CMS v1.1.2 - Pre-Auth SQL Injection

Clcknshop 1.0.0 - SQL Injection

Coppermine Gallery 1.6.25 - RCE

Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)

GLPI GZIP(Py3) 9.4.5 - RCE

Limo Booking Software v1.0 - CORS

Media Library Assistant Wordpress Plugin - RCE and LFI

Online ID Generator 1.0 - Remote Code Execution (RCE)

Shuttle-Booking-Software v1.0 - Multiple-SQLi

Webedition CMS v2.9.8.8 - Blind SSRF

WEBIGniter v28.7.23 File Upload - Remote Code Execution

Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation

Wordpress Sonaar Music Plugin 4.7 - Stored XSS

Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)
2023-10-10 00:16:32 +00:00
Exploit-DB
e5f7757184 DB: 2023-10-03
1 changes to exploits/shellcodes/ghdb
2023-10-03 00:16:26 +00:00
g0t mi1k
f88561adfb Merge branch 'nmap-version-parsing' into 'main'
Fix: searchsploit Nmap XML parsing loses software version data.

See merge request exploit-database/exploitdb!3
2023-09-25 16:46:54 +00:00
Michael Monsivais
8298b27c9c Fix: searchsploit Nmap parsing loses version data.
Modified searchsploit's Nmap XML parsing to correctly extract software
versions. Also, these versions are no longer split on '.'.
2023-09-15 20:29:25 -04:00
Exploit-DB
3cde8c39d6 DB: 2023-09-13
1 changes to exploits/shellcodes/ghdb
2023-09-13 00:16:29 +00:00
Exploit-DB
db6fc602bf DB: 2023-09-12
1 changes to exploits/shellcodes/ghdb
2023-09-12 00:16:26 +00:00
Exploit-DB
cbe784b087 DB: 2023-09-09
16 changes to exploits/shellcodes/ghdb

Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities

Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS

Drupal 10.1.2 - web-cache-poisoning-External-service-interaction

Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure

soosyze 2.0.0 - File Upload

SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection

Wordpress Plugin Elementor 3.5.5 - Iframe Injection

Wp2Fac - OS Command Injection

Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)

SyncBreeze 15.2.24 - 'login' Denial of Service

GOM Player 2.3.90.5360 - Buffer Overflow (PoC)

GOM Player 2.3.90.5360 - Remote Code Execution (RCE)

Windows/x64 - PIC Null-Free TCP Reverse Shell Shellcode (476 Bytes)
2023-09-09 00:16:33 +00:00
Exploit-DB
54971d143b DB: 2023-09-08
1 changes to exploits/shellcodes/ghdb
2023-09-08 00:16:30 +00:00