Exploit-DB
|
7ebfc36557
|
DB: 2025-04-17
24 changes to exploits/shellcodes/ghdb
ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE)
Ruckus IoT Controller 1.7.1.0 - Undocumented Backdoor Account
Dell EMC iDRAC7/iDRAC8 2.52.52.52 - Remote Code Execution (RCE)
FLIR AX8 1.46.16 - Remote Command Injection
ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF)
Ethercreative Logs 3.0.3 - Path Traversal
Garage Management System 1.0 (categoriesName) - Stored XSS
Nagios Log Server 2024R1.3.1 - Stored XSS
ProConf 6.0 - Insecure Direct Object Reference (IDOR)
Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection
ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) - File Write DoS
ABB Cylon Aspect 4.00.00 (factorySaved.php) - Unauthenticated XSS
ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution
Car Rental Project 1.0 - Remote Code Execution
KodExplorer 4.52 - Open Redirect
NagVis 1.9.33 - Arbitrary File Read
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
phpMyFAQ 3.2.10 - Unintended File Download Triggered by Embedded Frames
Smart Manager 8.27.0 - Post-Authenticated SQL Injection
Zabbix 7.0.0 - SQL Injection
Hugging Face Transformers MobileViTV2 4.41.1 - Remote Code Execution (RCE)
Fortinet FortiOS_ FortiProxy_ and FortiSwitchManager 7.2.0 - Authentication bypass
WebMethods Integration Server 10.15.0.0000-0092 - Improper Access on Login Page
|
2025-04-17 00:16:29 +00:00 |
|
Exploit-DB
|
b905517ca9
|
DB: 2025-04-16
22 changes to exploits/shellcodes/ghdb
Spring Boot common-user-management 0.1 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.07.02 (userManagement.php) - Weak Password Policy
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) - Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (licenseUpload.php) - Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 - Cookie User Password Disclosure
ABB Cylon Aspect 3.08.03 (CookieDB) - SQL Injection
Ivanti Connect Secure 22.7R2.5 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.08.03 (MapServicesHandler) - Authenticated Reflected XSS
ABB Cylon Aspect 3.08.03 - Hard-coded Secrets
Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE)
IBMi Navigator 7.5 - HTTP Security Token Bypass
IBMi Navigator 7.5 - Server Side Request Forgery (SSRF)
Plane 0.23.1 - Server side request forgery (SSRF)
ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) - Denial of Service (DOS)
ABB Cylon Aspect 3.08.02 (webServerUpdate.php) - Input Validation Config Poisoning
Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
OpenCMS 17.0 - Stored Cross Site Scripting (XSS)
Really Simple Security 9.1.1.1 - Authentication Bypass
Pymatgen 2024.1 - Remote Code Execution (RCE)
|
2025-04-16 00:16:24 +00:00 |
|
Exploit-DB
|
0f3d104e83
|
DB: 2025-04-15
15 changes to exploits/shellcodes/ghdb
ZTE ZXHN H168N 3.1 - Remote Code Execution (RCE) via authentication bypass
GestioIP 3.5.7 - Cross-Site Request Forgery (CSRF)
GestioIP 3.5.7 - Cross-Site Scripting (XSS)
GestioIP 3.5.7 - Reflected Cross-Site Scripting (Reflected XSS)
GestioIP 3.5.7 - Remote Command Execution (RCE)
GestioIP 3.5.7 - Stored Cross-Site Scripting (Stored XSS)
OpenPanel 0.3.4 - Directory Traversal
OpenPanel 0.3.4 - Incorrect Access Control
OpenPanel 0.3.4 - OS Command Injection
OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal
Pimcore 11.4.2 - Stored cross site scripting
Pimcore customer-data-framework 4.2.0 - SQL injection
SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated)
Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
|
2025-04-15 00:16:26 +00:00 |
|
Exploit-DB
|
60175c9963
|
DB: 2025-04-14
52 changes to exploits/shellcodes/ghdb
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
DataEase 2.4.0 - Database Configuration Information Exposure
Cosy+ firmware 21.2s7 - Command Injection
Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
ABB Cylon Aspect 3.07.02 - File Disclosure
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
CyberPanel 2.3.6 - Remote Code Execution (RCE)
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
MagnusSolution magnusbilling 7.3.0 - Command Injection
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
Watcharr 1.43.0 - Remote Code Execution (RCE)
Webmin Usermin 2.100 - Username Enumeration
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
Artica Proxy 4.50 - Remote Code Execution (RCE)
Centron 19.04 - Remote Code Execution (RCE)
ChurchCRM 5.9.1 - SQL Injection
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
CodeCanyon RISE CRM 3.7.0 - SQL Injection
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
Feng Office 3.11.1.2 - SQL Injection
flatCore 1.5 - Cross Site Request Forgery (CSRF)
flatCore 1.5.5 - Arbitrary File Upload
flatCore 1.5 - Cross Site Request Forgery (CSRF)
flatCore 1.5.5 - Arbitrary File Upload
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
Gnuboard5 5.3.2.8 - SQL Injection
LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
Litespeed Cache 6.5.0.1 - Authentication Bypass
MiniCMS 1.1 - Cross Site Scripting (XSS)
MoziloCMS 3.0 - Remote Code Execution (RCE)
NEWS-BUZZ News Management System 1.0 - SQL Injection
PandoraFMS 7.0NG.772 - SQL Injection
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
RosarioSIS 7.6 - SQL Injection
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
Typecho 1.3.0 - Race Condition
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
Typecho 1.3.0 - Race Condition
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
|
2025-04-14 00:16:26 +00:00 |
|
Exploit-DB
|
b165516b1b
|
DB: 2025-04-12
26 changes to exploits/shellcodes/ghdb
ABB Cylon Aspect 3.08.02 - PHP Session Fixation
ABB Cylon FLXeon 9.3.4 - Cross-Site Request Forgery
ABB Cylon FLXeon 9.3.4 - Default Credentials
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning
Netman 204 - Remote command without authentication
qBittorrent 5.0.1 - MITM RCE
CMU CERT/CC VINCE 2.0.6 - Stored XSS
CyberPanel 2.3.6 - Remote Code Execution (RCE)
GeoVision GV-ASManager 6.1.0.0 - Broken Access Control
GeoVision GV-ASManager 6.1.1.0 - CSRF
MagnusSolution magnusbilling 7.3.0 - Command Injection
Nagios Log Server 2024R1.3.1 - API Key Exposure
WebFileSys 2.31.0 - Directory Path Traversal
flatCore 1.5 - Cross Site Request Forgery (CSRF)
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
Gnuboard5 5.3.2.8 - SQL Injection
LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
MiniCMS 1.1 - Cross Site Scripting (XSS)
NEWS-BUZZ News Management System 1.0 - SQL Injection
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
RosarioSIS 7.6 - SQL Injection
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
|
2025-04-12 00:16:31 +00:00 |
|
Exploit-DB
|
9d3e200bec
|
DB: 2025-04-11
12 changes to exploits/shellcodes/ghdb
Cosy+ firmware 21.2s7 - Command Injection
K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
Centron 19.04 - Remote Code Execution (RCE)
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
Feng Office 3.11.1.2 - SQL Injection
flatCore 1.5.5 - Arbitrary File Upload
PandoraFMS 7.0NG.772 - SQL Injection
Typecho 1.3.0 - Race Condition
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
|
2025-04-11 00:17:01 +00:00 |
|