المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65

  1. [webapps] Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeove
  2. [webapps] DotCMS 20.11 - Stored Cross-Site Scripting
  3. [remote] Ksix Zigbee Devices - Playback Protection Bypass (PoC)
  4. [webapps] WebDamn User Registration & Login System with User Panel - SQLi Auth Bypass
  5. [webapps] ChurchCRM 4.2.0 - CSV/Formula Injection
  6. [webapps] ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)
  7. [webapps] Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated)
  8. [webapps] Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit P
  9. [webapps] WonderCMS 3.1.3 - 'Menu' Persistent Cross-Site Scripting
  10. [webapps] NewsLister - Authenticated Persistent Cross-Site Scripting
  11. [webapps] Bakeshop Online Ordering System 1.0 - 'Owner' Persistent Cross-site scripti
  12. [webapps] Online News Portal System 1.0 - 'Title' Stored Cross Site Scripting
  13. [webapps] Local Service Search Engine Management System 1.0 - SQLi Authentication Byp
  14. [webapps] WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution
  15. [webapps] WonderCMS 3.1.3 - Authenticated Remote Code Execution
  16. [webapps] PRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS
  17. [local] IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path
  18. [webapps] Online Voting System Project in PHP - 'username' Persistent Cross-Site Scri
  19. [webapps] EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Store
  20. [webapps] ILIAS Learning Management System 4.3 - SSRF
  21. [webapps] Pharmacy Store Management System 1.0 - 'id' SQL Injection
  22. [webapps] Under Construction Page with CPanel 1.0 - SQL injection
  23. [webapps] User Registration & Login System with Admin Panel - CSRF
  24. [webapps] Student Result Management System 1.0 - Authentication Bypass SQL Injection
  25. [webapps] Expense Management System - 'description' Stored Cross Site Scripting
  26. [local] aSc TimeTables 2021.6.2 - Denial of Service (PoC)
  27. [local] Pearson Vue VTS 2.3.1911 Installer - VUEApplicationWrapper Unquoted Service P
  28. [local] Intel(r) Management and Security Application 5.2 - User Notification Service
  29. [webapps] Tendenci 12.3.1 - CSV/ Formula Injection
  30. [webapps] Setelsa Conacwin 3.7.1.2 - Local File Inclusion
  31. [local] 10-Strike Network Inventory Explorer 8.65 - Buffer Overflow (SEH)
  32. [webapps] Multi Restaurant Table Reservation System 1.0 - Multiple Persistent XSS
  33. [webapps] Tailor Management System 1.0 - Unrestricted File Upload to Remote Code Exec
  34. [webapps] LEPTON CMS 4.7.0 - 'URL' Persistent Cross-Site Scripting
  35. [webapps] Medical Center Portal Management System 1.0 - 'login' SQL Injection
  36. [webapps] Pandora FMS 7.0 NG 749 - Multiple Persistent Cross-Site Scripting Vulnerabi
  37. [webapps] Social Networking Site - Authentication Bypass (SQli)
  38. [local] EPSON Status Monitor 3 'EPSON_PM_RPCV4_06' - Unquoted Service Path
  39. [local] Global Registration Service 1.0.0.3 - 'GREGsvc.exe' Unquoted Service Path
  40. [webapps] Pharmacy/Medical Store & Sale Point 1.0 - 'email' SQL Injection
  41. [webapps] Online Shopping Alphaware 1.0 - Error Based SQL injection
  42. [webapps] Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting
  43. [webapps] Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload
  44. [webapps] TypeSetter 5.1 - CSRF (Change admin e-mail)
  45. [remote] YATinyWinFTP - Denial of Service (PoC)
  46. [webapps] Intelbras Router RF 301K 1.1.2 - Authentication Bypass
  47. [webapps] Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
  48. [webapps] ATX MiniCMTS200a Broadband Gateway 2.0 - Credential Disclosure
  49. [webapps] ElkarBackup 1.3.3 - 'Policy[name]' and 'Policy[Description]' Stored Cross-s
  50. [webapps] Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated)
  51. [dos] libupnp 1.6.18 - Stack-based buffer overflow (DoS)
  52. [webapps] House Rental 1.0 - 'keywords' SQL Injection
  53. [local] Foxit Reader 9.0.1.1049 - Arbitrary Code Execution
  54. [webapps] Wordpress Theme Accesspress Social Icons 1.7.9 - SQL injection (Authenticat
  55. [webapps] Moodle 3.8 - Unrestricted File Upload
  56. [webapps] Acronis Cyber Backup 12.5 Build 16341 - Unauthenticated SSRF
  57. [webapps] FrozenNode Laravel-Administrator 4 - Unrestricted File Upload (Authenticate
  58. [webapps] Ruckus IoT Controller (Ruckus vRIoT) 1.5.1.0.21 - Remote Code Execution
  59. [webapps] Wordpress Theme Wibar 1.1.8 - 'Brand Component' Stored Cross Site Scripting
  60. [local] SAP Lumira 1.31 - Stored Cross-Site Scripting
  61. [webapps] WonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting
  62. [remote] Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
  63. [dos] Pure-FTPd 1.0.48 - Remote Denial of Service
  64. [webapps] SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow
  65. [local] Wondershare Driver Install Service help 10.7.1.321 - 'ElevationService' Unquo
  66. [webapps] WonderCMS 3.1.3 - 'page' Persistent Cross-Site Scripting
  67. [webapps] osCommerce 2.3.4.1 - 'title' Persistent Cross-Site Scripting
  68. [local] docPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)
  69. [webapps] OpenCart 3.0.3.6 - 'Profile Image' Stored Cross Site Scripting (Authenticat
  70. [webapps] OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
  71. [webapps] Seowon 130-SLC router 1.0.11 - 'ipAddr' RCE (Authenticated)
  72. [webapps] ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metaspl
  73. [webapps] nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting
  74. [webapps] Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
  75. [webapps] TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
  76. [webapps] VTiger v7.0 CRM - 'To' Persistent XSS
  77. [webapps] LifeRay 7.2.1 GA2 - Stored XSS
  78. [local] Boxoft Audio Converter 2.3.0 - '.wav' Buffer Overflow (SEH)
  79. [local] Boxoft Convert Master 1.3.0 - 'wav' SEH Local Exploit
  80. [local] Free MP3 CD Ripper 2.8 - Multiple File Buffer Overflow (Metasploit)
  81. [webapps] WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
  82. [local] IBM Tivoli Storage Manager Command Line Administrative Interface 5.2.0.1 - id
  83. [local] Zortam Mp3 Media Studio 27.60 - Remote Code Execution (SEH)
  84. [dos] Internet Download Manager 6.38.12 - Scheduler Downloads Scheduler Buffer Overfl
  85. [webapps] Nagios Log Server 2.1.7 - Persistent Cross-Site Scripting
  86. [webapps] Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injectio
  87. [webapps] M/Monit 3.7.4 - Privilege Escalation
  88. [webapps] M/Monit 3.7.4 - Password Disclosure
  89. [webapps] TestBox CFML Test Framework 4.1.0 - Arbitrary File Write and Remote Code Ex
  90. [webapps] TestBox CFML Test Framework 4.1.0 - Directory Traversal
  91. [webapps] PESCMS TEAM 2.3.2 - Multiple Reflected XSS
  92. [webapps] xuucms 3 - 'keywords' SQL Injection
  93. [webapps] Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
  94. [remote] Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
  95. [webapps] Gitlab 12.9.0 - Arbitrary File Read (Authenticated)
  96. [remote] ZeroLogon - Netlogon Elevation of Privilege
  97. [webapps] Wordpress Plugin WPForms 1.6.3.1 - Persistent Cross Site Scripting (Authent
  98. [webapps] BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Fo
  99. [local] LCD_Service 1.0.1.0 - 'LCD_Service' Unquote Service Path
  100. [remote] Aerospike Database 5.1.0.3 - OS Command Execution
  101. [remote] Apache Struts 2.5.20 - Double OGNL evaluation
  102. [webapps] WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting
  103. [local] Microsoft Internet Explorer 11 - Use-After-Free
  104. [webapps] Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scr
  105. [webapps] EgavilanMedia User Registration & Login System with Admin Panel Exploit - S
  106. [webapps] Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Inject
  107. [webapps] SugarCRM 6.5.18 - Persistent Cross-Site Scripting
  108. [remote] Cisco 7937G - DoS/Privilege Escalation
  109. [webapps] Car Rental Management System 1.0 - Remote Code Execution (Authenticated)
  110. [webapps] Car Rental Management System 1.0 - 'car_id' Sql Injection
  111. [webapps] PMB 5.6 - 'chemin' Local File Disclosure
  112. [local] Atheros Coex Service Application 8.0.0.255 - 'ZAtheros Bt&Wlan Coex Agent' Un
  113. [webapps] User Registration & Login and User Management System 2.1 - Login Bypass SQL
  114. [webapps] Car Rental Management System 1.0 - 'id' SQL Injection (Authenticated)
  115. [local] Logitech Solar Keyboard Service - 'L4301_Solar' Unquoted Service Path
  116. [local] Advanced System Care Service 13 - 'AdvancedSystemCareService13' Unquoted Serv
  117. [webapps] Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
  118. [webapps] Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
  119. [local] KiteService 1.2020.1113.1 - 'KiteService.exe' Unquoted Service Path
  120. [local] SAntivirus IC 10.0.21.61 - 'SAntivirusIC' Unquoted Service Path
  121. [local] IDT PC Audio 1.0.6425.0 - 'STacSV' Unquoted Service Path
  122. [webapps] OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
  123. [webapps] October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
  124. [local] DigitalPersona 5.1.0.656 'DpHostW' - Unquoted Service Path
  125. [webapps] Touchbase.io 1.10 - Stored Cross Site Scripting
  126. [webapps] Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
  127. [webapps] Citrix ADC NetScaler - Local File Inclusion (Metasploit)
  128. [webapps] Bludit 3.9.2 - Authentication Bruteforce Bypass (Metasploit)
  129. [webapps] ASUS TM-AC1900 - Arbitrary Command Execution (Metasploit)
  130. [local] Nidesoft 3GP Video Converter 2.6.18 - Local Stack Buffer Overflow
  131. [webapps] Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection
  132. [webapps] Water Billing System 1.0 - 'username' and 'password' parameters SQL Injecti
  133. [webapps] Customer Support System 1.0 - 'username' Authentication Bypass
  134. [webapps] CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated)
  135. [webapps] Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel
  136. [webapps] Customer Support System 1.0 - Cross-Site Request Forgery
  137. [webapps] Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
  138. [webapps] ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting
  139. [webapps] Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload
  140. [webapps] Joplin 1.2.6 - 'link' Cross Site Scripting
  141. [local] Privacy Drive v3.17.0 - 'pdsvc.exe' Unquoted Service Path
  142. [local] DiskBoss v11.7.28 - Multiple Services Unquoted Service Path
  143. [local] RealTimes Desktop Service 18.1.4 - 'rpdsvc.exe' Unquoted Service Path
  144. [local] Deep Instinct Windows Agent 1.2.24.0 - 'DeepNetworkService' Unquoted Service
  145. [local] Canon Inkjet Extended Survey Program 5.1.0.8 - 'IJPLMSVC.EXE' - Unquoted Ser
  146. [local] iDeskService 3.0.2.1 - 'iDeskService' Unquoted Service Path
  147. [local] Magic Mouse 2 utilities 2.20 - 'magicmouse2service' Unquoted Service Path
  148. [local] MEMU PLAY 3.7.0 - 'MEmusvc' Unquoted Service Path
  149. [local] Realtek Andrea RT Filters 1.0.64.10 - 'AERTSr64.EXE' Unquoted Service Path
  150. [local] Genexus Protection Server 9.6.4.2 - 'protsrvservice' Unquoted Service Path
  151. [local] DigitalPersona 4.5.0.2213 - 'DpHostW' Unquoted Service Path
  152. [local] Syncplify.me Server! 5.0.37 - 'SMWebRestServicev5' Unquoted Service Path
  153. [local] HP WMI Service 1.4.8.0 - 'HPWMISVC.exe' Unquoted Service Path
  154. [local] Motorola Device Manager 2.4.5 - 'ForwardDaemon.exe ' Unquoted Service Path
  155. [local] Motorola Device Manager 2.5.4 - 'MotoHelperService.exe' Unquoted Service Path
  156. [local] Motorola Device Manager 2.5.4 - 'ForwardDaemon.exe ' Unquoted Service Path
  157. [local] IPTInstaller 4.0.9 - 'PassThru Service' Unquoted Service Path
  158. [local] OKI sPSV Port Manager 1.0.41 - 'sPSVOpLclSrv' Unquoted Service Path
  159. [local] Winstep 18.06.0096 - 'Xtreme Service' Unquoted Service Path
  160. [webapps] SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)
  161. [local] KMSpico 17.1.0.0 - 'Service KMSELDI' Unquoted Service Path
  162. [local] HP Display Assistant x64 Edition 3.20 - 'DTSRVC' Unquoted Service Path
  163. [webapps] Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF
  164. [webapps] BlogEngine 3.3.8 - 'Content' Stored XSS
  165. [webapps] SmartBlog 2.0.1 - 'id_post' Blind SQL injection
  166. [webapps] CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
  167. [webapps] Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated)
  168. [webapps] Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticat
  169. [remote] TP-Link WDR4300 - Remote Code Execution (Authenticated)
  170. [webapps] iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass
  171. [webapps] iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege
  172. [local] Amarok 2.8.0 - Denial-of-Service
  173. [webapps] iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF)
  174. [webapps] PDW File Browser < v1.3 - Remote Code Execution
  175. [webapps] School Log Management System 1.0 - 'username' SQL Injection / Remote Code E
  176. [webapps] Student Attendance Management System 1.0 - 'username' SQL Injection / Remot
  177. [webapps] Processwire CMS 2.4.0 - 'download' Local File Inclusion
  178. [webapps] Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated
  179. [webapps] Exploit Title: Complaints Report Management System 1.0 - 'username' SQL Inj
  180. [webapps] WordPress Plugin Simple File List 5.4 - Arbitrary File Upload
  181. [webapps] Monitorr 1.7.6m - Remote Code Execution (Unauthenticated)
  182. [webapps] Monitorr 1.7.6m - Authorization Bypass
  183. [local] Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
  184. [local] Quick N Easy FTP Service 3.2 - Unquoted Service Path
  185. [webapps] Apache Flink 1.9.x - File Upload RCE (Unauthenticated)
  186. [webapps] Simple College Website 1.0 - 'username' SQL Injection / Remote Code Executi
  187. [webapps] Online Job Portal 1.0 - 'userid' SQL Injection
  188. [webapps] Citadel WebCit < 926 - Session Hijacking Exploit
  189. [webapps] DedeCMS v.5.8 - "keyword" Cross-Site Scripting
  190. [webapps] CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting
  191. [webapps] Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot
  192. [webapps] WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.
  193. [webapps] Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)
  194. [webapps] Online Examination System 1.0 - 'name' Stored Cross Site Scripting
  195. [webapps] Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12
  196. [local] Program Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service Path
  197. [local] Prey 1.9.6 - "CronService" Unquoted Service Path
  198. [local] IP Watcher v3.0.0.30 - 'PACService.exe' Unquoted Service Path
  199. [local] Exploit - EPSON 1.124 - 'seksmdb.exe' Unquoted Service Path
  200. [local] PackageKit < 1.1.13 - File Existence Disclosure
  201. [local] aptdaemon < 1.1.1 - File Existence Disclosure
  202. [local] Blueman < 2.1.4 - Local Privilege Escalation
  203. [webapps] Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
  204. [webapps] CSE Bookstore 1.0 - Authentication Bypass
  205. [remote] GoAhead Web Server 5.1.1 - Digest Authentication Capture Replay Nonce Reuse
  206. [webapps] Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
  207. [webapps] Client Management System 1.0 - 'searchdata' SQL injection
  208. [webapps] Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated)
  209. [local] TDM Digital Signage PC Player 4.1 - Insecure File Permissions
  210. [remote] Adtec Digital Multiple Products - Default Hardcoded Credentials Remote Root
  211. [webapps] ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service
  212. [webapps] ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthe
  213. [webapps] ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure
  214. [webapps] ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure
  215. [webapps] InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
  216. [webapps] PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS)
  217. [webapps] Genexis Platinum-4410 - 'SSID' Persistent XSS
  218. [webapps] CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Inject
  219. [webapps] Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
  220. [webapps] Bludit 3.9.2 - Auth Bruteforce Bypass
  221. [webapps] TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
  222. [webapps] Gym Management System 1.0 - Stored Cross Site Scripting
  223. [webapps] Gym Management System 1.0 - Authentication Bypass
  224. [webapps] School Faculty Scheduling System 1.0 - 'username' SQL Injection
  225. [webapps] School Faculty Scheduling System 1.0 - 'id' SQL Injection
  226. [webapps] Lot Reservation Management System 1.0 - Authentication Bypass
  227. [webapps] Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
  228. [webapps] Gym Management System 1.0 - 'id' SQL Injection
  229. [webapps] Point of Sales 1.0 - 'username' SQL Injection
  230. [webapps] Point of Sales 1.0 - 'id' SQL Injection
  231. [webapps] Car Rental Management System 1.0 - Arbitrary File Upload
  232. [webapps] User Registration & Login and User Management System 2.1 - SQL Injection
  233. [webapps] Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
  234. [webapps] Ajenti 2.1.36 - Remote Code Execution (Authenticated)
  235. [webapps] Online Library Management System 1.0 - Arbitrary File Upload
  236. [webapps] Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scrip
  237. [webapps] Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
  238. [webapps] Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
  239. [webapps] GOautodial 4.0 - Authenticated Shell Upload
  240. [webapps] Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scriptin
  241. [webapps] Hrsale 2.0.0 - Local File Inclusion
  242. [webapps] School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
  243. [webapps] School Faculty Scheduling System 1.0 - Authentication Bypass POC
  244. [webapps] Mobile Shop System v1.0 - SQL Injection Authentication Bypass
  245. [webapps] Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
  246. [webapps] WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
  247. [webapps] WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting
  248. [webapps] WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
  249. [webapps] User Registration & Login and User Management System With admin panel 2.1 -
  250. [webapps] RiteCMS 2.2.1 - Remote Code Execution (Authenticated)