المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62

  1. [webapps] Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
  2. [webapps] Sky File 2.1.0 iOS - Directory Traversal
  3. [webapps] EspoCRM 5.8.5 - Privilege Escalation
  4. [webapps] Edimax EW-7438RPn 1.13 - Remote Code Execution
  5. [local] Popcorn Time 6.2 - 'Update service' Unquoted Service Path
  6. [webapps] Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
  7. [webapps] PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
  8. [webapps] Netis E1+ 1.2.32533 - Backdoor Account (root)
  9. [webapps] Online shopping system advanced 1.0 - 'p' SQL Injection
  10. [webapps] Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
  11. [webapps] Online Course Registration 2.0 - Authentication Bypass
  12. [webapps] Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
  13. [local] Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
  14. [local] Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
  15. [remote] CloudMe 1.11.2 - Buffer Overflow (PoC)
  16. [webapps] School ERP Pro 1.0 - 'es_messagesid' SQL Injection
  17. [local] NVIDIA Update Service Daemon 1.0.21 - 'nvUpdatusService' Unquoted Service Pa
  18. [webapps] School ERP Pro 1.0 - Remote Code Execution
  19. [webapps] Open-AudIT Professional 3.3.1 - Remote Code Execution
  20. [webapps] School ERP Pro 1.0 - Arbitrary File Read
  21. [webapps] Easy Transfer 1.7 for iOS - Directory Traversal
  22. [local] Andrea ST Filters Service 1.0.64.7 - 'Andrea ST Filters Service ' Unquoted
  23. [local] Internet Download Manager 6.37.11.1 - Stack Buffer Overflow (PoC)
  24. [remote] ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
  25. [remote] Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
  26. [remote] PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metas
  27. [remote] DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
  28. [local] VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
  29. [remote] Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
  30. [remote] TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit
  31. [remote] Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
  32. [webapps] DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
  33. [webapps] File Transfer iFamily 2.1 - Directory Traversal
  34. [webapps] Xeroneit Library Management System 3.0 - 'category' SQL Injection
  35. [local] BlazeDVD 7.0.2 - Buffer Overflow (SEH)
  36. [webapps] Pinger 1.0 - Remote Code Execution
  37. [webapps] SeedDMS 5.1.18 - Persistent Cross-Site Scripting
  38. [webapps] Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
  39. [webapps] AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
  40. [webapps] SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
  41. [webapps] Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
  42. [webapps] WSO2 3.1.0 - Persistent Cross-Site Scripting
  43. [webapps] Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
  44. [local] B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)
  45. [webapps] MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
  46. [webapps] TVT NVMS 1000 - Directory Traversal
  47. [webapps] Webtateas 2.0 - Arbitrary File Read
  48. [webapps] WSO2 3.1.0 - Arbitrary File Delete
  49. [local] Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (S
  50. [webapps] Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
  51. [webapps] Huawei HG630 2 Router - Authentication Bypass
  52. [webapps] Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
  53. [dos] AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
  54. [local] Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
  55. [webapps] Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
  56. [webapps] Django 3.0 - Cross-Site Request Forgery Token Bypass
  57. [dos] dnsmasq-utils 2.79-1 - 'dhcp_release' Denial of Service (PoC)
  58. [dos] ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
  59. [local] Microsoft NET USE win10 - Insufficient Authentication Logic
  60. [webapps] pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
  61. [webapps] Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metaspl
  62. [webapps] WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
  63. [webapps] Bolt CMS 3.7.0 - Authenticated Remote Code Execution
  64. [webapps] LimeSurvey 4.1.11 - 'File Manager' Path Traversal
  65. [dos] UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)
  66. [webapps] LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
  67. [dos] UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)
  68. [dos] UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)
  69. [dos] ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)
  70. [local] Triologic Media Player 8 - '.m3l' Buffer Overflow (Unicode) (SEH)
  71. [dos] SpotAuditor 5.3.4 - 'Name' Denial of Service (PoC)
  72. [dos] Nsauditor 3.2.0.0 - 'Name' Denial of Service (PoC)
  73. [dos] Frigate 3.36 - Denial of Service (PoC)
  74. [local] Memu Play 7.1.3 - Insecure Folder Permissions
  75. [dos] Product Key Explorer 4.2.2.0 - 'Key' Denial of Service (PoC)
  76. [webapps] Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
  77. [local] AIDA64 Engineer 6.20.5300 - 'Report File' filename Buffer Overflow (SEH)
  78. [local] DiskBoss 7.7.14 - 'Input Directory' Local Buffer Overflow (PoC)
  79. [local] 10Strike LANState 9.32 - 'Force Check' Buffer Overflow (SEH)
  80. [dos] DiskBoss 7.7.14 - Denial of Service (PoC)
  81. [remote] Redis - Replication Code Execution (Metasploit)
  82. [remote] IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasp
  83. [remote] DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
  84. [remote] SharePoint Workflows - XOML Injection (Metasploit)
  85. [webapps] Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
  86. [webapps] Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Inject
  87. [dos] FlashFXP 4.2.0 Build 1730 - Denial of Service (PoC)
  88. [remote] Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
  89. [local] Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPA
  90. [webapps] Zen Load Balancer 3.10.1 - Remote Code Execution
  91. [local] 10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow
  92. [webapps] Joomla! com_fabrik 3.9.11 - Directory Traversal
  93. [dos] Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service (PoC)
  94. [webapps] rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
  95. [dos] Everest 5.50.2100 - 'Open File' Denial of Service (PoC)
  96. [webapps] Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
  97. [local] Easy RM to MP3 Converter 2.7.3.700 - 'Input' Local Buffer Overflow (SEH)
  98. [webapps] ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
  99. [webapps] TP-Link Archer C50 3 - Denial of Service (PoC)
  100. [webapps] Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
  101. [local] 10-Strike Network Inventory Explorer - 'srvInventoryWebServer' Unquoted Servi
  102. [local] 10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)
  103. [webapps] Joomla! Component GMapFP 3.30 - Arbitrary File Upload
  104. [local] AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
  105. [webapps] LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
  106. [webapps] Wordpress Plugin WPForms 1.5.9 - Persistent Cross-Site Scripting
  107. [local] Veyon 4.3.4 - 'VeyonService' Unquoted Service Path
  108. [webapps] UCM6202 1.0.18.13 - Remote Command Injection
  109. [webapps] UliCMS 2020.1 - Persistent Cross-Site Scripting
  110. [webapps] Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
  111. [webapps] FIBARO System Home Center 5.021 - Remote File Include
  112. [webapps] rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
  113. [remote] CyberArk PSMP 10.9.1 - Policy Restriction Bypass
  114. [dos] ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
  115. [dos] Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
  116. [webapps] Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
  117. [local] VMware Fusion 11.5.2 - Privilege Escalation
  118. [remote] Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
  119. [local] NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
  120. [remote] Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
  121. [local] Microsoft VSCode Python Extension - Code Execution
  122. [local] VMWare Fusion - Local Privilege Escalation
  123. [webapps] Netlink GPON Router 1.0.11 - Remote Code Execution
  124. [remote] Rconfig 3.x - Chained Remote Code Execution (Metasploit)
  125. [remote] ManageEngine Desktop Central - Java Deserialization (Metasploit)
  126. [webapps] MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
  127. [webapps] PHPKB Multi-Language 9 - Authenticated Remote Code Execution
  128. [webapps] PHPKB Multi-Language 9 - Authenticated Directory Traversal
  129. [webapps] PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execu
  130. [webapps] Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin
  131. [webapps] Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
  132. [dos] Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABI
  133. [remote] Drobo 5N2 4.1.1 - Remote Command Injection
  134. [local] AnyBurn 4.8 - Buffer Overflow (SEH)
  135. [webapps] Centos WebPanel 7 - 'term' SQL Injection
  136. [webapps] Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
  137. [webapps] Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
  138. [webapps] rConfig 3.9 - 'searchColumn' SQL Injection
  139. [webapps] rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
  140. [webapps] Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
  141. [webapps] WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
  142. [webapps] Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
  143. [webapps] HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
  144. [local] ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
  145. [webapps] Wordpress Plugin Search Meter 2.13.2 - CSV injection
  146. [local] ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
  147. [remote] Nagios XI - Authenticated Remote Command Execution (Metasploit)
  148. [remote] PHPStudy - Backdoor Remote Code execution (Metasploit)
  149. [webapps] Persian VIP Download Script 1.0 - 'active' SQL Injection
  150. [local] Counter Strike: GO - '.bsp' Memory Control (PoC)
  151. [webapps] Sysaid 20.1.11 b26 - Remote Command Execution
  152. [webapps] YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
  153. [remote] Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
  154. [local] OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
  155. [remote] Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
  156. [remote] Google Chrome 67, 68 and 69 - Object.create Type Confusion (Metasploit)
  157. [remote] Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
  158. [remote] PHP-FPM - Underflow Remote Code Execution (Metasploit)
  159. [local] Microsoft Windows - 'WizardOpium' Local Privilege Escalation
  160. [webapps] Sentrifugo HRMS 3.2 - 'id' SQL Injection
  161. [webapps] 60CycleCMS - 'news.php' SQL Injection
  162. [webapps] ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization
  163. [local] ASUS GiftBox Desktop 1.1.1.127 - 'ASUSGiftBoxDesktop' Unquoted Service Path
  164. [local] Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Pat
  165. [local] Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Se
  166. [local] SpyHunter 4 - 'SpyHunter 4 Service' Unquoted Service Path
  167. [remote] netkit-telnet-0.17 telnetd (Fedora 31) - 'BraveStarr' Remote Code Execution
  168. [remote] Exchange Control Panel - Viewstate Deserialization (Metasploit)
  169. [remote] EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
  170. [webapps] UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
  171. [webapps] Alfresco 5.2.4 - Persistent Cross-Site Scripting
  172. [webapps] GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
  173. [webapps] RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
  174. [webapps] RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
  175. [webapps] Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
  176. [webapps] TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
  177. [remote] Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
  178. [webapps] Wing FTP Server 6.2.5 - Privilege Escalation
  179. [webapps] TP LINK TL-WR849N - Remote Code Execution
  180. [remote] CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
  181. [webapps] Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
  182. [webapps] Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
  183. [local] Wing FTP Server 6.2.3 - Privilege Escalation
  184. [webapps] Joplin Desktop 1.0.184 - Cross-Site Scripting
  185. [local] Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
  186. [webapps] Netis WF2419 2.2.36123 - Remote Code Execution
  187. [webapps] qdPM < 9.1 - Remote Code Execution
  188. [webapps] Cacti 1.2.8 - Authenticated Remote Code Execution
  189. [webapps] Cacti 1.2.8 - Unauthenticated Remote Code Execution
  190. [webapps] Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
  191. [webapps] Comtrend VR-3033 - Command Injection
  192. [webapps] Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
  193. [remote] OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
  194. [webapps] GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
  195. [remote] OpenSMTPD 6.6.3 - Arbitrary File Read
  196. [dos] Core FTP LE 2.2 - Denial of Service (PoC)
  197. [webapps] PhpIX 2012 Professional - 'id' SQL Injection
  198. [dos] Odin Secure FTP Expert 7.6.3 - Denial of Service (PoC)
  199. [webapps] WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Proc
  200. [webapps] Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypas
  201. [dos] SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
  202. [dos] aSc TimeTables 2020.11.4 - Denial of Service (PoC)
  203. [local] Android Binder - Use-After-Free (Metasploit)
  204. [remote] Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Met
  205. [local] Diamorphine Rootkit - Signal Privilege Escalation (Metasploit)
  206. [webapps] Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
  207. [webapps] Cacti 1.2.8 - Remote Code Execution
  208. [webapps] DotNetNuke 9.5 - Persistent Cross-Site Scripting
  209. [webapps] DotNetNuke 9.5 - File Upload Restrictions Bypass
  210. [webapps] ManageEngine EventLog Analyzer 10.0 - Information Disclosure
  211. [dos] Go SSH servers 0.0.2 - Denial of Service (PoC)
  212. [webapps] eLection 2.0 - 'id' SQL Injection
  213. [dos] Quick N Easy Web Server 3.3.8 - Denial of Service (PoC)
  214. [webapps] CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
  215. [webapps] AMSS++ 4.7 - Backdoor Admin Account
  216. [webapps] SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure
  217. [webapps] ATutor 2.2.4 - 'id' SQL Injection
  218. [webapps] I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure
  219. [webapps] Real Web Pentesting Tutorial Step by Step - [Persian]
  220. [webapps] AMSS++ v 4.31 - 'id' SQL Injection
  221. [webapps] SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure
  222. [webapps] Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripti
  223. [webapps] ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure
  224. [webapps] Easy2Pilot 7 - Cross-Site Request Forgery (Add User)
  225. [dos] Core FTP Lite 1.3 - Denial of Service (PoC)
  226. [webapps] Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
  227. [webapps] Virtual Freer 1.58 - Remote Command Execution
  228. [webapps] DBPower C300 HD Camera - Remote Configuration Disclosure
  229. [webapps] WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
  230. [remote] Anviz CrossChex - Buffer Overflow (Metasploit)
  231. [webapps] LabVantage 8.3 - Information Disclosure
  232. [webapps] SOPlanning 1.45 - Cross-Site Request Forgery (Add User)
  233. [local] Cuckoo Clock v5.0 - Buffer Overflow
  234. [webapps] SOPlanning 1.45 - 'users' SQL Injection
  235. [webapps] Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
  236. [webapps] WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
  237. [local] TFTP Turbo 4.6.1273 - 'TFTP Turbo 4' Unquoted Service Path
  238. [local] MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation
  239. [local] DHCP Turbo 4.61298 - 'DHCP Turbo 4' Unquoted Service Path
  240. [local] HP System Event 1.2.9.0 - 'HPWMISVC' Unquoted Service Path
  241. [webapps] Wordpress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripti
  242. [webapps] Avaya Aura Communication Manager 5.2 - Remote Code Execution
  243. [local] BOOTP Turbo 2.0.1214 - 'BOOTP Turbo' Unquoted Service Path
  244. [webapps] SOPlanning 1.45 - 'by' SQL Injection
  245. [local] Windows Kernel - Information Disclosure
  246. [local] PHP 7.0 < 7.4 (Unix) - 'debug_backtrace' disable_functions Bypass
  247. [local] SprintWork 2.3.1 - Local Privilege Escalation
  248. [local] HomeGuard Pro 9.3.1 - Insecure Folder Permissions
  249. [local] EPSON EasyMP Network Projection 2.81 - 'EMP_NSWLSV' Unquoted Service Path
  250. [webapps] phpMyChat Plus 1.98 - 'pmc_username' SQL Injection