المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63

  1. [webapps] Navigate CMS 2.8.7 - Cross-Site Request Forgery (Add Admin)
  2. [webapps] VMWAre vCloud Director 9.7.0.15498291 - Remote Code Execution
  3. [webapps] Oriol Espinal CMS 1.0 - 'id' SQL Injection
  4. [webapps] Clinic Management System 1.0 - Authenticated Arbitrary File Upload
  5. [webapps] Navigate CMS 2.8.7 - ''sidx' SQL Injection (Authenticated)
  6. [webapps] Clinic Management System 1.0 - Unauthenticated Remote Code Execution
  7. [webapps] Hostel Management System 2.0 - 'id' SQL Injection (Unauthenticated)
  8. [local] IObit Uninstaller 9.5.0.15 - 'IObit Uninstaller Service' Unquoted Service Pat
  9. [webapps] AirControl 1.4.2 - PreAuth Remote Code Execution
  10. [remote] vCloud Director 9.7.0.15498291 - Remote Code Execution
  11. [webapps] OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated)
  12. [webapps] Clinic Management System 1.0 - Authentication Bypass
  13. [remote] Microsoft Windows - 'SMBGhost' Remote Code Execution
  14. [webapps] QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
  15. [webapps] VMware vCenter Server 6.7 - Authentication Bypass
  16. [webapps] Wordpress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
  17. [webapps] Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass
  18. [webapps] WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete
  19. [webapps] QNAP QTS and Photo Station 6.0.3 - Remote Command Execution
  20. [webapps] NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection
  21. [webapps] Online-Exam-System 2015 - 'fid' SQL Injection
  22. [webapps] EyouCMS 1.4.6 - Persistent Cross-Site Scripting
  23. [webapps] Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting
  24. [webapps] LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting
  25. [webapps] osTicket 1.14.1 - 'Ticket Queue' Persistent Cross-Site Scripting
  26. [webapps] osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting
  27. [webapps] Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting
  28. [webapps] OXID eShop 6.3.4 - 'sorting' SQL Injection
  29. [dos] BIND - 'TSIG' Denial of Service
  30. [local] StreamRipper32 2.6 - Buffer Overflow (PoC)
  31. [webapps] Joomla! Plugin XCloner Backup 3.5.3 - Local File Inclusion (Authenticated)
  32. [webapps] Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
  33. [webapps] WordPress Plugin Drag and Drop File Upload Contact Form 1.3.3.2 - Remote Co
  34. [webapps] OpenEMR 5.0.1 - Remote Code Execution
  35. [webapps] Open-AudIT 3.3.0 - Reflective Cross-Site Scripting (Authenticated)
  36. [remote] Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
  37. [remote] Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploi
  38. [local] GoldWave - Buffer Overflow (SEH Unicode)
  39. [webapps] Victor CMS 1.0 - 'add_user' Persistent Cross-Site Scripting
  40. [webapps] Online Discussion Forum Site 1.0 - Remote Code Execution
  41. [webapps] Wordpress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated)
  42. [remote] WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metas
  43. [webapps] Gym Management System 1.0 - Unauthenticated Remote Code Execution
  44. [local] Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
  45. [webapps] Dolibarr 11.0.3 - Persistent Cross-Site Scripting
  46. [dos] Filetto 1.0 - 'FEAT' Denial of Service (PoC)
  47. [local] VUPlayer 2.49 .m3u - Local Buffer Overflow (DEP,ASLR)
  48. [dos] Konica Minolta FTP Utility 1.0 - 'NLST' Denial of Service (PoC)
  49. [dos] Konica Minolta FTP Utility 1.0 - 'LIST' Denial of Service (PoC)
  50. [local] CloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)
  51. [webapps] PHPFusion 9.03.50 - Persistent Cross-Site Scripting
  52. [webapps] Composr CMS 10.0.30 - Persistent Cross-Site Scripting
  53. [webapps] OpenEDX platform Ironwood 2.5 - Remote Code Execution
  54. [dos] AbsoluteTelnet 11.21 - 'Username' Denial of Service (PoC)
  55. [webapps] forma.lms 5.6.40 - Cross-Site Request Forgery (Change Admin Email)
  56. [webapps] CraftCMS 3 vCard Plugin 1.0.0 - Remote Code Execution
  57. [webapps] Victor CMS 1.0 - Authenticated Arbitrary File Upload
  58. [remote] Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
  59. [webapps] NukeViet VMS 4.4.00 - Cross-Site Request Forgery (Change Admin Password)
  60. [webapps] Submitty 20.04.01 - Persistent Cross-Site Scripting
  61. [webapps] php-fusion 9.03.50 - 'ctype' SQL Injection
  62. [webapps] qdPM 9.1 - 'cfg[app_app_name]' Persistent Cross-Site Scripting
  63. [webapps] Victor CMS 1.0 - 'cat_id' SQL Injection
  64. [webapps] Victor CMS 1.0 - 'comment_author' Persistent Cross-Site Scripting
  65. [webapps] Online Healthcare management system 1.0 - Authentication Bypass
  66. [remote] HP LinuxKI 6.01 - Remote Command Injection
  67. [webapps] Oracle Hospitality RES 3700 5.7 - Remote Code Execution
  68. [webapps] forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting
  69. [webapps] Monstra CMS 3.0.4 - Authenticated Arbitrary File Upload
  70. [webapps] online Chatting System 1.0 - 'id' SQL Injection
  71. [webapps] Online Healthcare Patient Record Management System 1.0 - Authentication Byp
  72. [webapps] Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
  73. [webapps] Wordpress Plugin Ajax Load More 5.3.1 - '#1' Authenticated SQL Injection
  74. [webapps] Online Examination System 1.0 - 'eid' SQL Injection
  75. [webapps] ManageEngine Service Desk 10.0 - Cross-Site Scripting
  76. [webapps] vBulletin 5.6.1 - 'nodeId' SQL Injection
  77. [webapps] E-Commerce System 1.0 - Unauthenticated Remote Code Execution
  78. [webapps] Netlink XPON 1GE WiFi V2801RGW - Remote Command Execution
  79. [local] Dameware Remote Support 12.1.1.273 - Buffer Overflow (SEH)
  80. [webapps] Complaint Management System 1.0 - 'username' SQL Injection
  81. [webapps] Tryton 5.4 - Persistent Cross-Site Scripting
  82. [webapps] Sellacious eCommerce 4.6 - Persistent Cross-Site Scripting
  83. [local] Remote Desktop Audit 2.3.0.157 - Buffer Overflow (SEH)
  84. [webapps] TylerTech Eagle 2018.3.11 - Remote Code Execution
  85. [local] MacOS 320.whatis Script - Privilege Escalation
  86. [local] LanSend 3.2 - Buffer Overflow (SEH)
  87. [webapps] CuteNews 2.1.2 - Authenticated Arbitrary File Upload
  88. [webapps] Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site S
  89. [webapps] qdPM 9.1 - Arbitrary File Upload
  90. [webapps] ChopSlider3 Wordpress Plugin3.4 - 'id' SQL Injection
  91. [webapps] Orchard Core RC1 - Persistent Cross-Site Scripting
  92. [webapps] Phase Botnet - Blind SQL Injection
  93. [webapps] OpenZ ERP 3.6.60 - Persistent Cross-Site Scripting
  94. [webapps] Victor CMS 1.0 - 'post' SQL Injection
  95. [webapps] Complaint Management System 1.0 - Authentication Bypass
  96. [webapps] LibreNMS 1.46 - 'search' SQL Injection
  97. [webapps] CuteNews 2.1.2 - Arbitrary File Deletion
  98. [local] SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
  99. [webapps] Online AgroCulture Farm Management System 1.0 - 'uname' SQL Injection
  100. [webapps] Kartris 1.6 - Arbitrary File Upload
  101. [webapps] Sentrifugo CMS 3.2 - Persistent Cross-Site Scripting
  102. [webapps] Pi-hole < 4.4 - Remote Code Execution
  103. [webapps] Pi-hole < 4.4 - Remote Code Execution / Privileges Escalation
  104. [dos] Extreme Networks Aerohive HiveOS 11.0 - Remote Denial of Service (PoC)
  105. [webapps] Draytek VigorAP 1000C - Persistent Cross-Site Scripting
  106. [webapps] School File Management System 1.0 - 'username' SQL Injection
  107. [webapps] Online Clothing Store 1.0 - Arbitrary File Upload
  108. [webapps] Pisay Online E-Learning System 1.0 - Remote Code Execution
  109. [webapps] Online AgroCulture Farm Management System 1.0 - 'pid' SQL Injection
  110. [dos] FlashGet 1.9.6 - Denial of Service (PoC)
  111. [webapps] Car Park Management System 1.0 - Authentication Bypass
  112. [webapps] GitLab 12.9.0 - Arbitrary File Read
  113. [webapps] YesWiki cercopitheque 2020.04.18.1 - 'id' SQL Injection
  114. [webapps] MPC Sharj 3.11.1 - Arbitrary File Download
  115. [webapps] Online Clothing Store 1.0 - Persistent Cross-Site Scripting
  116. [webapps] i-doit Open Source CMDB 1.14.1 - Arbitrary File Deletion
  117. [webapps] Booked Scheduler 2.7.7 - Authenticated Directory Traversal
  118. [webapps] Online Clothing Store 1.0 - 'username' SQL Injection
  119. [webapps] webTareas 2.0.p8 - Arbitrary File Deletion
  120. [webapps] NEC Electra Elite IPK II WebPro 01.03.01 - Session Enumeration
  121. [webapps] SimplePHPGal 0.7 - Remote File Inclusion
  122. [webapps] Fishing Reservation System 7.5 - 'uid' SQL Injection
  123. [local] Oracle Database 11g Release 2 - 'OracleDBConsoleorcl' Unquoted Service Path
  124. [webapps] Online Scheduling System 1.0 - 'username' SQL Injection
  125. [webapps] webERP 4.15.1 - Unauthenticated Backup File Access
  126. [remote] Saltstack 3000.2 - Remote Code Execution
  127. [webapps] BlogEngine 3.3 - 'syndication.axd' XML External Entity Injection
  128. [webapps] PhreeBooks ERP 5.2.5 - Remote Command Execution
  129. [webapps] osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
  130. [local] Outline Service 1.3.3 - 'Outline Service ' Unquoted Service Path
  131. [local] Frigate 3.36 - Buffer Overflow (SEH)
  132. [webapps] addressbook 9.0.0.1 - 'id' SQL Injection
  133. [webapps] BoltWire 6.03 - Local File Inclusion
  134. [remote] Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
  135. [webapps] HardDrive 2.1 for iOS - Arbitrary File Upload
  136. [webapps] Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
  137. [webapps] Online Scheduling System 1.0 - Authentication Bypass
  138. [webapps] Online Scheduling System 1.0 - Persistent Cross-Site Scripting
  139. [webapps] php-fusion 9.03.50 - Persistent Cross-Site Scripting
  140. [webapps] Super Backup 2.0.5 for iOS - Directory Traversal
  141. [webapps] ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
  142. [dos] VirtualTablet Server 3.0.2 - Denial of Service (PoC)
  143. [local] EmEditor 19.8 - Insecure File Permissions
  144. [webapps] hits script 1.0 - 'item_name' SQL Injection
  145. [local] Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
  146. [remote] Nexus Repository Manager - Java EL Injection RCE (Metasploit)
  147. [local] Code Blocks 16.01 - Buffer Overflow (SEH) UNICODE
  148. [webapps] Centreon 19.10.5 - 'id' SQL Injection
  149. [local] Atomic Alarm Clock 6.3 - Stack Overflow (Unicode+SEH)
  150. [webapps] Fork CMS 5.8.0 - Persistent Cross-Site Scripting
  151. [local] Nsauditor 3.2.1.0 - Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))
  152. [local] Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH)
  153. [local] Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path
  154. [remote] Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
  155. [webapps] CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
  156. [webapps] PMB 5.6 - 'logid' SQL Injection
  157. [webapps] CSZ CMS 1.2.7 - 'title' HTML Injection
  158. [webapps] IQrouter 3.3.1 Firmware - Remote Code Execution
  159. [local] Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
  160. [webapps] NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
  161. [webapps] jizhi CMS 1.6.7 - Arbitrary File Download
  162. [webapps] P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
  163. [remote] Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
  164. [local] RM Downloader 3.1.3.2.2010.06.13 - 'Load' Buffer Overflow (SEH)
  165. [webapps] Edimax EW-7438RPn - Information Disclosure (WiFi Password)
  166. [webapps] Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
  167. [webapps] Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
  168. [webapps] User Management System 2.0 - Persistent Cross-Site Scripting
  169. [webapps] User Management System 2.0 - Authentication Bypass
  170. [webapps] Complaint Management System 4.2 - Persistent Cross-Site Scripting
  171. [webapps] Complaint Management System 4.2 - Authentication Bypass
  172. [webapps] Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
  173. [webapps] Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
  174. [webapps] Sky File 2.1.0 iOS - Directory Traversal
  175. [webapps] EspoCRM 5.8.5 - Privilege Escalation
  176. [webapps] Edimax EW-7438RPn 1.13 - Remote Code Execution
  177. [local] Popcorn Time 6.2 - 'Update service' Unquoted Service Path
  178. [webapps] Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
  179. [webapps] PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
  180. [webapps] Netis E1+ 1.2.32533 - Backdoor Account (root)
  181. [webapps] Online shopping system advanced 1.0 - 'p' SQL Injection
  182. [webapps] Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
  183. [webapps] Online Course Registration 2.0 - Authentication Bypass
  184. [webapps] Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
  185. [local] Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
  186. [local] Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
  187. [remote] CloudMe 1.11.2 - Buffer Overflow (PoC)
  188. [webapps] School ERP Pro 1.0 - 'es_messagesid' SQL Injection
  189. [local] NVIDIA Update Service Daemon 1.0.21 - 'nvUpdatusService' Unquoted Service Pa
  190. [webapps] School ERP Pro 1.0 - Remote Code Execution
  191. [webapps] Open-AudIT Professional 3.3.1 - Remote Code Execution
  192. [webapps] School ERP Pro 1.0 - Arbitrary File Read
  193. [webapps] Easy Transfer 1.7 for iOS - Directory Traversal
  194. [local] Andrea ST Filters Service 1.0.64.7 - 'Andrea ST Filters Service ' Unquoted
  195. [local] Internet Download Manager 6.37.11.1 - Stack Buffer Overflow (PoC)
  196. [remote] ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
  197. [remote] Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
  198. [remote] PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metas
  199. [remote] DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
  200. [local] VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
  201. [remote] Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
  202. [remote] TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit
  203. [remote] Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
  204. [webapps] DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
  205. [webapps] File Transfer iFamily 2.1 - Directory Traversal
  206. [webapps] Xeroneit Library Management System 3.0 - 'category' SQL Injection
  207. [local] BlazeDVD 7.0.2 - Buffer Overflow (SEH)
  208. [webapps] Pinger 1.0 - Remote Code Execution
  209. [webapps] SeedDMS 5.1.18 - Persistent Cross-Site Scripting
  210. [webapps] Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
  211. [webapps] AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
  212. [webapps] SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
  213. [webapps] Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
  214. [webapps] WSO2 3.1.0 - Persistent Cross-Site Scripting
  215. [webapps] Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
  216. [local] B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)
  217. [webapps] MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
  218. [webapps] TVT NVMS 1000 - Directory Traversal
  219. [webapps] Webtateas 2.0 - Arbitrary File Read
  220. [webapps] WSO2 3.1.0 - Arbitrary File Delete
  221. [local] Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (S
  222. [webapps] Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
  223. [webapps] Huawei HG630 2 Router - Authentication Bypass
  224. [webapps] Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
  225. [dos] AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
  226. [local] Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
  227. [webapps] Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
  228. [webapps] Django 3.0 - Cross-Site Request Forgery Token Bypass
  229. [dos] dnsmasq-utils 2.79-1 - 'dhcp_release' Denial of Service (PoC)
  230. [dos] ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
  231. [local] Microsoft NET USE win10 - Insufficient Authentication Logic
  232. [webapps] pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
  233. [webapps] Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metaspl
  234. [webapps] WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
  235. [webapps] Bolt CMS 3.7.0 - Authenticated Remote Code Execution
  236. [webapps] LimeSurvey 4.1.11 - 'File Manager' Path Traversal
  237. [dos] UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)
  238. [webapps] LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
  239. [dos] UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)
  240. [dos] UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)
  241. [dos] ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)
  242. [local] Triologic Media Player 8 - '.m3l' Buffer Overflow (Unicode) (SEH)
  243. [dos] SpotAuditor 5.3.4 - 'Name' Denial of Service (PoC)
  244. [dos] Nsauditor 3.2.0.0 - 'Name' Denial of Service (PoC)
  245. [dos] Frigate 3.36 - Denial of Service (PoC)
  246. [local] Memu Play 7.1.3 - Insecure Folder Permissions
  247. [dos] Product Key Explorer 4.2.2.0 - 'Key' Denial of Service (PoC)
  248. [webapps] Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
  249. [local] AIDA64 Engineer 6.20.5300 - 'Report File' filename Buffer Overflow (SEH)
  250. [local] DiskBoss 7.7.14 - 'Input Directory' Local Buffer Overflow (PoC)