- [webapps] gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
- [remote] Xplico - Remote Code Execution (Metasploit)
- [remote] Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)
- [remote] Iopsys Router - 'dhcp' Remote Code Execution
- [local] Multiple CPUs - 'Spectre' Information Disclosure (PoC)
- [papers] Spectre - Trick Error-Free Applications Into Giving Up Secret Information
- [papers] Meltdown - Bypass Intel's Hardware Barrier Between Applications And The Comp
- [papers] Fortinet FortiClient - Local Privilege Escalation
- [papers] PoC || GTFO 0x17
- [papers] [Hebrew] Digital Whisper Security Magazine #90
- [webapps] EMC xPression 4.5SP1 Patch 13 - 'model.jobHistoryId' SQL Injection
- [local] Kingsoft Antivirus/Internet Security 9+ - Privilege Escalation
- [webapps] WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass
- [papers] Fortinet FortiClient - Local Privilege Escalation
- [local] Linux Kernel < 4.4.0-83 / < 4.8.0-58 (Ubuntu 14.04/16.04) - Local Privilege E
- [papers] PoC || GTFO 0x17
- [papers] [Hebrew] Digital Whisper Security Magazine #90
- [dos] Apple macOS - IOHIDSystem Kernel Read/Write
- [webapps] Huawei Router HG532 - Arbitrary Command Execution
- [remote] Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)
- [remote] Cambium ePMP1000 - 'ping' Shell via Command Injection (Metasploit)
- [remote] HP Mercury LoadRunner Agent magentproc.exe - Remote Command Execution (Metas
- [dos] D3DGear 5.00 Build 2175 - Buffer Overflow
- [webapps] PHP Melody 2.7.1 - 'playlist' SQL Injection
- [remote] NetTransport 2.96L - Buffer Overflow (DEP Bypass)
- [remote] ALLMediaServer 0.95 - Buffer Overflow (Metasploit)
- [dos] ALLMediaServer 0.95 - Buffer Overflow
- [webapps] DotNetNuke DreamSlider 01.01.02 - Arbitrary File Download
- [webapps] Xerox DC260 EFI Fiery Controller Webtools 2.0 - Arbitrary File Disclosure
- [dos] SysGauge Server 3.6.18 - Denial of Service
- [webapps] Telesquare SKT LTE Router SDT-CS3B1 - Information Disclosure
- [dos] Telesquare SKT LTE Router SDT-CS3B1 - Denial of Service
- [webapps] Telesquare SKT LTE Router SDT-CS3B1 - Cross-Site Request Forgery
- [local] Sony Playstation 4 4.05 FW - Local Kernel Exploit
- [webapps] SilverStripe CMS 3.6.2 - CSV Excel Macro Injection
- [webapps] Sendroid < 6.5.0 - SQL Injection
- [webapps] Biometric Shift Employee Management System 3.0 - Local File Disclosure
- [webapps] Joomla! Component JEXTN FAQ Pro 4.0.0 - 'id' SQL Injection
- [dos] GetGo Download Manager 5.3.0.2712 - Buffer Overflow
- [local] Ubiquiti UniFi Video 3.7.3 - Local Privilege Escalation
- [remote] COMTREND ADSL Router CT-5367 - Remote Code Execution
- [remote] Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosur
- [remote] Netcore / Netis Routers - UDP Backdoor
- [remote] Fortinet FortiGate 4.x < 5.0.7 - SSH Backdoor
- [remote] Technicolor DPC3928SL - SNMP Authentication Bypass
- [remote] Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Requ
- [local] Ruby < 2.2.8 / < 2.3.5 / < 2.4.2 / < 2.5.0-preview1 - 'NET::Ftp' Command Inje
- [webapps] Conarc iChannel - Improper Access Restrictions
- [dos] Microsoft Windows Kernel - 'NtQueryVirtualMemory(MemoryMappedFilenameInformat io
- [webapps] BEIMS ContractorWeb 5.18.0.0 - SQL Injection
- [webapps] Ability Mail Server 3.3.2 - Cross-Site Scripting
- [remote] Samsung Internet Browser - SOP Bypass (Metasploit)
- [remote] Jenkins - XStream Groovy classpath Deserialization (Metasploit)
- [remote] Tuleap 9.6 - Second-Order PHP Object Injection (Metasploit)
- [dos] Intel Content Protection HECI Service - Type Confusion Privilege Escalation
- [dos] Microsoft Windows - 'jscript!RegExpFncObj::LastParen' Out-of-Bounds Read
- [dos] Microsoft Windows - 'jscript!JsArraySlice' Uninitialized Variable
- [dos] Microsoft Windows - jscript.dll 'Array.sort' Heap Overflow
- [dos] Microsoft Windows - 'jscript!RegExpComp::Compile' Heap Overflow Through IE or L
- [dos] Microsoft Internet Explorer 11 - 'jscript!JSONStringifyObject' Use-After-Free
- [dos] Microsoft Windows - 'jscript!NameTbl::GetValDef' Use-After-Free
- [local] TeamViewer 11 < 13 (Windows 10 x86) - Inline Hooking / Direct Memory Modifica
- [webapps] Joomla! Component NextGen Editor 2.1.0 - 'plname' SQL Injection
- [webapps] BrightSign Digital Signage - Multiple Vulnerablities
- [webapps] Linksys WVBR0 - 'User-Agent' Remote Command Injection
- [webapps] vBulletin 5 - 'cacheTemplates' Unauthenticated Remote Arbitrary File Deleti
- [webapps] vBulletin 5 - 'routestring' Unauthenticated Remote Code Execution
- [remote] GoAhead httpd 2.5 < 3.6.5 - 'LD_PRELOAD' Remote Code Execution
- [local] Firejail < 0.9.44.4 / < 0.9.38.8 LTS - Local Sandbox Escape
- [webapps] Joomla! Component My Projects 2.0 - SQL Injection
- [webapps] Joomla! Component User Bench 1.0 - 'userid' SQL Injection
- [remote] Western Digital MyCloud - 'multi_uploadify' File Upload (Metasploit)
- [dos] Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow
- [dos] Zoom Linux Client 2.0.106600.0904 - Command Injection
- [remote] Outlook for Android - Attachment Download Directory Traversal
- [dos] CDex 1.96 - Buffer Overflow
- [local] Linux kernel < 4.10.15 - Race Condition Privilege Escalation
- [webapps] Joomla! Component Guru Pro - 'promocode' SQL Injection
- [webapps] Joomla! Component JB Visa 1.0 - 'visatype' SQL Injection
- [webapps] Monstra CMS 3.0.4 - Arbitrary File Upload / Remote Code Execution
- [webapps] Movie Guide 2.0 - SQL Injection
- [dos] Sync Breeze 10.2.12 - Denial of Service
- [webapps] ITGuard-Manager 0.0.0.1 - Remote Code Execution
- [remote] pfSense 2.4.1 - CSRF Error Page Clickjacking (Metasploit)
- [remote] Palo Alto Networks Firewalls - Remote root Code Execution
- [webapps] Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Bu
- [remote] Dup Scout Enterprise - Login Buffer Overflow (Metasploit)
- [remote] Microsoft Office - DDE Payload Delivery (Metasploit)
- [webapps] Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
- [webapps] Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection
- [webapps] Readymade Video Sharing Script 3.2 - HTML Injection
- [webapps] FS Lynda Clone 1.0 - SQL Injection
- [webapps] Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection
- [webapps] Bus Booking Script 1.0 - 'txtname' SQL Injection
- [webapps] Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
- [local] glibc ld.so - Memory Leak / Buffer Overflow
- [webapps] Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
- [dos] Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usag
- [dos] macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifet
- [dos] macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapri
- [dos] macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket
- [webapps] Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
- [webapps] Accesspress Anonymous Post Pro < 3.2.0 - Unauthenticated Arbitrary File Upl
- [dos] iOS/macOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MI
- [dos] macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Ker
- [dos] LibTIFF pal2rgb 4.0.9 - Heap Buffer Overflow
- [dos] macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
- [dos] macOS - 'getrusage' Stack Leak Through struct Padding
- [dos] MikroTik 6.40.5 ICMP - Denial of Service
- [webapps] Vanguard 1.4 - SQL Injection
- [webapps] Resume Clone Script 2.0.5 - SQL Injection
- [webapps] Advanced World Database 2.0.5 - SQL Injection
- [webapps] Vanguard 1.4 - Arbitrary File Upload
- [webapps] Basic Job Site Script 2.0.5 - SQL Injection
- [webapps] Car Rental Script 2.0.4 - 'val' SQL Injection
- [webapps] Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
- [webapps] MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
- [webapps] Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
- [webapps] MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
- [webapps] Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection
- [webapps] Advanced Real Estate Script 4.0.7 - SQL Injection
- [webapps] Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
- [webapps] Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
- [webapps] Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQ
- [webapps] Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
- [webapps] Entrepreneur Dating Script 2.0.1 - 'marital' / 'gender' / 'country' / 'prof
- [webapps] PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
- [webapps] Professional Service Script 1.0 - 'service-list?city' SQL Injection
- [webapps] Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
- [webapps] Readymade Video Sharing Script 3.2 - SQL Injection
- [webapps] Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
- [webapps] Multivendor Penny Auction Clone Script 1.0 - SQL Injection
- [webapps] Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
- [webapps] Opensource Classified Ads Script 3.2 - SQL Injection
- [webapps] Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
- [webapps] Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
- [webapps] Laundry Booking Script 1.0 - 'list?city' SQL Injection
- [webapps] Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
- [webapps] Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
- [webapps] Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
- [webapps] Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
- [webapps] Food Order Script 1.0 - 'list?city' SQL Injection
- [webapps] Yoga Class Script 1.0 - 'list?city' SQL Injection
- [webapps] Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
- [webapps] Entrepreneur Job Portal Script 2.0.6 - 'jobsearch_all.php?rid1' SQL Injecti
- [webapps] Consumer Complaints Clone Script 1.0 - 'id' SQL Injection
- [webapps] Doctor Search Script 1.0 - 'city' SQL Injection
- [webapps] E-commerce MLM Software 1.0 - SQL Injection
- [webapps] Event Calendar Category Script 1.0 - 'city' SQL Injection
- [webapps] CMS Auditor Website 1.0 - SQL Injection
- [webapps] Co-work Space Search Script 1.0 - 'city' SQL Injection
- [webapps] Chartered Accountant Booking Script 1.0 - 'city' SQL Injection
- [webapps] Child Care Script 1.0 - 'city' SQL Injection
- [webapps] Cab Booking Script 1.0 - 'city' SQL Injection
- [webapps] Nearbuy Clone Script 3.2 - 'search' SQL Injection
- [webapps] FS Foodpanda Clone 1.0 - SQL Injection
- [webapps] Advance B2B Script 2.1.3 - 'show_id' / 'pid' SQL Injection
- [webapps] Advance Online Learning Management Script 3.1 - 'subcatid' / 'popcourseid'
- [webapps] Affiliate MLM Script 1.0 - 'product-category.php?key' SQL Injection
- [webapps] Basic B2B Script 2.0.8 - 'product_details.php?id' SQL Injection
- [webapps] Beauty Parlour Booking Script 1.0 - 'gender' / 'city' SQL Injection
- [webapps] FS Expedia Clone 1.0 - 'fl_orig' / 'fl_dest' / 'id' SQL Injection
- [webapps] FS Gigs Script 1.0 - 'cat' / 'sc' SQL Injection
- [webapps] FS Freelancer Clone 1.0 - 'profile.php?u' SQL Injection
- [webapps] FS Ebay Clone 1.0 - 'id' / 'sub_category_id' / 'category_id' SQL Injection
- [webapps] FS Crowdfunding Script 1.0 - 'latest_news_details.php?id' SQL Injection
- [webapps] FS Care Clone 1.0 - 'jobFrequency' / 'jobType' SQL Injection
- [webapps] FS Amazon Clone 1.0 - SQL Injection
- [webapps] FS Trademe Clone 1.0 - 'search' / 'id' SQL Injection
- [webapps] FS Indiamart Clone 1.0 - 'token' / 'id' / 'c' SQL Injection
- [webapps] FS IMDB Clone 1.0 - 'f' / 's' / 'id' SQL Injection
- [webapps] FS Linkedin Clone 1.0 - 'grid' / 'fid' / 'id' SQL Injection
- [webapps] FS Grubhub Clone 1.0 - 'keywords' SQL Injection
- [webapps] FS Groupon Clone 1.0 - 'id' SQL Injection
- [webapps] FS Makemytrip Clone 1.0 - 'fl_orig' / 'fl_dest' SQL Injection
- [local] Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation
- [local] Apple macOS 10.13.1 (High Sierra) - Insecure Cron System Local Privilege Esca
- [webapps] FS Quibids Clone 1.0 - SQL Injection
- [webapps] FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection
- [webapps] FS Monster Clone 1.0 - 'Employer_Details.php?id' SQL Injection
- [webapps] Realestate Crowdfunding Script 2.7.2 - 'pid' SQL Injection
- [webapps] FS Thumbtack Clone 1.0 - 'cat' / 'sc' SQL Injection
- [webapps] FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection
- [webapps] FS Shutterstock Clone 1.0 - 'keywords' SQL Injection
- [webapps] Simple Chatting System 1.0.0 - Arbitrary File Upload
- [webapps] Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection
- [webapps] DomainSale PHP Script 1.0 - 'id' SQL Injection
- [remote] LabF nfsAxe FTP Client 3.7 - Buffer Overflow (DEP Bypass)
- [dos] Wireshark 2.4.0 - 2.4.2 / 2.2.0 - 2.2.10 - CIP Safety Dissector Crash
- [dos] Linux Kernel - DCCP Socket Use-After-Free
- [remote] Polycom Shell HDX Series - Traceroute Command Execution (Metasploit)
- [remote] Claymore Dual ETH + DCR/SC/LBC/PASC GPU Miner - Stack Buffer Overflow / Path
- [webapps] OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting
- [remote] LaCie 5big Network 2.2.8 - Command Injection
- [webapps] FS IMDB Clone - 'id' SQL Injection
- [webapps] FS Facebook Clone - 'token' SQL Injection
- [dos] Microsoft Windows Defender - Controlled Folder Bypass Through UNC Path
- [local] Hashicorp vagrant-vmware-fusion 5.0.0 - Local root Privilege Escalation
- [local] Hashicorp vagrant-vmware-fusion 4.0.24 - Local root Privilege Escalation
- [local] Hashicorp vagrant-vmware-fusion 4.0.23 - Local root Privilege Escalation
- [local] Proxifier for Mac 2.19 - Local root Privilege Escalation
- [local] Arq 5.9.7 - Local root Privilege Escalation
- [local] Murus 1.4.11 - Local root Privilege Escalation
- [local] Arq 5.9.6 - Local root Privilege Escalation
- [local] Hashicorp vagrant-vmware-fusion 5.0.3 - Local root Privilege Escalation
- [local] Sera 1.2 - Local root Privilege Escalation / Password Disclosure
- [local] Hashicorp vagrant-vmware-fusion 5.0.1 - Local root Privilege Escalation
- [webapps] FS Makemytrip Clone - 'id' SQL Injection
- [webapps] WinduCMS 3.1 - Local File Disclosure
- [webapps] FS Shaadi Clone - 'token' SQL Injection
- [webapps] Readymade Classifieds Script 1.0 - SQL Injection
- [webapps] Techno Portfolio Management Panel - 'id' SQL Injection
- [remote] VX Search 10.2.14 - 'command_name' Buffer Overflow
- [local] Perspective ICM Investigation & Case 5.1.1.16 - Privilege Escalation
- [dos] Abyss Web Server < 2.11.6 - Heap Memory Corruption
- [remote] HP iMC Plat 7.2 - Remote Code Execution (2)
- [webapps] Jobs2Careers / Coroflot Clone - SQL Injection
- [papers] [Hebrew] Digital Whisper Security Magazine #89
- [webapps] Artica Web Proxy 3.06 - Remote Code Execution
- [webapps] MistServer 2.12 - Cross-Site Scripting
- [remote] HP iMC Plat 7.2 - Remote Code Execution
- [local] macOS High Sierra - Root Privilege Escalation (Metasploit)
- [dos] Asterisk 13.17.2 - Memory Corruption
- [dos] Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page
- [webapps] WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal
- [dos] QEMU - Stack Buffer Overflow in NBD Server Triggered via Long Export Name
- [remote] pfSense - Authenticated Group Member RCE (Metasploit)
- [local] Microsoft Windows 10 Creators Update (version 1703) (x86) - 'WARBIRD' 'NtQuer
- [webapps] osCommerce 2.3.4.1 - Arbitrary File Upload
- [webapps] Synology StorageManager 5.2 - Remote Root Command Execution
- [dos] Android Gmail < 7.11.5.176568039 - Directory Traversal in Attachment Download
- [webapps] ZTE ZXDSL 831CII - Improper Access Restrictions
- [local] Diving Log 6.0 - XML External Entity Injection
- [dos] KMPlayer 4.2.2.4 - Denial of Service
- [dos] Winamp Pro 5.66.Build.3512 - Denial of Service
- [dos] Exim 4.89 - 'BDAT' Denial of Service
- [dos] Microsoft Edge Chakra JIT - 'BailOutOnTaggedValue' Bailouts Type Confusion
- [dos] Microsoft Edge Chakra JIT - 'Inline::InlineCallApplyTarget_Shared' does not Ret
- [dos] Microsoft Edge Chakra JIT - Incorrect Function Declaration Scope
- [dos] Microsoft Edge Chakra JIT - 'GlobOpt::OptTagChecks' Must Consider IsLoopPrePass
- [webapps] CommuniGatePro 6.1.16 - Cross-Site Scripting
- [local] ALLPlayer 7.5 - Local Buffer Overflow (SEH Unicode)
- [dos] Linux - 'mincore()' Uninitialized Kernel Heap Page Disclosure
- [dos] WebKit - 'WebCore::AXObjectCache::performDeferredCacheUpdat e' Use-After-Free
- [dos] WebKit - 'WebCore::RenderObject::previousSibling' Use-After-Free
- [dos] WebKit - 'WebCore::DocumentLoader::frameLoader' Use-After-Free
- [dos] WebKit - 'WebCore::FormSubmission::create' Use-After-Free
- [dos] WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoi nt' Out-of-Bounds Re
- [dos] WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
- [dos] WebKit - 'WebCore::SVGPatternElement::collectPatternAttribu tes' Out-of-Bounds R