المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 [25] 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66

  1. [local] Hashicorp vagrant-vmware-fusion 4.0.24 - Local root Privilege Escalation
  2. [local] Hashicorp vagrant-vmware-fusion 4.0.23 - Local root Privilege Escalation
  3. [local] Proxifier for Mac 2.19 - Local root Privilege Escalation
  4. [local] Arq 5.9.7 - Local root Privilege Escalation
  5. [local] Murus 1.4.11 - Local root Privilege Escalation
  6. [local] Arq 5.9.6 - Local root Privilege Escalation
  7. [local] Hashicorp vagrant-vmware-fusion 5.0.3 - Local root Privilege Escalation
  8. [local] Sera 1.2 - Local root Privilege Escalation / Password Disclosure
  9. [local] Hashicorp vagrant-vmware-fusion 5.0.1 - Local root Privilege Escalation
  10. [webapps] FS Makemytrip Clone - 'id' SQL Injection
  11. [webapps] WinduCMS 3.1 - Local File Disclosure
  12. [webapps] FS Shaadi Clone - 'token' SQL Injection
  13. [webapps] Readymade Classifieds Script 1.0 - SQL Injection
  14. [webapps] Techno Portfolio Management Panel - 'id' SQL Injection
  15. [remote] VX Search 10.2.14 - 'command_name' Buffer Overflow
  16. [local] Perspective ICM Investigation & Case 5.1.1.16 - Privilege Escalation
  17. [dos] Abyss Web Server < 2.11.6 - Heap Memory Corruption
  18. [remote] HP iMC Plat 7.2 - Remote Code Execution (2)
  19. [webapps] Jobs2Careers / Coroflot Clone - SQL Injection
  20. [papers] [Hebrew] Digital Whisper Security Magazine #89
  21. [webapps] Artica Web Proxy 3.06 - Remote Code Execution
  22. [webapps] MistServer 2.12 - Cross-Site Scripting
  23. [remote] HP iMC Plat 7.2 - Remote Code Execution
  24. [local] macOS High Sierra - Root Privilege Escalation (Metasploit)
  25. [dos] Asterisk 13.17.2 - Memory Corruption
  26. [dos] Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page
  27. [webapps] WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal
  28. [dos] QEMU - Stack Buffer Overflow in NBD Server Triggered via Long Export Name
  29. [remote] pfSense - Authenticated Group Member RCE (Metasploit)
  30. [local] Microsoft Windows 10 Creators Update (version 1703) (x86) - 'WARBIRD' 'NtQuer
  31. [webapps] osCommerce 2.3.4.1 - Arbitrary File Upload
  32. [webapps] Synology StorageManager 5.2 - Remote Root Command Execution
  33. [dos] Android Gmail < 7.11.5.176568039 - Directory Traversal in Attachment Download
  34. [webapps] ZTE ZXDSL 831CII - Improper Access Restrictions
  35. [local] Diving Log 6.0 - XML External Entity Injection
  36. [dos] KMPlayer 4.2.2.4 - Denial of Service
  37. [dos] Winamp Pro 5.66.Build.3512 - Denial of Service
  38. [dos] Exim 4.89 - 'BDAT' Denial of Service
  39. [dos] Microsoft Edge Chakra JIT - 'BailOutOnTaggedValue' Bailouts Type Confusion
  40. [dos] Microsoft Edge Chakra JIT - 'Inline::InlineCallApplyTarget_Shared' does not Ret
  41. [dos] Microsoft Edge Chakra JIT - Incorrect Function Declaration Scope
  42. [dos] Microsoft Edge Chakra JIT - 'GlobOpt::OptTagChecks' Must Consider IsLoopPrePass
  43. [webapps] CommuniGatePro 6.1.16 - Cross-Site Scripting
  44. [local] ALLPlayer 7.5 - Local Buffer Overflow (SEH Unicode)
  45. [dos] Linux - 'mincore()' Uninitialized Kernel Heap Page Disclosure
  46. [dos] WebKit - 'WebCore::AXObjectCache::performDeferredCacheUpdat e' Use-After-Free
  47. [dos] WebKit - 'WebCore::RenderObject::previousSibling' Use-After-Free
  48. [dos] WebKit - 'WebCore::DocumentLoader::frameLoader' Use-After-Free
  49. [dos] WebKit - 'WebCore::FormSubmission::create' Use-After-Free
  50. [dos] WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoi nt' Out-of-Bounds Re
  51. [dos] WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
  52. [dos] WebKit - 'WebCore::SVGPatternElement::collectPatternAttribu tes' Out-of-Bounds R
  53. [dos] WebKit - 'WebCore::RenderText::localCaretRect' Out-of-Bounds Read
  54. [dos] WebKit - 'WebCore::PositionIterator::decrement' Use-After-Free
  55. [dos] WebKit - 'WebCore::InputType::element' Use-After-Free
  56. [dos] WebKit - 'WebCore::TreeScope::documentScope' Use-After-Free
  57. [webapps] Icon Time Systems RTC-1000 Firmware 2.5.7458 - Cross-Site Scripting
  58. [dos] Vonage VDV-23 - Denial of Service
  59. [dos] Microsoft Windows 10 - 'nt!NtQueryDirectoryFile (luafv!LuafvCopyDirectoryEntry)
  60. [remote] Microsoft Office - OLE Remote Code Execution
  61. [local] Microsoft Windows 10 - CiSetFileCache TOCTOU Security Feature Bypass
  62. [dos] iOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of Service
  63. [papers] Reversing and Exploiting IoT devices
  64. [papers] [Hebrew] Digital Whisper Security Magazine #88
  65. [webapps] MyBB 1.8.13 - Remote Code Execution
  66. [webapps] MyBB 1.8.13 - Cross-Site Scripting
  67. [local] VX Search 10.2.14 - 'Proxy' Buffer Overflow (SEH)
  68. [webapps] Zeta Components Mail 1.8.1 - Remote Code Execution
  69. [dos] Microsoft Edge Chakra JIT - Type Confusion with switch Statements
  70. [dos] Microsoft Edge Chakra: JIT - 'Lowerer::LowerBoundCheck' Incorrect Integer Overf
  71. [dos] Microsoft Edge Chakra: JIT - 'OP_Memset' Type Confusion
  72. [dos] Microsoft Edge - 'Object.setPrototypeOf' Memory Corruption
  73. [webapps] Vonage VDV23 - Cross-Site Scripting
  74. [webapps] TP-Link TL-WR740N - Cross-Site Scripting
  75. [webapps] LanSweeper 6.0.100.75 - Cross-Site Scripting
  76. [dos] D-Link DIR605L - Denial of Service
  77. [webapps] D-Link DCS-936L Network Camera - Cross-Site Request Forgery
  78. [remote] Dup Scout Enterprise 10.0.18 - 'Login' Buffer Overflow
  79. [dos] Microsoft Internet Explorer 11 - 'jscript!JsErrorToString' Use-After-Free
  80. [remote] Mako Server 2.5 - OS Command Injection Remote Command Execution (Metasploit)
  81. [dos] PHP 7.1.8 - Heap-Based Buffer Overflow
  82. [remote] D-Link DIR-850L - Unauthenticated OS Command Execution (Metasploit)
  83. [dos] PSFTPd Windows FTP Server 10.0.4 Build 729 - Log Injection / Use-After-Free
  84. [remote] Wireless IP Camera (P2P) WIFICAM - Unauthenticated Remote Code Execution
  85. [remote] Ulterius Server < 1.9.5.0 - Directory Traversal
  86. [webapps] Kirby CMS < 2.5.7 - Cross-Site Scripting
  87. [local] IKARUS anti.virus 2.16.7 - 'ntguard_x64' Privilege Escalation
  88. [webapps] Web Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload
  89. [dos] Xlight FTP Server 3.8.8.5 - Buffer Overflow (PoC)
  90. [webapps] ManageEngine Applications Manager 13 - SQL Injection
  91. [local] Vir.IT eXplorer Anti-Virus 8.5.39 - 'VIAGLT64.SYS' Privilege Escalation
  92. [webapps] Ingenious School Management System 2.3.0 - 'friend_index' SQL injection
  93. [dos] WhatsApp 2.17.52 - Memory Corruption
  94. [webapps] WordPress Plugin JTRT Responsive Tables 4.1 - SQL Injection
  95. [webapps] OctoberCMS 1.0.426 (Build 426) - Cross-Site Request Forgery
  96. [local] Easy MPEG/AVI/DIVX/WMV/RM to DVD - 'Enter User Name' Buffer Overflow (SEH)
  97. [dos] GraphicsMagick - Memory Disclosure / Heap Overflow
  98. [remote] tnftp - 'savefile' Arbitrary Command Execution (Metasploit)
  99. [webapps] Ladon Framework for Python 0.9.40 - XML External Entity Expansion
  100. [webapps] Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via
  101. [dos] Ipswitch WS_FTP Professional < 12.6.0.3 - Local Buffer Overflow (SEH)
  102. [webapps] WordPress Plugin Userpro < 4.9.17.1 - Authentication Bypass
  103. [remote] Actiontec C1000A Modem - Backdoor Account
  104. [dos] Debut Embedded httpd 1.20 - Denial of Service
  105. [dos] Avaya OfficeScan (IPO) < 10.1 - ActiveX Buffer Overflow
  106. [remote] Avaya OfficeScan (IPO) < 10.1 - 'SoftConsole' Buffer Overflow (SEH)
  107. [webapps] Logitech Media Server 7.9.0 - 'favorites' Cross-Site Scripting
  108. [webapps] Logitech Media Server 7.9.0 - 'Radio URL' Cross-Site Scripting
  109. [dos] SMPlayer 17.11.0 - '.m3u' Buffer Overflow (PoC)
  110. [papers] PoC || GTFO 0x16
  111. [local] Linux Kernel 4.13 (Ubuntu 17.10) - 'waitid()' SMEP/SMAP/Chrome Sandbox Privil
  112. [webapps] pfSense 2.3.1_1 - Command Execution
  113. [webapps] Oracle Java SE - Web Start jnlp XML External Entity Processing Information
  114. [remote] ZyXEL PK5001Z Modem - Backdoor Account
  115. [webapps] pfSense 2.3.1_1 - Command Execution
  116. [webapps] ManageEngine Applications Manager 13 - SQL Injection
  117. [local] Linux Kernel 4.13 - 'waitid()' SMEP/SMAP Privilege Escalation
  118. [papers] PoC || GTFO 0x16
  119. [dos] SMPlayer 17.11.0 - '.m3u' Buffer Overflow (PoC)
  120. [webapps] Logitech Media Server 7.9.0 - 'favorites' Cross-Site Scripting
  121. [webapps] Logitech Media Server 7.9.0 - 'Radio URL' Cross-Site Scripting
  122. [remote] Avaya OfficeScan (IPO) < 10.1 - 'SoftConsole' Buffer Overflow (SEH)
  123. [dos] Avaya OfficeScan (IPO) < 10.1 - ActiveX Buffer Overflow
  124. [dos] Debut Embedded httpd 1.20 - Denial of Service
  125. [remote] Actiontec C1000A Modem - Backdoor Account
  126. [webapps] WordPress Plugin Userpro < 4.9.17.1 - Authentication Bypass
  127. [dos] Ipswitch WS_FTP Professional < 12.6.0.3 - Local Buffer Overflow (SEH)
  128. [webapps] Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via
  129. [webapps] Ladon Framework for Python 0.9.40 - XML External Entity Expansion
  130. [dos] GraphicsMagick - Memory Disclosure / Heap Overflow
  131. [remote] tnftp - 'savefile' Arbitrary Command Execution (Metasploit)
  132. [webapps] WordPress Plugin JTRT Responsive Tables 4.1 - SQL Injection
  133. [local] Vir.IT eXplorer Anti-Virus - Privilege Escalation
  134. [webapps] Ingenious School Management System 2.3.0 - 'friend_index' SQL injection
  135. [dos] WhatsApp 2.17.52 - Memory Corruption
  136. [webapps] OctoberCMS 1.0.426 (Build 426) - Cross-Site Request Forgery
  137. [remote] ZyXEL PK5001Z Modem - Backdoor Account
  138. [local] Easy MPEG/AVI/DIVX/WMV/RM to DVD - 'Enter User Name' Buffer Overflow (SEH)
  139. [webapps] Oracle Java SE - Web Start jnlp XML External Entity Processing Information
  140. [webapps] Shareet - 'photo' SQL Injection
  141. [webapps] US Zip Codes Database - 'state' SQL Injection
  142. [webapps] Newspaper 1.0 - SQL Injection
  143. [webapps] Sokial Social Network Script 1.0 - SQL Injection
  144. [webapps] tPanel 2009 - Authentication Bypass
  145. [webapps] Vastal I-Tech Dating Zone 0.9.9 - 'product_id' SQL Injection
  146. [webapps] ZeeBuddy 2x - 'groupid' SQL Injection
  147. [webapps] Protected Links - SQL Injection
  148. [webapps] AROX School ERP PHP Script - 'id' SQL Injection
  149. [webapps] SoftDatepro Dating Social Network 1.3 - SQL Injection
  150. [webapps] Joomla! Component NS Download Shop 2.2.6 - 'id' SQL Injection
  151. [webapps] MyBuilder Clone 1.0 - 'subcategory' SQL Injection
  152. [webapps] Same Sex Dating Software Pro 1.0 - SQL Injection
  153. [webapps] Job Board Script - 'nice_theme' SQL Injection
  154. [webapps] Joomla! Component Zh YandexMap 6.1.1.0 - 'placemarklistid' SQL Injection
  155. [webapps] Mailing List Manager Pro 3.0 - SQL Injection
  156. [webapps] iStock Management System 1.0 - Arbitrary File Upload
  157. [webapps] PG All Share Video 1.0 - SQL Injection
  158. [webapps] PHP CityPortal 2.0 - SQL Injection
  159. [webapps] iProject Management System 1.0 - 'ID' SQL Injection
  160. [webapps] Article Directory Script 3.0 - 'id' SQL Injection
  161. [webapps] Adult Script Pro 2.2.4 - SQL Injection
  162. [webapps] D-Park Pro 1.0 - SQL Injection
  163. [webapps] iTech Gigs Script 1.21 - SQL Injection
  164. [webapps] PHPMyFAQ 2.9.8 - Cross-Site Scripting (3)
  165. [webapps] Ingenious 2.3.0 - Arbitrary File Upload
  166. [webapps] Online Exam Test Application - 'sort' SQL Injection
  167. [webapps] Php Inventory - Arbitrary File Upload
  168. [webapps] Zomato Clone Script - 'resid' SQL Injection
  169. [webapps] Website Broker Script - 'status_id' SQL Injection
  170. [webapps] Vastal I-Tech Agent Zone - SQL Injection
  171. [webapps] WordPress Plugin Ultimate Product Catalog 4.2.24 - PHP Object Injection
  172. [webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery
  173. [webapps] PHP Melody 2.6.1 - SQL Injection
  174. [remote] MitraStar DSL-100HN-T1/GPT-2541GNAC - Privilege Escalation
  175. [dos] Tizen Studio 1.3 Smart Development Bridge
  176. [remote] DameWare Remote Controller
  177. [local] HitmanPro 3.7.15 Build 281 - Kernel Pool Overflow
  178. [local] PHPMailer
  179. [remote] Netgear DGN1000 1.1.00.48 - Setup.cgi Unauthenticated Remote Code Execution
  180. [webapps] KeystoneJS 4.0.0-beta.5 - CSV Excel Macro Injection
  181. [webapps] KeystoneJS 4.0.0-beta.5 - Cross-Site Scripting
  182. [webapps] FS Trademe Clone - 'id' SQL Injection
  183. [webapps] FS Thumbtack Clone - 'ser' SQL Injection
  184. [webapps] FS Monster Clone - 'id' SQL Injection
  185. [webapps] FS Care Clone - 'sitterService' SQL Injection
  186. [webapps] FS Realtor Clone - 'id' SQL Injection
  187. [webapps] FS Crowdfunding Script - 'id' SQL Injection
  188. [webapps] FS Shutter Stock Clone - 'keywords' SQL Injection
  189. [webapps] Mura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injectio
  190. [webapps] FS Ebay Clone - 'pd_maincat_id' Parameter SQL Injection
  191. [webapps] FS Expedia Clone - 'hid' SQL Injection
  192. [webapps] FS Groupon Clone - 'category' SQL Injection
  193. [webapps] FS Lynda Clone - 'category' SQL Injection
  194. [webapps] FS Indiamart Clone - 'keywords' SQL Injection
  195. [webapps] FS Freelancer Clone - 'sk' SQL Injection
  196. [webapps] FS Food Delivery Script - 'keywords' SQL Injection
  197. [webapps] FS Car Rental Script - 'pickup_location' Parameter SQL Injection
  198. [webapps] FS Amazon Clone - 'category_id' Parameter SQL Injection
  199. [webapps] FS OLX Clone - 'catg_id' Parameter SQL Injection
  200. [webapps] FS Book Store Script - 'category' Parameter SQL Injection
  201. [local] Mikogo 5.4.1.160608 - Local Credentials Disclosure
  202. [remote] Polycom - Command Shell Authorization Bypass (Metasploit)
  203. [remote] Unitrends UEB 9 - bpserverd Authentication Bypass Remote Command Execution (
  204. [remote] Unitrends UEB 9 - http api/storage Remote Root (Metasploit)
  205. [local] Linux Kernel 4.14.0-rc4+ - 'waitid()' Privilege Escalation
  206. [webapps] Kaltura
  207. [webapps] CometChat < 6.2.0 BETA 1 - Local File Inclusion
  208. [dos] ArGoSoft Mini Mail Server 1.0.0.2 - Denial of Service
  209. [remote] Ayukov NFTP FTP Client
  210. [webapps] TP-Link TL-MR3220 - Cross-Site Scripting
  211. [webapps] Logitech Media Server - Cross-Site Scripting
  212. [webapps] TP-Link WR940N - Authenticated Remote Code Exploit
  213. [webapps] Check_MK 1.2.8p25 - Information Disclosure
  214. [dos] Mozilla Firefox < 55 - Denial of Service
  215. [webapps] ZKTime Web Software 2.0 - Improper Access Restrictions
  216. [webapps] ZKTime Web Software 2.0 - Cross-Site Request Forgery
  217. [local] Microsoft Game Definition File Editor 6.3.9600 - XML External Entity Injectio
  218. [papers] Hacksys Extreme Vulnerable Windows Driver analysis Part 1
  219. [dos] Xen - Unbounded Recursion in Pagetable De-typing
  220. [webapps] Afian AB FileRun 2017.03.18 - Multiple Vulnerabilities
  221. [webapps] Linksys E Series - Multiple Vulnerabilities
  222. [webapps] Wordpress Plugin Car Park Booking - SQL Injection
  223. [webapps] Career Portal 1.0 - SQL Injection
  224. [dos] Linux Kernel - 'AF_PACKET' Use-After-Free
  225. [webapps] Apache Solr 7.0.1 - XML External Entity Expansion / Remote Code Execution
  226. [remote] Tomcat - Remote Code Execution via JSP Upload Bypass (Metasploit)
  227. [local] Shadowsocks - Log File Command Execution
  228. [local] shadowsocks-libev 3.1.0 - Command Execution
  229. [webapps] OpenText Documentum Content Server - Arbitrary File Download
  230. [webapps] OpenText Documentum Content Server - dmr_content Privilege Escalation
  231. [webapps] OpenText Documentum Content Server - Arbitrary File Download Privilege Esca
  232. [webapps] OpenText Documentum Content Server - Privilege Escalation
  233. [dos] Microsoft Windows - 'nt!NtQueryObject (ObjectNameInformation)' Kernel Pool Memo
  234. [dos] Microsoft Edge Chakra JIT - 'RegexHelper::StringReplace' Must Call the Callback
  235. [dos] Microsoft Edge Chakra JIT - Incorrect GenerateBailOut Calling Patterns
  236. [dos] Microsoft Windows 10 - WLDP/MSHTML CLSID UMCI Bypass
  237. [remote] Apple iOS 10.2 (14C92) - Remote Code Execution
  238. [dos] Microsoft Excel - OLE Arbitrary Code Execution
  239. [dos] Microsoft Office Groove - 'Workspace Shortcut' Arbitrary Code Execution
  240. [shellcode] Windows x64 - API Hooking Shellcode (117 bytes)
  241. [webapps] 3CX Phone System 15.5.3554.1 - Directory Traversal
  242. [webapps] Trend Micro Data Loss Prevention Virtual Appliance 5.2 - Path Traversal
  243. [webapps] Webmin 1.850 - Multiple Vulnerabilities
  244. [webapps] AlienVault Unified Security Management (USM) 5.4.2 - Cross-Site Request For
  245. [webapps] phpMyFAQ 2.9.8 - Cross-Site Scripting
  246. [webapps] Dreambox Plugin BouquetEditor - Cross-Site Scripting
  247. [webapps] TYPO3 Extension Restler 1.7.0 - Local File Disclosure
  248. [remote] Sync Breeze Enterprise 10.1.16 - Buffer Overflow (SEH) (Metasploit)
  249. [webapps] E-Sic Software livre CMS - Cross Site Scripting
  250. [webapps] E-Sic Software livre CMS - 'f' Parameter SQL Injection