- [shellcode] - Linux/x86-64 - NetCat Reverse Shell Shellcode (72 bytes)
- [shellcode] - Linux/x86-64 - Polymorphic NetCat Reverse Shell Shellcode (106 bytes)
- [webapps] - EPSON TMNet WebConfig 1.00 - Cross-Site Scripting
- [shellcode] - Linux/x86-64 - Polymorphic Flush IPTables Shellcode (47 bytes)
- [webapps] - pfSense 2.3.2 - Cross-Site Scripting / Cross-Site Request Forgery
- [webapps] - Joomla! Component Coupon 3.5 - SQL Injection
- [webapps] - Wordpress < 4.7.1 - Username Enumeration
- [shellcode] - Linux/x86-64 - Polymorphic Setuid(0) & Execve(/bin/sh) Shellcode (31 by
- [webapps] - Joomla! Component Abstract 2.1 - SQL Injection
- [webapps] - Joomla! Component StreetGuessr Game 1.0 - SQL Injection
- [webapps] - Joomla! Component Guesser 1.0.4 - 'type' Parameter SQL Injection
- [webapps] - Joomla! Component Recipe Manager 2.2 - 'id' Parameter SQL Injection
- [webapps] - Php Classified OLX Clone Script - 'category' Parameter SQL Injection
- [webapps] - SchoolDir - SQL Injection
- [shellcode] - Windows x86 - Reverse TCP Staged Alphanumeric Shellcode (332 Bytes)
- [webapps] - Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scriptin
- [webapps] - WordPress Plugin Contact Form Manager - Cross-Site Request Forgery / Cros
- [webapps] - WordPress Plugin User Login Log 2.2.1 - Cross-Site Scripting
- [webapps] - WordPress Plugin Popup by Supsystic 1.7.6 - Cross-Site Request Forgery
- [webapps] - WordPress Plugin NewStatPress 1.2.4 - Cross-Site Scripting
- [webapps] - WordPress Plugin Global Content Blocks 2.1.5 - Cross-Site Request Forgery
- [webapps] - WordPress Plugin File Manager 3.0.1 - Cross-Site Request Forgery
- [webapps] - DLink DSL-2730U Wireless N 150 - Cross-Site Request Forgery
- [remote] - SysGauge 1.5.18 - Buffer Overflow
- [shellcode] - Linux/x86-64 - Reverse Shell Shellcode (84 bytes)
- [dos] - BlueIris 4.5.1.4 - Denial of Service
- [dos] - Synchronet BBS 3.16c - Denial of Service
- [local] - Cisco AnyConnect Secure Mobility Client 4.3.04027 - Privilege Escalation
- [webapps] - NETGEAR DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery
- [remote] - MVPower DVR TV-7104HE 1.8.4 115215B9 - Shell Unauthenticated Command Execu
- [papers] - RSA Asymmetric Polymorphic Shellcode
- [webapps] - Joomla! Component OneVote! 1.0 - SQL Injection
- [shellcode] - Linux/x86_64 - Random Listener Shellcode (54 bytes)
- [shellcode] - Windows x86 - Executable Directory Search Shellcode (130 bytes)
- [webapps] - NETGEAR DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution
- [webapps] - Joomla! Component Gnosis 1.1.2 - 'id' Parameter SQL Injection
- [webapps] - Joomla! Component My MSG 3.2.1 - SQL Injection
- [webapps] - Joomla! Component Spinner 360 1.3.0 - SQL Injection
- [webapps] - Joomla! Component JomSocial - SQL Injection
- [dos] - Linux Kernel 4.4.0 (Ubuntu) - DCCP Double-Free PoC
- [local] - Linux Kernel 4.4.0 (Ubuntu) - DCCP Double-Free Privilege Escalation
- [webapps] - Joomla! Component Intranet Attendance Track 2.6.5 - SQL Injection
- [webapps] - Joomla! Component JooDatabase 3.1.0 - SQL Injection
- [webapps] - Joomla! Component JO Facebook Gallery 4.5 - SQL Injection
- [webapps] - Joomla! Component AJAX Search for K2 2.2 - SQL Injection
- [webapps] - Joomla! Component Community Surveys 4.3 - SQL Injection
- [webapps] - Joomla! Component Community Polls 4.5.0 - SQL Injection
- [webapps] - Joomla! Component GPS Tools 4.0.1 - SQL Injection
- [webapps] - Joomla! Component Community Quiz 4.3.5 - SQL Injection
- [webapps] - Apple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting
- [webapps] - Apple WebKit 10.0.2 - Cross-Origin or Sandboxed IFRAME Pop-up Blocker Byp
- [webapps] - Apple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting
- [dos] - Microsoft Edge and Internet Explorer - 'HandleColumnBreakOnColumnSpanningElem
- [remote] - macOS HelpViewer 10.12.1 - XSS Leads to Arbitrary File Execution and Arbit
- [shellcode] - Linux/x86-64 - Egghunter Shellcode (38 bytes)
- [webapps] - Joomla! Component Store for K2 3.8.2 - SQL Injection
- [webapps] - Joomla! Component UserExtranet 1.3.1 - SQL Injection
- [webapps] - Joomla! Component MultiTier 3.1 - SQL Injection
- [remote] - Disk Savvy Enterprise 9.4.18 - Buffer Overflow (SEH)
- [webapps] - Teradici Management Console 2.2.0 - Privilege Escalation
- [dos] - Google Chrome - 'layout' Out-of-Bounds Read
- [dos] - EasyCom For PHP 4.0.0 - Buffer Overflow (PoC)
- [dos] - EasyCom For PHP 4.0.0 - Denial of Service
- [webapps] - Joomla! Component ContentMap 1.3.8 - 'contentid' Parameter SQL Injection
- [webapps] - Joomla! Component VehicleManager 3.9 - SQL Injection
- [webapps] - Joomla! Component RealEstateManager 3.9 - SQL Injection
- [webapps] - Joomla! Component BookLibrary 3.6.1 - SQL Injection
- [webapps] - Joomla! Component MediaLibrary Basic 3.5 - SQL Injection
- [webapps] - Joomla! Component J-HotelPortal 6.0.2 - 'review_id' Parameter SQL Injecti
- [webapps] - Joomla! Component J-CruiseReservation Standard 3.0 - 'city' Parameter SQL
- [webapps] - Joomla! Component Eventix Events Calendar 1.0 - SQL Injection
- [webapps] - Joomla! Component J-MultipleHotelReservation Standard 6.0.2 - 'review_id'
- [webapps] - Joomla! Component Directorix Directory Manager 1.1.1 - SQL Injection
- [webapps] - Joomla! Component Magic Deals Web 1.2.0 - SQL Injection
- [webapps] - Joomla! Component J-BusinessDirectory 4.6.8 - SQL Injection
- [webapps] - DIGISOL DG-HR1400 Wireless Router - Cross-Site Request Forgery
- [shellcode] - Linux/x86 - SELinux Permissive Mode Switcher Shellcode (45 bytes)
- [webapps] - Album Lock 4.0 iOS - Directory Traversal
- [webapps] - Joomla! Component MaQma Helpdesk 4.2.7 - 'id' Parameter SQL Injection
- [webapps] - Joomla! Component PayPal IPN for DOCman 3.1 - 'id' Parameter SQL Injectio
- [papers] - Injecting SQLite Database Based Applications
- [webapps] - PHPShell 2.4 - Session Fixation
- [shellcode] - Linux - Reverse Shell Shellcode (66 bytes)
- [webapps] - Joomla! Component Joomloc-CAT 4.1.3 - 'ville' Parameter SQL Injection
- [webapps] - Joomla! Component Joomloc-Lite 1.3.2 - 'site_id' Parameter SQL Injection
- [webapps] - Joomla! Component JomWALL 4.0 - 'wuid' Parameter SQL Injection
- [webapps] - Joomla! Component OS Property 3.0.8 - SQL Injection
- [webapps] - Joomla! Component EShop 2.5.1 - 'id' Parameter SQL Injection
- [webapps] - Joomla! Component OS Services Booking 2.5.1 - SQL Injection
- [webapps] - Joomla! Component Room Management 1.0 - SQL Injection
- [shellcode] - Windows x86 - Protect Process Shellcode (229 bytes)
- [webapps] - Joomla! Component WMT Content Timeline 1.0 - 'id' Parameter SQL Injection
- [webapps] - Joomla! Component Team Display 1.2.1 - 'filter_category' Parameter SQL In
- [webapps] - Joomla! Component Groovy Gallery 1.0.0 - SQL Injection
- [webapps] - Joomla! Component JEmbedAll 1.4 - SQL Injection
- [webapps] - Joomla! Component Spider Calendar Lite 3.2.16 - SQL Injection
- [webapps] - Joomla! Component Spider Catalog Lite 1.8.10 - SQL Injection
- [webapps] - Joomla! Component Spider Facebook 1.6.1 - SQL Injection
- [webapps] - Joomla! Component Spider FAQ Lite 1.3.1 - SQL Injection
- [shellcode] - Linux - Dual/Multi mode Bind Shell Shellcode (156 bytes)
- [webapps] - WordPress Plugin Corner Ad 1.0.7 - Cross-Site Scripting
- [webapps] - dotCMS 3.6.1 - Blind Boolean SQL Injection
- [dos] - Cisco ASA - WebVPN CIFS Handling Buffer Overflow
- [webapps] - Joomla! Component JSP Store Locator 2.2 - 'id' Parameter SQL Injection
- [dos] - Microsoft Windows gdi32.dll - EMR_SETDIBITSTODEVICE Heap-Based Out-of-Bounds
- [dos] - NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
- [dos] - NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
- [remote] - OpenText Documentum D2 - Remote Code Execution
- [dos] - GOM Player 2.3.10.5266 - '.fpx' Denial of Service
- [webapps] - Joomla! Component JoomBlog 1.3.1 - SQL Injection
- [webapps] - Geutebruck 5.02024 G-Cam/EFD-2250 - Remote Command Execution (Metasploit)
- [dos] - LG G4 - lgdrmserver Binder Service Multiple Race Conditions
- [dos] - LG G4 - lghashstorageserver Directory Traversal
- [dos] - LG G4 - Touchscreen Driver write_log Kernel Read/Write
- [dos] - Google Android - Inter-process munmap in android.util.MemoryIntArray
- [dos] - Google Android - android.util.MemoryIntArray Ashmem Race Conditions
- [local] - ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
- [dos] - Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
- [remote] - Piwik 2.14.0 / 2.16.0 / 2.17.1 / 3.0.1 - Superuser Plugin Upload (Metasplo
- [local] - ShadeYouVPN Client 2.0.1.11 - Privilege Escalation
- [webapps] - Joomla! Component JE Classify Ads 1.2 - 'pro_id' Parameter SQL Injection
- [webapps] - Joomla! Component JE Gallery 1.3 - 'photo_id' Parameter SQL Injection
- [webapps] - Joomla! Component JE Directory 1.7 - 'ditemid' Parameter SQL Injection
- [webapps] - Joomla! Component JE QuoteForm - 'Itemid' Parameter SQL Injection
- [webapps] - Joomla! Component JE Property Finder 1.6.3 - SQL Injection
- [webapps] - Joomla! Component JE Tour 2.0 - SQL Injection
- [webapps] - Joomla! Component JE Video Rate 1.0 - SQL Injection
- [webapps] - Joomla! Component JE auction 1.6 - 'eid' Parameter SQL Injection
- [webapps] - Joomla! Component JE Auto 1.5 - 'd_itemid' Parameter SQL Injection
- [webapps] - PHP Marketplace Script - SQL Injection
- [webapps] - Joomla! Component Soccer Bet 4.1.5 - 'userid' Parameter SQL Injection
- [webapps] - WhizBiz 1.9 - SQL Injection
- [webapps] - TI Online Examination System 2.0 - SQL Injection
- [webapps] - Viavi Real Estate - SQL Injection
- [webapps] - Viavi Movie Review - 'id' Parameter SQL Injection
- [webapps] - Viavi Product Review - 'id' Parameter SQL Injection
- [webapps] - Quadz School Management System 3.1 - 'uisd' Parameter SQL Injection
- [webapps] - Domains & Hostings Manager PRO 3.0 - 'entries' Parameter SQL Injection
- [local] - Cimetrics BACstac 6.2f - Privilege Escalation
- [local] - Cimetrics BACnet Explorer 4.0 - XML External Entity Injection
- [webapps] - Kodi 17.1 - Arbitrary File Disclosure
- [webapps] - SonicDICOM PACS 2.3.2 - Cross-Site Scripting
- [webapps] - SonicDICOM PACS 2.3.2 - Cross-Site Request Forgery (Add Admin)
- [webapps] - SonicDICOM PACS 2.3.2 - Privilege Escalation
- [webapps] - Multilanguage Estate Agency Pro 1.2 - SQL Injection
- [remote] - F5 BIG-IP SSL Virtual Server - Memory Disclosure
- [webapps] - D-link DIR-600M - Cross-Site Request Forgery
- [remote] - HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasp
- [webapps] - CMS Lite 1.3.1 - SQL Injection
- [webapps] - Tiger Post 3.0.1 - SQL Injection
- [webapps] - Gram Post 1.0 - SQL Injection
- [webapps] - Youtube Analytics Multi Channel 3.0 - SQL Injection
- [webapps] - Collabo - Arbitrary File Download
- [webapps] - Takas Classified 1.1 - SQL Injection
- [webapps] - Zigaform - SQL Injection
- [papers] - Exploiting Node.js deserialization bug for Remote Code Execution
- [webapps] - Mobiketa 3.5 - SQL Injection
- [webapps] - Sendroid 5.2 - SQL Injection
- [webapps] - Fome SMS Portal 2.0 - SQL Injection
- [webapps] - SOA School Management - SQL Injection
- [webapps] - Client Expert 1.0.1 - SQL Injection
- [webapps] - EXAMPLO - SQL Injection
- [shellcode] - Linux/x86 - Reverse TCP Alphanumeric Staged Shellcode (103 bytes)
- [webapps] - Muviko Video CMS - SQL Injection
- [webapps] - Multi Outlets POS 3.1 - 'id' Parameter SQL Injection
- [papers] - MySQL Injection in Update, Insert, and Delete
- [webapps] - Fully Featured News CMS 1.0 - 'id' Parameter SQL Injection
- [webapps] - MySQL File Uploader 1.0 - 'id' Parameter SQL Injection
- [webapps] - Easy Support Tools 1.0 - 'stt' Parameter SQL Injection
- [webapps] - Easy Web Search 3 - 'id' Parameter SQL Injection
- [webapps] - FTP Made Easy PRO 1.2 - Arbitrary File Download
- [webapps] - Easy File Uploader 1.2 - Arbitrary File Download
- [webapps] - Responsive Filemanger
- [papers] - MySQL Out-of-Band Hacking
- [papers] - Alternative for Information_Schema.Tables in MySQL
- [webapps] - Viral Fun Facts Sharing Script 1.1.0 - 'id' Parameter SQL Injection
- [webapps] - Web Inspiration Gallery Script 1.0.0 - 'id' Parameter SQL Injection
- [webapps] - ThisIsWhyImBroke Clone Script 4.0 - 'id' Parameter SQL Injection
- [webapps] - Upworthy Clone Script 1.1.0 - 'id' Parameter SQL Injection
- [webapps] - Ultimate Viral Media Script 1.0 - 'id' Parameter SQL Injection
- [webapps] - Visual Link Sharing Websites Builder Script 2.1.0 - SQL Injection
- [webapps] - ThisIsWhyImBroke Clone Script 4.0.0 - 'id' Parameter SQL Injection
- [webapps] - Funny Image and Video Script 2.0.0 - 'id' Parameter SQL Injection
- [webapps] - Clone Script Directory Script 1.1.0 - 'cid' Parameter SQL Injection
- [webapps] - Viral Pictures and Video Script 2.0.0 - 'id' Parameter SQL Injection
- [webapps] - NewsBee CMS - SQL Injection
- [webapps] - Alstrasoft Template Seller Pro 3.25e - 'tempid' Parameter SQL Injection
- [webapps] - Itech Job Portal Script 9.13 - Multiple Vulnerabilities
- [webapps] - iScripts AutoHoster 3.0 - 'siteid' Parameter SQL Injection
- [webapps] - Alstrasoft EPay Enterprise 5.17 - SQL Injection
- [webapps] - Alstrasoft ProTaxi Enterprise 3.5 - Arbitrary File Upload
- [webapps] - Alstrasoft e-Friends 5.12 - SQL Injection
- [webapps] - Alstrasoft Video Share Enterprise 4.72 - SQL Injection
- [webapps] - Alstrasoft Flippa Clone MarketPlace Script 4.10 - Cross-Site Request Forg
- [webapps] - Alstrasoft FMyLife Pro 1.02 - Cross-Site Request Forgery (Add Admin)
- [webapps] - Alstrasoft Forum Pay Per Post Exchange Script 2.01 - SQL Injection
- [local] - Debian 9 ntfs-3g - Privilege Escalation
- [webapps] - Zoneminder 1.29 / 1.30 - Cross-Site Scripting / SQL Injection / Session F
- [webapps] - Itech Multi Vendor Script 6.49 - SQL Injection
- [remote] - Netwave IP Camera - Password Disclosure
- [remote] - CUPS < 2.0.3 - Remote Command Execution
- [webapps] - SlimarUSER Management 1.0 - 'id' Parameter SQL Injection
- [webapps] - Itech Travel Portal Script 9.35 - SQL Injection
- [webapps] - Property Listing Script - 'propid' Parameter Blind SQL Injection
- [webapps] - Itech Inventory Management Software 3.77 - SQL Injection
- [webapps] - Itech Movie Portal Script 7.37 - SQL Injection
- [webapps] - Itech News Portal Script 6.28 - 'sc' Parameter SQL Injection
- [webapps] - Itech Auction Script 6.49 - 'pid' Parameter SQL Injection
- [shellcode] - Linux - Multi/Dual mode Reverse Shell Shellcode (129 bytes)
- [local] - Ghostscript 9.20 - 'Filename' Command Execution
- [webapps] - WordPress 4.7.0/4.7.1 - Unauthenticated Content Injection (PoC)
- [webapps] - WordPress 4.7.0/4.7.1 - Unauthenticated Content Injection Arbitrary Code
- [dos] - Google Android - 'cfp_ropp_new_key_reenc' and 'cfp_ropp_new_key' RKP Memory C
- [dos] - Google Android - Unprotected MSRs in EL1 RKP Privilege Escalation
- [local] - Google Android - RKP EL1 Code Loading Bypass
- [dos] - Google Android - RKP Information Disclosure via s2-remapping Physical Ranges
- [dos] - QNAP NVR/NAS - Buffer Overflow
- [dos] - Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
- [dos] - Google Chrome - 'HTMLKeygenElement::shadowSelect()' Type Confusion
- [dos] - Apple WebKit - 'HTMLKeygenElement' Type Confusion
- [dos] - Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
- [webapps] - LogoStore - SQL Injection
- [webapps] - Netman 204 - Backdoor Account / Password Reset
- [local] - Viscosity 1.6.7 - Privilege Escalation
- [webapps] - Itech Multi Vendor Script 6.49 - SQL Injection
- [webapps] - Itech News Portal Script 6.28 - SQL Injection
- [webapps] - Itech Real Estate Script 3.12 - SQL Injection
- [webapps] - Caregiver Script 2.57 - SQL Injection
- [webapps] - Auction Script 6.49 - SQL Injection
- [webapps] - Itech B2B Script 4.28 - SQL Injection
- [webapps] - Itech Classifieds Script 7.27 - SQL Injection
- [webapps] - Itech Dating Script 3.26 - SQL Injection
- [webapps] - Itech Freelancer Script 5.13 - SQL Injection
- [webapps] - PEAR Base System 1.10.1 - Arbitrary File Download
- [webapps] - TrueConf Server 4.3.7 - Multiple Vulnerabilities
- [shellcode] - Linux - Multi/Dual mode execve("/bin/sh", NULL, 0) Shellcode (37 bytes)
- [webapps] - WordPress Plugin WP Private Messages 1.0.1 - SQL Injection
- [webapps] - Online Hotel Booking System Pro 1.2 - SQL Injection
- [webapps] - WordPress Plugin Online Hotel Booking System Pro 1.0 - SQL Injection
- [webapps] - My Photo Gallery 1.0 - SQL Injection
- [webapps] - Maian Weblog 4.0 - SQL Injection
- [dos] - Google Android - 'pm_qos' KASLR Bypass
- [remote] - Haraka
- [dos] - macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
- [dos] - macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
- [webapps] - KB Affiliate Referral Script 1.0 - Authentication Bypass
- [webapps] - KB Login Authentication Script 1.1 - Authentication Bypass
- [webapps] - KB Messages PHP Script 1.0 - Authentication Bypass
- [remote] - Autodesk Backburner Manager 3 < 2016.0.0.2150 - Null Dereference Denial of
- [webapps] - Pear HTTP_Upload 1.0.0b3 - Arbitrary File Upload