- [webapps] - Openfire 3.10.2 - Unrestricted File Upload
- [local] - Total Commander 8.52 - SEH-Overwrite BOF
- [remote] - TP-Link NC200/NC220 Cloud Camera 300Mbps Wi-Fi - Hard-Coded Credentials
- [webapps] - EZ SQL Reports < 4.11.37 - Multiple Vulnerabilities
- [webapps] - ManageEngine OpManager 11.5 - Multiple Vulnerabilities
- [webapps] - ManageEngine EventLog Analyzer < 10.6 build 10060 - SQL Query Execution
- [dos] - IKEView.exe Fox beta 1 - Stack Buffer Overflow
- [dos] - IKEView.exe R60 - Stack Buffer Overflow
- [dos] - Microsoft Internet Explorer 11 - Stack Underflow Crash PoC
- [remote] - Windows Media Center Command Execution - MS15-100
- [webapps] - Monsta FTP 1.6.2 - Multiple Vulnerabilities
- [local] - Logitech Webcam Software 1.1 - eReg.exe SEH/Unicode Buffer Overflow
- [dos] - OpenLDAP 2.4.42 - ber_get_next Denial of Service
- [shellcode] - OS X x64 - tcp bind shellcode, NULL byte free (144 bytes)
- [local] - OS X Install.framework suid Helper Privilege Escalation
- [local] - OS X Install.framework Arbitrary mkdir, unlink and chown to admin Group
- [local] - OS X Install.framework suid root Runner Binary Privilege Escalation
- [webapps] - Octogate UTM 3.0.12 - Admin Interface Directory Traversal
- [webapps] - Synology Video Station 1.5-0757 - Multiple Vulnerabilities
- [webapps] - php - cgimode fpm writeprocmemfile bypass disable function demo
- [shellcode] - Linux/x86 - execve(/bin/bash) - 31 bytes
- [dos] - PHP unserialize() Use-After-Free Vulnerabilities
- [remote] - Android Stagefright - Remote Code Execution
- [dos] - PHP Session Deserializer Use-After-Free
- [dos] - PHP SplObjectStorage unserialize() Use-After-Free
- [dos] - PHP GMP unserialize() Use-After-Free
- [dos] - PHP SplDoublyLinkedList unserialize() Use-After-Free
- [webapps] - Auto-Exchanger 5.1.0 - CSRF Vulnerability
- [webapps] - Qlikview
- [papers] - Evading All Web-Application Firewalls XSS Filters
- [shellcode] - Linux/x86 - Create file with permission 7775 and exit (Shell Generator)
- [shellcode] - Linux/x86 - execve("/bin/cat", ["/bin/cat", "/etc/passwd"], NULL)
- [webapps] - DirectAdmin Web Control Panel 1.483 - Multiple Vulnerabilities
- [local] - IBM AIX High Availability Cluster Multiprocessing (HACMP) Local Privilege E
- [local] - Cisco Sourcefire User Agent 2.2 - Insecure File Permissions
- [dos] - Advantech WebAccess 8.0, 3.4.3 ActiveX - Multiple Vulnerabilities
- [papers] - Shoot zend_executor_globals to bypass php disable_functions
- [local] - VeryPDF HTML Converter 2.0 - SEH/ToLower() Bypass Buffer Overflow
- [remote] - Endian Firewall Proxy Password Change Command Injection
- [webapps] - NETGEAR Wireless Management System 2.1.4.15 (Build 1236) - Privilege Esca
- [webapps] - JSPMySQL Administrador - Multiple Vulnerabilities
- [webapps] - HooToo Tripmate HT-TM01 2.000.022 - CSRF Vulnerabilities
- [webapps] - Zhone ADSL2+ 4P Bridge & Router (Broadcom) - Multiple Vulnerabilities
- [local] - Disconnect.me Mac OS X Client
- [webapps] - FireEye Appliance Unauthorized File Disclosure
- [webapps] - Elastix < 2.5 , PHP Code Injection Exploit
- [webapps] - WordPress Contact Form Generator
- [dos] - ActiveState Perl.exe x64 Client 5.20.2 - Crash PoC
- [local] - AutoCAD DWG and DXF To PDF Converter 2.2 - Buffer Overflow
- [papers] - Compromising ISP Issued 802.11 Wireless Cable Modem Networks for Profit
- [papers] - [Hebrew] Digital Whisper Security Magazine #63
- [papers] - [Hebrew] Digital Whisper Security Magazine #64
- [webapps] - YesWiki 0.2 - Path Traversal Vulnerability
- [shellcode] - Mainframe/System Z Bind Shell
- [webapps] - Cerb 7.0.3 - CSRF Vulnerability
- [webapps] - GPON Home Router FTP G-93RG1 - CSRF Command Execution Vulnerability
- [dos] - SphereFTP Server 2.0 - Crash PoC
- [papers] - [Persian] Pyrit Cluster with Kali Linux
- [papers] - [Persian] Cracking WPA/WPA2 with Rainbow Table
- [shellcode] - OS X x64 /bin/sh Shellcode, NULL Byte Free, 34 bytes
- [webapps] - Thomson Wireless VoIP Cable Modem TWG850-4B ST9C.05.08 - Authentication B
- [webapps] - Edimax BR6228nS/BR6228nC - Multiple Vulnerabilities
- [dos] - XGI Windows VGA Display Manager 6.14.10.1090 - Arbitrary Write PoC
- [dos] - SiS Windows VGA Display Manager 6.14.10.3930 - Write-What-Where PoC
- [dos] - Mpxplay Multimedia Commander 2.00a - .m3u Stack-Based Buffer Overflow
- [webapps] - Bedita 3.5.1 - XSS Vulnerabilities
- [dos] - PFTP Server 8.0f Lite - textfield Local SEH Buffer Overflow
- [local] - Boxoft WAV to MP3 Converter - convert Feature Buffer Overflow
- [local] - Apple OS X Entitlements Rootpipe Privilege Escalation
- [webapps] - Cyberoam Firewall CR500iNG-XP - 10.6.2 MR-1 - Blind SQL Injection Vulnera
- [papers] - How to HeapSpray and Exploit Memory Corruption in IIS6
- [dos] - Viber 4.2.0 - Non-Printable Characters Handling Denial of Service Vulnerabili
- [dos] - Microsoft Office 2007 - msxml5.dll Crash PoC
- [webapps] - Ganglia Web Frontend < 3.5.1 - PHP Code Execution
- [webapps] - Edimax PS-1206MF - Web Admin Auth Bypass
- [webapps] - PhpWiki 1.5.4 - Multiple Vulnerabilities
- [remote] - PCMan FTP Server 2.0.7 - RENAME Command Buffer Overflow
- [remote] - PCMan FTP Server 2.0.7 - GET Command Buffer Overflow
- [dos] - Sysax Multi Server 6.40 SSH Component Denial of Service
- [remote] - MS SQL Server 2000/2005 SQLNS.SQLNamespace COM Object Refresh() Unhandled
- [webapps] - Samsung SyncThruWeb 2.01.00.26 - SMB Hash Disclosure
- [webapps] - Pluck CMS 4.7.3 - Multiple Vulnerabilities
- [dos] - freeSSHd 1.3.1 - Denial of Service Vulnerability
- [webapps] - Wolf CMS Arbitrary File Upload To Command Execution
- [webapps] - Jenkins 1.626 - Cross Site Request Forgery / Code Execution
- [webapps] - WordPress Responsive Thumbnail Slider Plugin 1.0 - Arbitrary File Upload
- [dos] - Photo Transfer (2) 1.0 iOS - Denial of Service Vulnerability
- [dos] - QEMU Programmable Interrupt Timer Controller Heap Overflow
- [webapps] - IP.Board 4.X - Stored XSS
- [local] - BSIGN 0.4.5 - Buffer Overflow
- [local] - FENIX 0.92 - Buffer Overflow
- [dos] - Xion Audio Player 1.5 build 155 Stack Based Buffer Overflow
- [remote] - FHFS - FTP/HTTP File Server 2.1.2 Remote Command Execution
- [webapps] - Magento eCommerce - Remote Code Execution
- [dos] - VLC Media Player 2.2.1 - m3u8/m3u Crash PoC
- [local] - ZSNES 1.51 - Buffer Overflow
- [dos] - Microsoft Office 2007 Malformed Document Stack-Based Buffer Overflow
- [dos] - Microsoft Office 2007 OneTableDocumentStream Invalid Object
- [webapps] - Keeper IP Camera 3.2.2.10 - Authentication Bypass
- [remote] - Firefox PDF.js Privileged Javascript Injection
- [dos] - GOM Audio 2.0.8 - (.gas) Crash POC
- [webapps] - WordPress GeoPlaces3 Theme - Arbitrary File Upload Vulnerbility
- [webapps] - Pligg CMS 2.0.2 - CSRF Add Admin Exploit
- [dos] - Mock SMTP Server 1.0 Remote Crash PoC
- [papers] - MySQL Error Based SQL Injection Using EXP
- [remote] - Easy Address Book Web Server 1.6 - USERID Remote Buffer Overflow
- [webapps] - Netsweeper 4.0.8 - Authentication Bypass
- [remote] - Easy File Sharing Web Server 6.9 - USERID Remote Buffer Overflow
- [local] - Multiple ChiefPDF Software 2.0 - Buffer Overflow
- [webapps] - Netsweeper 4.0.8 - Arbitrary File Upload and Execution
- [webapps] - Netsweeper 3.0.6 - Authentication Bypass
- [webapps] - Netsweeper 4.0.9 - Arbitrary File Upload And Execution
- [webapps] - Netsweeper 4.0.8 - Authentication Bypass Issue
- [webapps] - Netsweeper 4.0.8 - SQL Injection Authentication Bypass
- [webapps] - Netsweeper 4.0.4 - SQL Injection
- [webapps] - Netsweeper 2.6.29.8 - SQL Injection
- [local] - Mozilla Maintenance Service Log File Overwrite Elevation of Privilege
- [dos] - Microsoft Office 2007 MSPTLS Heap Index Integer Underflow
- [dos] - Windows ATMFD.DLL CharString Stream Out-of-Bounds Reads
- [dos] - Windows ATMFD.DLL Write to Uninitialized Address Due to Malformed CFF Table
- [dos] - Windows win32k.sys TTF Font Processing IUP[] Program Instruction Pool-Based B
- [dos] - Windows win32k.sys TTF Font Processing win32k!scl_ApplyTranslation Pool-Based
- [dos] - Windows ATMFD.DLL Out-of-Bounds Read Due to Malformed Name INDEX in the CFF T
- [dos] - Windows ATMFD.DLL Out-of-Bounds Read Due to Malformed FDSelect Offset in the
- [dos] - Windows win32k.sys TTF Font Processing win32k!fsc_RemoveDups Out-of-Bounds Po
- [dos] - Windows win32k.sys TTF Font Processing win32k!fsc_BLTHoriz Out-of-Bounds Pool
- [dos] - Microsoft Office 2007 MSO.dll Use-After-Free
- [dos] - Microsoft Office 2007 MSO.dll Arbitrary Free
- [dos] - Microsoft Office 2007 OGL.dll DpOutputSpanStretch::OutputSpan Out of Bounds W
- [webapps] - WordPress MDC Private Message Plugin 1.0.0 - Persistent XSS
- [shellcode] - Win2003 x64 - Token Stealing shellcode - 59 bytes
- [webapps] - Pligg CMS 2.0.2 - Arbitrary Code Execution
- [dos] - Valhala Honeypot 1.8 - Stack-Based Buffer Overflow
- [webapps] - Vifi Radio v1 - CSRF Vulnerability
- [webapps] - Aruba Mobility Controller 6.4.2.8 - Multiple vulnerabilities
- [webapps] - up.time 7.5.0 Upload And Execute File Exploit
- [webapps] - up.time 7.5.0 Arbitrary File Disclose And Delete Exploit
- [webapps] - up.time 7.5.0 XSS And CSRF Add Admin Exploit
- [webapps] - up.time 7.5.0 Superadmin Privilege Escalation Exploit
- [dos] - Adobe Flash Heap Use-After-Free in SurfaceFilterList::CreateFromScriptAtom
- [dos] - Adobe Flash AS2 Use-After-Free in TextField.filters
- [dos] - Adobe Flash Overflow in ID3 Tag Parsing
- [dos] - Adobe Flash Shared Object Type Confusion
- [dos] - Adobe Flash Heap-Based Buffer Overflow Due to Indexing Error When Loading FLV
- [dos] - Adobe Flash Heap-Based Buffer Overflow Loading FLV File with Nellymoser Audio
- [dos] - Adobe Flash: FileReference Class Type Confusion
- [dos] - Adobe Flash Use-After-Free in TextField.gridFitType
- [dos] - Adobe Flash XMLSocket Destructor Not Cleared Before Setting User Data in conn
- [dos] - Adobe Flash URL Resource Use-After-Free
- [dos] - Adobe Flash Type Confusion in TextRenderer.setAdvancedAntialiasingTable
- [dos] - Adobe Flash Use-After-Free in attachMovie
- [dos] - Adobe Flash Use-After-Free in Drawing Methods "this"
- [dos] - Adobe Flash Use-After-Free in scale9Grid
- [dos] - Adobe Flash Out-of-Bounds Read in UTF Conversion
- [dos] - Flash AS2 Use-After-Free in DisplacementMapFilter.mapBitmap (2)
- [dos] - Flash Use-After-Free with Color.setRGB in AS2
- [dos] - Adobe Flash Use-After-Free in XML.childNodes
- [dos] - Adobe Flash Out-of-Bounds Memory Read While Parsing a Mutated TTF File Embedd
- [dos] - Adobe Flash Use-After-Free When Setting Variable
- [remote] - Flash Boundless Tunes - Universal SOP Bypass Through ActionSctipt's Sound
- [dos] - Flash Use-After-Free in NetConnection.connect
- [dos] - Flash Use-After-Free in Display List Handling
- [dos] - Flash AS2 Use After Free While Setting TextField.filters
- [dos] - Flash AS2 Use After Free in TextField.filters
- [dos] - Flash Issues in DefineBitsLossless and DefineBitsLossless2 Leads to Using Uni
- [dos] - Flash Uninitialized Stack Variable MPD Parsing Memory Corruption
- [dos] - Flash AVSS.setSubscribedTags Use After Free Memory Corruption
- [dos] - Flash Player Integer Overflow in Function.apply
- [remote] - Flash Broker-Based Sandbox Escape via Unexpected Directory Lock
- [remote] - Flash Broker-Based Sandbox Escape via Forward Slash Instead of Backslash
- [dos] - Flash PCRE Regex Compilation Zero-Length Assertion Arbitrary Bytecode Executi
- [remote] - Easy File Management Web Server 5.6 - USERID Remote Buffer Overflow
- [webapps] - WordPress WP Symposium Plugin 15.1 - Blind SQL Injection
- [webapps] - BigTree CMS 4.2.3 - Authenticated SQL Injection Vulnerabilities
- [webapps] - CodoForum 3.3.1 - Multiple SQL Injection Vulnerabilities
- [webapps] - PHPfileNavigator 2.3.3 - Privilege Escalation
- [webapps] - PHPfileNavigator 2.3.3 - CSRF Vulnerability
- [webapps] - PHPfileNavigator 2.3.3 - XSS Vulnerabilities
- [remote] - Werkzeug Debug Shell Command Execution
- [local] - VideoCharge Studio Buffer Overflow (SEH)
- [webapps] - Magento CE < 1.9.0.1 Post Auth RCE
- [dos] - FTP Commander 8.02 - SEH Overwrite
- [webapps] - Nuts CMS Remote PHP Code Injection / Execution
- [remote] - Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064
- [webapps] - Sagemcom F@ST 3864 V2 - Get Admin Password
- [local] - MASM321 11 Quick Editor (.qeditor) 4.0g- .qse SEH Based Buffer Overflow (AS
- [dos] - XMPlay 3.8.1.12 - .pls Local Crash PoC
- [shellcode] - Windows x86 All Versions - user32!MessageBox "Hello World!" (199 Bytes
- [webapps] - Security IP Camera Star Vision DVR - Authentication Bypass
- [dos] - Ubuntu 14.04 NetKit FTP Client - Crash/DoS PoC
- [dos] - Ability FTP Server 2.1.4 - Admin Panel AUTHCODE Command Remote DoS
- [dos] - Ability FTP Server 2.1.4 - afsmain.exe USER Command Remote DoS
- [webapps] - Joomla com_informations component - SQL Injection vulnerability
- [webapps] - Joomla com_memorix component - SQL Injection vulnerability
- [local] - Firefox < 39.03 - pdf.js Same Origin Policy Exploit
- [local] - Microsoft HTML Help Compiler 4.74.8702.0 - SEH Based Overflow
- [webapps] - TOTOLINK Routers - Backdoor and RCE Exploit PoC
- [webapps] - Gkplugins Picasaweb - Download File
- [local] - PDF Shaper 3.5 - Buffer Overflow
- [local] - Windows 8.1 DCOM DCE/RPC Local NTLM Reflection Privilege Escalation (MS15-0
- [shellcode] - Linux x86 - /bin/sh ROL/ROR Encoded Shellcode
- [dos] - Internet Explorer CTreeNode::GetCascadedLang Use-After-Free Vulnerability (MS
- [webapps] - WordPress Candidate Application Form Plugin 1.0 - Arbitrary File Download
- [webapps] - WordPress Simple Image Manipulator Plugin 1.0 - Arbitrary File Download
- [webapps] - WordPress Recent Backups Plugin 0.7 - Arbitrary File Download
- [webapps] - WordPress WPTF Image Gallery 1.03 - Aribtrary File Download
- [webapps] - WDS CMS - SQL Injection
- [shellcode] - Linux x86 Egg Hunter Shellcode (19 bytes)
- [webapps] - WordPress Video Gallery 2.7 SQL Injection
- [dos] - Havij Pro - Crash POC
- [dos] - OSX Keychain - EXC_BAD_ACCESS DoS
- [dos] - Classic FTP 2.36 - CWD Reconnection DoS
- [dos] - Brasero - Crash Proof Of Concept
- [dos] - Acunetix Web Vulnerability Scanner 9.5 - Crash PoC
- [webapps] - JoomShopping - Blind SQL Injection
- [local] - Tomabo MP4 Player 3.11.3 - (.m3u) SEH Buffer Overflow
- [dos] - Dell Netvault Backup 10.0.1.24 - Denial of Service
- [webapps] - WordPress Job Manager Plugin 0.7.22 - Persistent XSS
- [webapps] - Microweber 1.0.3 File Upload Filter Bypass Remote PHP Code Execution
- [webapps] - Microweber 1.0.3 - Stored XSS And CSRF Add Admin Exploit
- [papers] - BIGINT Overflow Error Based SQL Injection
- [local] - Windows NDProxy Privilege Escalation XP SP3 x86 and 2003 SP2 x86 (MS14-002)
- [remote] - PCMan FTP Server 2.0.7 - PUT Command Buffer Overflow
- [webapps] - PHP News Script 4.0.0 - SQL Injection
- [webapps] - Froxlor Server Management Panel 0.9.33.1 - MySQL Login Information Disclo
- [local] - Linux x86 Memory Sinkhole Privilege Escalation PoC
- [local] - Linux Privilege Escalation Due to Nested NMIs Interrupting espfix64
- [dos] - ISC BIND9 TKEY Remote DoS PoC
- [dos] - BIND9 - TKEY PoC
- [dos] - KMPlayer 3.9.x - .srt Crash PoC
- [dos] - T-Mobile Internet Manager - Contact Name Crash PoC
- [webapps] - Tendoo CMS 1.3 - XSS Vulnerabilities
- [local] - Sudo
- [local] - Heroes of Might and Magic III - Map Parsing Arbitrary Code Execution
- [webapps] - phpFileManager 0.9.8 - CSRF Vulnerability
- [webapps] - phpFileManager 0.9.8 - Remote Command Execution Vulnerability
- [webapps] - Xceedium Xsuite - Multiple Vulnerabilities
- [webapps] - WordPress Count Per Day Plugin 3.4 - SQL Injection
- [webapps] - WordPress Unite Gallery Lite Plugin 1.4.6 - Multiple Vulnerabilities
- [dos] - Libuser Library - Multiple Vulnerabilities
- [webapps] - Hawkeye-G v3.0.1.4912 Persistent XSS & Information Leakage
- [local] - Foxit Reader - PNG Conversion Parsing tEXt Chunk Arbitrary Code Execution
- [webapps] - Airdroid iOS, Android & Win 3.1.3 - Persistent Vulnerability
- [webapps] - Hawkeye-G v3.0.1.4912 CSRF Vulnerability
- [webapps] - phpVibe < 4.20 Stored XSS
- [webapps] - WordPress Download Manager Free 2.7.94 & Pro 4 Authenticated Stored XSS
- [local] - OS X 10.10 DYLD_PRINT_TO_FILE Local Privilege Escalation
- [dos] - Counter-Strike 1.6 'GameInfo' Query Reflection DoS PoC
- [remote] - Internet Download Manager - OLE Automation Array Remote Code Execution
- [remote] - SysAid Help Desk 'rdslogs' Arbitrary File Upload