المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 4 5 6 7 8 9 [10] 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67

  1. [local] AppXSvc - Privilege Escalation
  2. [webapps] Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
  3. [local] Windows NTFS - Privileged File Access Enumeration
  4. [remote] Inteno IOPSYS Gateway - Improper Access Restrictions
  5. [webapps] College-Management-System 1.2 - Authentication Bypass
  6. [webapps] Ticket-Booking 1.4 - Authentication Bypass
  7. [webapps] LimeSurvey 3.17.13 - Cross-Site Scripting
  8. [webapps] phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
  9. [webapps] Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
  10. [dos] Folder Lock 7.7.9 - Denial of Service
  11. [dos] Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processi
  12. [dos] Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
  13. [webapps] eWON Flexy - Authentication Bypass
  14. [webapps] AVCON6 systems management platform - OGNL Remote Command Execution
  15. [local] Windows 10 - UAC Protection Bypass Via Windows Store (WSReset.exe) and Regist
  16. [local] Windows 10 - UAC Protection Bypass Via Windows Store (WSReset.exe) (Metasploi
  17. [remote] October CMS - Upload Protection Bypass Code Execution (Metasploit)
  18. [remote] LibreNMS - Collectd Command Injection (Metasploit)
  19. [webapps] WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
  20. [webapps] WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
  21. [webapps] WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
  22. [webapps] Dolibarr ERP-CRM 10.0.1 - SQL Injection
  23. [webapps] WordPress Plugin Sell Downloads 1.0.86 - Cross-Site Scripting
  24. [webapps] Rifatron Intelligent Digital Security System - 'animate.cgi' Stream Disclos
  25. [webapps] Enigma NMS 65.0.0 - SQL Injection
  26. [webapps] Enigma NMS 65.0.0 - OS Command Injection
  27. [webapps] Enigma NMS 65.0.0 - Cross-Site Request Forgery
  28. [webapps] Dolibarr ERP-CRM 10.0.1 - 'elemid' SQL Injection
  29. [webapps] Wordpress 5.2.3 - Cross-Site Host Modification
  30. [remote] FusionPBX 4.4.8 - Remote Code Execution
  31. [webapps] Inventory Webapp - 'itemquery' SQL injection
  32. [remote] Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Remote Code Execution
  33. [remote] AwindInc SNMP Service - Command Injection (Metasploit)
  34. [webapps] DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
  35. [webapps] WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
  36. [webapps] FileThingie 2.5.7 - Arbitrary File Upload
  37. [remote] Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command E
  38. [remote] Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (M
  39. [remote] Cisco UCS Director - default scpuser password (Metasploit)
  40. [local] ptrace - Sudo Token Privilege Escalation (Metasploit)
  41. [local] ktsuss 1.4 - suid Privilege Escalation (Metasploit)
  42. [webapps] Craft CMS 2.7.9/3.2.5 - Information Disclosure
  43. [local] Kaseya VSA agent 9.5 - Privilege Escalation
  44. [webapps] Alkacon OpenCMS 10.5.x - Local File inclusion
  45. [webapps] Alkacon OpenCMS 10.5.x - Cross-Site Scripting (2)
  46. [webapps] Alkacon OpenCMS 10.5.x - Cross-Site Scripting
  47. [remote] IntelBras TELEFONE IP TIP200/200 LITE 60.61.75.15 - Arbitrary File Read
  48. [webapps] Wordpress Plugin Event Tickets 4.10.7.1 - CSV Injection
  49. [local] ChaosPro 3.1 - SEH Buffer Overflow
  50. [local] ChaosPro 2.1 - SEH Buffer Overflow
  51. [local] ChaosPro 2.0 - SEH Buffer Overflow
  52. [webapps] Opencart 3.x - Cross-Site Scripting
  53. [remote] Cisco Email Security Appliance (IronPort) C160 - 'Host' Header Injection
  54. [dos] VX Search Enterprise 10.4.16 - 'User-Agent' Denial of Service
  55. [webapps] WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting
  56. [webapps] YouPHPTube 7.4 - Remote Code Execution
  57. [webapps] DomainMod 4.13 - Cross-Site Scripting
  58. [webapps] Sentrifugo 3.2 - Persistent Cross-Site Scripting
  59. [webapps] Sentrifugo 3.2 - File Upload Restriction Bypass
  60. [dos] Asus Precision TouchPad 11.0.0.25 - Denial of Service
  61. [local] Canon PRINT 2.5.5 - Information Disclosure
  62. [remote] QEMU - Denial of Service
  63. [dos] Easy MP3 Downloader 4.7.8.8 - 'Unlock Code' Denial of Service
  64. [dos] SQL Server Password Changer 1.90 - Denial of Service
  65. [dos] Webkit JSC: JIT - Uninitialized Variable Access in ArgumentsEliminationPhase::t
  66. [webapps] PilusCart 1.4.1 - Local File Disclosure
  67. [webapps] Jobberbase 2.0 - 'subscribe' SQL Injection
  68. [remote] Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Ci
  69. [webapps] WordPress Plugin GoURL.io < 1.4.14 - File Upload
  70. [webapps] Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
  71. [webapps] SQLiteManager 1.2.0 / 1.2.4 - Blind SQL Injection
  72. [dos] Outlook Password Recovery 2.10 - Denial of Service
  73. [webapps] Tableau - XML External Entity
  74. [local] Exim 4.87 / 4.91 - Local Privilege Escalation (Metasploit)
  75. [webapps] openITCOCKPIT 3.6.1-2 - Cross-Site Request Forgery
  76. [webapps] WordPress Plugin UserPro 4.9.32 - Cross-Site Scripting
  77. [webapps] WordPress Plugin Import Export WordPress Users 1.3.1 - CSV Injection
  78. [webapps] LSoft ListServ < 16.5-2018a - Cross-Site Scripting
  79. [webapps] Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal
  80. [remote] LibreOffice < 6.2 Macro - Python Code Execution (Metasploit)
  81. [webapps] Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure (meta
  82. [webapps] WordPress Plugin 2.2.1 - Cross-Site Request Forgery
  83. [webapps] YouPHPTube 7.2 - 'userCreate.json.php' SQL Injection
  84. [webapps] Webmin 1.920 - Remote Code Execution
  85. [webapps] Neo Billing 3.5 - Persistent Cross-Site Scripting
  86. [webapps] FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure
  87. [webapps] FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Met
  88. [webapps] Kimai 2 - Persistent Cross-Site Scripting
  89. [dos] RAR Password Recovery 1.80 - 'User Name and Registration Code' Denial of Servic
  90. [webapps] Web Wiz Forums 12.01 - 'PF' SQL Injection
  91. [webapps] Integria IMS 5.0.86 - Arbitrary File Upload
  92. [dos] GetGo Download Manager 6.2.2.3300 - Denial of Service
  93. [webapps] Joomla! component com_jsjobs 1.2.6 - Arbitrary File Deletion
  94. [webapps] EyesOfNetwork 5.1 - Authenticated Remote Command Execution
  95. [dos] Adobe Acrobat Reader DC for Windows - Double Free due to Malformed JP2 Stream
  96. [dos] Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malform
  97. [dos] Adobe Acrobat Reader DC for Windows - Heap-Based Memory Corruption due to Malfo
  98. [dos] Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow in CoolType.dl
  99. [dos] Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malform
  100. [dos] Adobe Acrobat Reader DC for Windows - Static Buffer Overflow due to Malformed F
  101. [dos] Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow While Processi
  102. [dos] Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Strea
  103. [dos] Adobe Acrobat Reader DC for Windows - Heap-Based Out-of-Bounds read due to Malf
  104. [dos] Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in FixSbitSubTabl
  105. [dos] Microsoft Font Subsetting - DLL Heap Corruption in MakeFormat12MergedGlyphList
  106. [dos] Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in WriteTableFrom
  107. [dos] Microsoft Font Subsetting - DLL Heap Corruption in ReadAllocFormat12CharGlyphMa
  108. [dos] Microsoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
  109. [dos] Microsoft Font Subsetting - DLL Heap Corruption in FixSbitSubTables
  110. [dos] Microsoft Font Subsetting - DLL Double Free in MergeFormat12Cmap / MakeFormat12
  111. [dos] Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in GetGlyphIdx
  112. [dos] Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FD
  113. [dos] Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Fo
  114. [local] Microsoft Windows Text Services Framework MSCTF - Multiple Vulnerabilities
  115. [dos] NSKeyedUnarchiver - Info Leak in Decoding SGBigUTF8String
  116. [remote] Agent Tesla Botnet - Arbitrary Code Execution (Metasploit)
  117. [webapps] ManageEngine opManager 12.3.150 - Authenticated Code Execution
  118. [dos] ABC2MTEX 1.6.1 - Command Line Stack Overflow
  119. [local] Microsoft Windows 10 AppXSvc Deployment Service - Arbitrary File Deletion
  120. [webapps] TortoiseSVN 1.12.1 - Remote Code Execution
  121. [webapps] WordPress Plugin Download Manager 2.5 - Cross-Site Request Forgery
  122. [webapps] D-Link DIR-600M - Authentication Bypass (Metasploit)
  123. [webapps] Joomla! Component JS Jobs (com_jsjobs) 1.2.5 - 'customfields.php' SQL Injec
  124. [dos] Windows PowerShell - Unsanitized Filename Command Execution
  125. [webapps] SugarCRM Enterprise 9.0.0 - Cross-Site Scripting
  126. [webapps] Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated OS Command Inj
  127. [webapps] Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated Configuration
  128. [remote] Azorult Botnet - SQL Injection
  129. [remote] Agent Tesla Botnet - Arbitrary Code Execution
  130. [local] Steam Windows Client - Local Privilege Escalation
  131. [dos] WebKit - UXSS via XSLT and Nested Document Replacements
  132. [dos] Linux - Use-After-Free Reads in show_numa_stats()
  133. [webapps] Joomla! Component JS Jobs (com_jsjobs) 1.2.5 - 'cities.php' SQL Injection
  134. [local] Ghidra (Linux) 9.0.4 - .gar Arbitrary Code Execution
  135. [remote] Webmin 1.920 - Unauthenticated Remote Code Execution (Metasploit)
  136. [remote] ManageEngine OpManager 12.4x - Unauthenticated Remote Command Execution (Met
  137. [remote] ManageEngine Application Manager 14.2 - Privilege Escalation / Remote Comman
  138. [remote] ManageEngine OpManager 12.4x - Privilege Escalation / Remote Command Executi
  139. [webapps] osTicket 1.12 - Persistent Cross-Site Scripting
  140. [webapps] osTicket 1.12 - Formula Injection
  141. [webapps] osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
  142. [webapps] Joomla! Component JS Support Ticket (com_jssupportticket) 1.1.6 - 'ticket.p
  143. [webapps] Joomla! Component JS Support Ticket (com_jssupportticket) 1.1.6 - 'ticketre
  144. [webapps] UNA 10.0.0 RC1 - 'polyglot.php' Persistent Cross-Site Scripting
  145. [webapps] Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
  146. [webapps] BSI Advance Hotel Booking System 2.0 - 'booking_details.php Persistent Cros
  147. [webapps] Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 -
  148. [webapps] Adive Framework 2.0.7 - Cross-Site Request Forgery
  149. [webapps] Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 -
  150. [remote] Baldr Botnet Panel - Arbitrary Code Execution (Metasploit)
  151. [webapps] Aptana Jaxer 1.0.3.4547 - Local File inclusion
  152. [webapps] Daily Expense Manager 1.0 - Cross-Site Request Forgery (Delete Income)
  153. [webapps] Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
  154. [dos] Google Chrome 74.0.3729.0 / 76.0.3789.0 - Heap Use-After-Free in blink::Present
  155. [webapps] WordPress Plugin JoomSport 3.3 - SQL Injection
  156. [remote] ARMBot Botnet - Arbitrary Code Execution
  157. [remote] Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
  158. [dos] macOS iMessage - Heap Overflow when Deserializing
  159. [webapps] 1CRM On-Premise Software 8.5.7 - Persistent Cross-Site Scripting
  160. [webapps] Rest - Cafe and Restaurant Website CMS - 'slug' SQL Injection
  161. [webapps] Sar2HTML 3.2.1 - Remote Command Execution
  162. [webapps] Cisco Catalyst 3850 Series Device Manager - Cross-Site Request Forgery
  163. [webapps] WebIncorp ERP - SQL injection
  164. [webapps] Ultimate Loan Manager 2.0 - Cross-Site Scripting
  165. [webapps] Oracle Hyperion Planning 11.1.2.3 - XML External Entity
  166. [remote] Redis 4.x / 5.x - Unauthenticated Code Execution (Metasploit)
  167. [dos] iMessage - NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
  168. [dos] iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
  169. [dos] iMessage - NSArray Deserialization can Invoke Subclass that does not Retain Ref
  170. [dos] macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving
  171. [dos] macOS / iOS JavaScriptCore - JSValue Use-After-Free in ValueProfiles
  172. [dos] macOS / iOS JavaScriptCore - Loop-Invariant Code Motion (LICM) Leaves Object Pr
  173. [webapps] Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
  174. [remote] WP Database Backup < 5.2 - Remote Code Execution (Metasploit)
  175. [remote] Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Met
  176. [webapps] GigToDo 1.3 - Cross-Site Scripting
  177. [webapps] WordPress Theme Real Estate 2.8.9 - Cross-Site Scripting
  178. [webapps] WordPress Plugin Simple Membership < 3.8.5 - Cross-Site Request Forgery
  179. [webapps] Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection
  180. [webapps] Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote
  181. [webapps] Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote
  182. [dos] pdfresurrect 0.15 - Buffer Overflow
  183. [webapps] Moodle Filepicker 3.5.2 - Server Side Request Forgery
  184. [local] Microsoft Windows 7 build 7601 (x86) - Local Privilege Escalation
  185. [local] Deepin Linux 15 - 'lastore-daemon' Local Privilege Escalation
  186. [local] ASAN/SUID - Local Privilege Escalation
  187. [local] Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (2)
  188. [local] S-nail < 14.8.16 - Local Privilege Escalation
  189. [local] VMware Workstation/Player < 12.5.5 - Local Privilege Escalation
  190. [local] Linux Kernel 4.4.0-21 < 4.4.0-51 (Ubuntu 14.04/16.04 x86-64) - 'AF_PACKET' Ra
  191. [local] Linux Kernel < 4.4.0/ < 4.8.0 (Ubuntu 14.04/16.04 / Linux Mint 17/18 / Zorin)
  192. [local] Linux Kernel 4.8.0-34 < 4.8.0-45 (Ubuntu / Linux Mint) - Packet Socket Local
  193. [local] Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Es
  194. [local] Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Es
  195. [local] Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Es
  196. [local] Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Es
  197. [local] Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalati
  198. [dos] WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
  199. [webapps] Ovidentia 8.4.3 - SQL Injection
  200. [webapps] Ovidentia 8.4.3 - Cross-Site Scripting
  201. [dos] Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
  202. [remote] Trend Micro Deep Discovery Inspector IDS - Security Bypass
  203. [webapps] WordPress Plugin Hybrid Composer 1.4.6 - Improper Access Restrictions
  204. [webapps] Cisco Wireless Controller 3.6.10E - Cross-Site Request Forgery
  205. [webapps] NoviSmart CMS - SQL injection
  206. [webapps] Axway SecureTransport 5 - Unauthenticated XML Injection
  207. [local] Comtrend-AR-5310 - Restricted Shell Escape
  208. [dos] BACnet Stack 0.8.6 - Denial of Service
  209. [local] Docker - Container Escape
  210. [webapps] REDCap < 9.1.2 - Cross-Site Scripting
  211. [webapps] Web Ofisi Firma 13 - 'oz' SQL Injection
  212. [webapps] Web Ofisi Rent a Car 3 - 'klima' SQL Injection
  213. [webapps] Web Ofisi Firma Rehberi 1 - 'il' SQL Injection
  214. [webapps] Web Ofisi Emlak 3 - 'emlak_durumu' SQL Injection
  215. [webapps] Web Ofisi Emlak 2 - 'ara' SQL Injection
  216. [webapps] Web Ofisi Platinum E-Ticaret 5 - 'q' SQL Injection
  217. [webapps] Web Ofisi E-Ticaret 3 - 'a' SQL Injection
  218. [webapps] fuelCMS 1.4.1 - Remote Code Execution
  219. [remote] MAPLE Computer WBT SNMP Administrator 2.0.195.15 - Remote Buffer Overflow (E
  220. [webapps] WordPress Plugin OneSignal 1.17.5 - 'subdomain' Persistent Cross-Site Scrip
  221. [local] Microsoft Windows 10 1903/1809 - RPCSS Activation Kernel Security Callback Pr
  222. [local] Windows - NtUserSetWindowFNID Win32k User Callback Privilege Escalation (Meta
  223. [local] Linux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME
  224. [webapps] Oracle Siebel CRM 19.0 - Persistent Cross-Site Scripting
  225. [dos] WinMPG iPod Convert 3.0 - 'Register' Denial of Service
  226. [remote] MAPLE Computer WBT SNMP Administrator 2.0.195.15 - Remote Buffer Overflow
  227. [remote] PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Com
  228. [local] Microsoft Windows 10 < build 17763 - AppXSvc Hard Link Privilege Escalation (
  229. [dos] Microsoft Compiled HTML Help / Uncompiled .chm File - XML External Entity Injec
  230. [local] DameWare Remote Support 12.0.0.509 - 'Host' Buffer Overflow (SEH)
  231. [webapps] CentOS Control Web Panel 0.9.8.838 - User Enumeration
  232. [webapps] CentOS Control Web Panel 0.9.8.836 - Privilege Escalation
  233. [webapps] CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
  234. [local] R 3.4.4 (Windows 10 x64) - Buffer Overflow SEH (DEP/ASLR Bypass)
  235. [webapps] FlightPath < 4.8.2 / < 5.0-rc2 - Local File Inclusion
  236. [dos] Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)
  237. [dos] Android 7 - 9 VideoPlayer - 'ihevcd_parse_pps' Out-of-Bounds Write
  238. [webapps] CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
  239. [webapps] NETGEAR WiFi Router JWNR2010v5 / R6080 - Authentication Bypass
  240. [local] Streamripper 2.6 - 'Song Pattern' Buffer Overflow
  241. [local] Microsoft Windows 10.0.17134.648 - HTTP -> SMB NTLM Reflection Leads to Privi
  242. [remote] Xymon 4.3.25 - useradm Command Execution (Metasploit)
  243. [dos] Microsoft Font Subsetting - DLL Heap Corruption in ComputeFormat4CmapData
  244. [webapps] Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Exe
  245. [webapps] Jenkins Dependency Graph View Plugin 0.13 - Persistent Cross-Site Scripting
  246. [webapps] Sahi Pro 8.0.0 - Remote Command Execution
  247. [webapps] MyT Project Management 1.5.1 - User[username] Persistent Cross-Site Scripti
  248. [webapps] Tenda D301 v2 Modem Router - Persistent Cross-Site Scripting
  249. [webapps] Sitecore 9.0 rev 171002 - Persistent Cross-Site Scripting
  250. [local] SNMPc Enterprise Edition 9/10 - Mapping Filename Buffer Overflow