المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 4 [5] 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67

  1. [webapps] Tailor Management System - 'id' SQL Injection
  2. [local] ShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service Path
  3. [webapps] Cabot 0.11.12 - Persistent Cross-Site Scripting
  4. [webapps] grocy 2.7.1 - Persistent Cross-Site Scripting
  5. [webapps] ManageEngine Applications Manager 14700 - Remote Code Execution (Authentica
  6. [local] Nord VPN-6.31.13.0 - 'nordvpn-service' Unquoted Service Path
  7. [webapps] Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
  8. [webapps] BloodX CMS 1.0 - Authentication Bypass
  9. [webapps] Daily Tracker System 1.0 - Authentication Bypass
  10. [webapps] SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
  11. [local] BarracudaDrive v6.5 - Insecure Folder Permissions
  12. [webapps] Stock Management System 1.0 - Cross-Site Request Forgery (Change Username)
  13. [webapps] Mara CMS 7.5 - Remote Code Execution (Authenticated)
  14. [webapps] moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
  15. [webapps] Mara CMS 7.5 - Reflective Cross-Site Scripting
  16. [webapps] Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
  17. [webapps] CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated)
  18. [webapps] Online Book Store 1.0 - 'id' SQL Injection
  19. [local] BlazeDVD 7.0 Professional - '.plf' Local Buffer Overflow (SEH,ASLR,DEP)
  20. [webapps] Online Shopping Alphaware 1.0 - 'id' SQL Injection
  21. [webapps] Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
  22. [webapps] SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting
  23. [webapps] Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
  24. [webapps] Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
  25. [webapps] Mida eFramework 2.9.0 - Remote Code Execution
  26. [local] ASX to MP3 converter 3.1.3.7.2010.11.05 - '.wax' Local Buffer Overflow (DEP,A
  27. [webapps] Eibiz i-Media Server Digital Signage 3.8.0 - Directory Traversal
  28. [webapps] Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
  29. [webapps] Eibiz i-Media Server Digital Signage 3.8.0 - Configuration Disclosure
  30. [webapps] LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
  31. [webapps] Eibiz i-Media Server Digital Signage 3.8.0 - Authentication Bypass
  32. [webapps] Complaint Management System 1.0 - 'cid' SQL Injection
  33. [webapps] Seowon SlC 130 Router - Remote Code Execution
  34. [webapps] vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
  35. [webapps] ElkarBackup 1.3.3 - Persistent Cross-Site Scripting
  36. [webapps] PNPSCADA 2.200816204020 - 'interf' SQL Injection (Authenticated)
  37. [webapps] Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal
  38. [webapps] Savsoft Quiz 5 - Stored Cross-Site Scripting
  39. [webapps] Pharmacy Medical Store and Sale Point 1.0 - 'catid' SQL Injection
  40. [webapps] Microsoft SharePoint Server 2019 - Remote Code Execution
  41. [webapps] QiHang Media Web Digital Signage 3.0.9 - Cleartext Credential Disclosure
  42. [webapps] QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Del
  43. [webapps] QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Dis
  44. [webapps] QiHang Media Web Digital Signage 3.0.9 - Remote Code Execution (Unauthentic
  45. [webapps] Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
  46. [webapps] Artica Proxy 4.3.0 - Authentication Bypass
  47. [webapps] GetSimple CMS Plugin Multi User 1.8.2 - Cross-Site Request Forgery (Add Adm
  48. [webapps] CMS Made Simple 2.2.14 - Authenticated Arbitrary File Upload
  49. [webapps] vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
  50. [webapps] Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)
  51. [webapps] Warehouse Inventory System 1.0 - Cross-Site Request Forgery (Change Admin P
  52. [webapps] ManageEngine ADSelfService Build prior to 6003 - Remote Code Execution (Una
  53. [local] BarcodeOCR 19.3.6 - 'BarcodeOCR' Unquoted Service Path
  54. [webapps] All-Dynamics Digital Signage System 2.0.2 - Cross-Site Request Forgery (Add
  55. [webapps] Daily Expenses Management System 1.0 - 'item' SQL Injection
  56. [local] CodeMeter 6.60 - 'CodeMeter.exe' Unquoted Service Path
  57. [webapps] Victor CMS 1.0 - 'Search' SQL Injection
  58. [dos] QlikView 12.50.20000.0 - 'FTP Server Address' Denial of Service (PoC)
  59. [webapps] Stock Management System 1.0 - Authentication Bypass
  60. [dos] ACTi NVR3 Standard or Professional Server 3.0.12.42 - Denial of Service (PoC)
  61. [dos] RTSP for iOS 1.0 - 'IP Address' Denial of Service (PoC)
  62. [webapps] Daily Expenses Management System 1.0 - 'username' SQL Injection
  63. [webapps] Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
  64. [dos] Mocha Telnet Lite for iOS 4.2 - 'User' Denial of Service (PoC)
  65. [webapps] Online Shopping Alphaware 1.0 - Authentication Bypass
  66. [webapps] Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary
  67. [webapps] Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site
  68. [webapps] Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
  69. [webapps] eGroupWare 1.14 - 'spellchecker.php' Remote Command Execution
  70. [local] docPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)
  71. [webapps] Rails 5.0.1 - Remote Code Execution
  72. [webapps] Virtual Airlines Manager 2.6.2 - Persistent Cross-Site Scripting
  73. [webapps] Socket.io-file 2.0.31 - Arbitrary File Upload
  74. [webapps] pfSense 2.4.4-p3 - Cross-Site Request Forgery
  75. [webapps] Sickbeard 0.1 - Cross-Site Request Forgery (Disable Authentication)
  76. [webapps] F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
  77. [webapps] elaniin CMS - Authentication Bypass
  78. [webapps] PandoraFMS 7.0 NG 746 - Persistent Cross-Site Scripting
  79. [webapps] Webtareas 2.1p - Arbitrary File Upload (Authenticated)
  80. [webapps] Bio Star 2.8.2 - Local File Inclusion
  81. [webapps] Koken CMS 0.22.24 - Arbitrary File Upload (Authenticated)
  82. [webapps] Online Course Registration 1.0 - Unauthenticated Remote Code Execution
  83. [webapps] LibreHealth 2.0.0 - Authenticated Remote Code Execution
  84. [webapps] UBICOD Medivision Digital Signage 1.5.1 - Cross-Site Request Forgery (Add A
  85. [local] Port Forwarding Wizard 4.8.0 - Buffer Overflow (SEH)
  86. [dos] Calavera UpLoader 3.5 - 'FTP Logi' Denial of Service (PoC + SEH Overwrite)
  87. [webapps] WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated Fi
  88. [webapps] WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injecti
  89. [webapps] Bludit 3.9.2 - Directory Traversal
  90. [local] Free MP3 CD Ripper 2.8 - Stack Buffer Overflow (SEH + Egghunter)
  91. [webapps] INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
  92. [webapps] GOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated)
  93. [local] Socusoft Photo to Video Converter Professional 8.07 - 'Output Folder' Buffer
  94. [webapps] ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
  95. [local] DiskBoss 7.7.14 - 'Reports and Data Directory' Buffer Overflow (SEH Egghunter
  96. [local] Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)
  97. [local] Nidesoft DVD Ripper 5.2.18 - Local Buffer Overflow (SEH)
  98. [local] FTPDummy 4.80 - Local Buffer Overflow (SEH)
  99. [local] Snes9K 0.09z - 'Port Number' Buffer Overflow (SEH)
  100. [webapps] UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
  101. [webapps] Sophos VPN Web Panel 2020 - Denial of Service (Poc)
  102. [webapps] WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
  103. [webapps] Docsify.js 4.11.4 - Reflective Cross-Site Scripting
  104. [local] NetPCLinker 1.0.0.0 - Buffer Overflow (SEH Egghunter)
  105. [local] Simple Startup Manager 1.17 - 'File' Local Buffer Overflow (PoC)
  106. [webapps] CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
  107. [local] Sonar Qube 8.3.1 - 'SonarQube Service' Unquoted Service Path
  108. [webapps] RiteCMS 2.2.1 - Remote Code Execution
  109. [webapps] Wing FTP Server 6.3.8 - Remote Code Execution (Authenticated)
  110. [webapps] Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting
  111. [webapps] Infor Storefront B2B 1.0 - 'usr_name' SQL Injection
  112. [webapps] Online Polling System 1.0 - Authentication Bypass
  113. [webapps] Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass
  114. [webapps] Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
  115. [webapps] SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
  116. [webapps] Zyxel Armor X1 WAP6806 - Directory Traversal
  117. [webapps] BSA Radar 1.6.7234.24750 - Local File Inclusion
  118. [webapps] Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Rem
  119. [webapps] Park Ticketing Management System 1.0 - 'viewid' SQL Injection
  120. [webapps] Park Ticketing Management System 1.0 - Authentication Bypass
  121. [webapps] HelloWeb 2.0 - Arbitrary File Download
  122. [webapps] Barangay Management System 1.0 - Authentication Bypass
  123. [remote] Aruba ClearPass Policy Manager 6.7.0 - Unauthenticated Remote Command Execut
  124. [webapps] Wordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site
  125. [local] FrootVPN 4.8 - 'frootvpn' Unquoted Service Path
  126. [webapps] Savsoft Quiz 5 - Persistent Cross-Site Scripting
  127. [webapps] PHP 7.4 FFI - 'disable_functions' Bypass
  128. [webapps] BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
  129. [webapps] SuperMicro IPMI 03.40 - Cross-Site Request Forgery (Add Admin)
  130. [remote] Microsoft Windows mshta.exe 2019 - XML External Entity Injection
  131. [webapps] BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
  132. [local] Sony Playstation 4 (PS4) < 7.02 / FreeBSD 9 / FreeBSD 12 - 'ip6_setpktopt' Ke
  133. [webapps] Sickbeard 0.1 - Remote Command Injection
  134. [webapps] Online Shopping Portal 3.1 - 'email' SQL Injection
  135. [webapps] Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
  136. [webapps] BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 <
  137. [webapps] BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 <
  138. [webapps] Nagios XI 5.6.12 - 'export-rrd.php' Remote Code Execution
  139. [webapps] RSA IG&L Aveksa 7.1.1 - Remote Code Execution
  140. [dos] Grafana 7.0.1 - Denial of Service (PoC)
  141. [dos] Fire Web Server 0.1 - Remote Denial of Service (PoC)
  142. [webapps] File Management System 1.1 - Persistent Cross-Site Scripting
  143. [webapps] RiteCMS 2.2.1 - Authenticated Remote Code Execution
  144. [webapps] OCS Inventory NG 2.7 - Remote Code Execution
  145. [webapps] WhatsApp Remote Code Execution - Paper
  146. [webapps] ZenTao Pro 8.8.2 - Command Injection
  147. [local] RM Downloader 2.50.60 2006.06.23 - 'Load' Local Buffer Overflow (EggHunter) (
  148. [webapps] e-learning Php Script 0.1.0 - 'search' SQL Injection
  149. [webapps] PHP-Fusion 9.03.60 - PHP Object Injection
  150. [webapps] Online Shopping Portal 3.1 - Authentication Bypass
  151. [webapps] Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting
  152. [webapps] Reside Property Management 3.0 - 'profile' SQL Injection
  153. [local] KiteService 1.2020.618.0 - Unquoted Service Path
  154. [webapps] OpenEMR 5.0.1 - 'controller' Remote Code Execution
  155. [local] Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
  156. [webapps] FHEM 6.0 - Local File Inclusion
  157. [remote] mySCADA myPRO 7 - Hardcoded Credentials
  158. [webapps] BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
  159. [local] Lansweeper 7.2 - Incorrect Access Control
  160. [webapps] Online Student Enrollment System 1.0 - Cross-Site Request Forgery (Add Stud
  161. [dos] Code Blocks 20.03 - Denial Of Service (PoC)
  162. [webapps] Responsive Online Blog 1.0 - 'id' SQL Injection
  163. [webapps] Student Enrollment 1.0 - Unauthenticated Remote Code Execution
  164. [webapps] Odoo 12.0 - Local File Inclusion
  165. [webapps] Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Uploa
  166. [webapps] WebPort 1.19.1 - Reflected Cross-Site Scripting
  167. [webapps] WebPort 1.19.1 - 'setup' Reflected Cross-Site Scripting
  168. [dos] Frigate 2.02 - Denial Of Service (PoC)
  169. [webapps] FileRun 2019.05.21 - Reflected Cross-Site Scripting
  170. [webapps] Beauty Parlour Management System 1.0 - Authentication Bypass
  171. [local] Code Blocks 17.12 - 'File Name' Local Buffer Overflow (Unicode) (SEH) (PoC)
  172. [webapps] OpenCTI 3.3.1 - Directory Traversal
  173. [webapps] College-Management-System-Php 1.0 - Authentication Bypass
  174. [webapps] Gila CMS 1.11.8 - 'query' SQL Injection
  175. [local] Bandwidth Monitor 3.9 - 'Svc10StrikeBandMontitor' Unquoted Service Path
  176. [webapps] NETGEAR
  177. [remote] SOS JobScheduler 1.13.3 - Stored Password Decryption
  178. [webapps] Sysax MultiServer 6.90 - Reflected Cross Site Scripting
  179. [webapps] Avaya IP Office 11 - Password Disclosure
  180. [webapps] SmarterMail 16 - Arbitrary File Upload
  181. [local] Frigate Professional 3.36.0.9 - 'Find Computer' Local Buffer Overflow (SEH) (
  182. [dos] Savant Web Server 3.1 - Denial of-Service (PoC)
  183. [dos] ALLPlayer 7.5 - Denial of-Service (PoC)
  184. [dos] Sync Breeze Enterprise 10.0.28 - Denial of-Service (PoC)
  185. [dos] Sync Breeze Enterprise 10.4.18 - Denial of-Service (PoC)
  186. [local] WinGate 9.4.1.5998 - Insecure Folder Permissions
  187. [webapps] Virtual Airlines Manager 2.6.2 - 'id' SQL Injection
  188. [remote] HFS Http File Server 2.3m Build 300 - Buffer Overflow (PoC)
  189. [local] 10-Strike Bandwidth Monitor 3.9 - Buffer Overflow (SEH,DEP,ASLR)
  190. [webapps] Sistem Informasi Pengumuman Kelulusan Online 1.0 - Cross-Site Request Forge
  191. [webapps] Joomla J2 Store 3.3.11 - 'filter_order_Dir' SQL Injection (Authenticated)
  192. [webapps] Bludit 3.9.12 - Directory Traversal
  193. [webapps] Virtual Airlines Manager 2.6.2 - 'airport' SQL Injection
  194. [local] Quick Player 1.3 - '.m3l' Buffer Overflow (Unicode & SEH)
  195. [webapps] Virtual Airlines Manager 2.6.2 - 'notam' SQL Injection
  196. [local] Frigate 3.36.0.9 - 'Command Line' Local Buffer Overflow (SEH) (PoC)
  197. [webapps] Kyocera Printer d-COPIA253MF - Directory Traversal (PoC)
  198. [webapps] Online-Exam-System 2015 - 'feedback' SQL Injection
  199. [webapps] Online Course Registration 1.0 - Authentication Bypass
  200. [webapps] Secure Computing SnapGear Management Console SG560 3.1.5 - Arbitrary File R
  201. [webapps] Cayin Signage Media Player 3.0 - Remote Command Injection (root)
  202. [webapps] Cayin Digital Signage System xPost 2.5 - Remote Command Injection
  203. [webapps] SnapGear Management Console SG560 3.1.5 - Cross-Site Request Forgery (Add S
  204. [webapps] Online Marriage Registration System 1.0 - Remote Code Execution
  205. [webapps] Cayin Content Management Server 11.0 - Remote Command Injection (root)
  206. [webapps] D-Link DIR-615 T1 20.10 - CAPTCHA Bypass
  207. [webapps] Navigate CMS 2.8.7 - Authenticated Directory Traversal
  208. [webapps] Navigate CMS 2.8.7 - Cross-Site Request Forgery (Add Admin)
  209. [webapps] VMWAre vCloud Director 9.7.0.15498291 - Remote Code Execution
  210. [webapps] Oriol Espinal CMS 1.0 - 'id' SQL Injection
  211. [webapps] Clinic Management System 1.0 - Authenticated Arbitrary File Upload
  212. [webapps] Navigate CMS 2.8.7 - ''sidx' SQL Injection (Authenticated)
  213. [webapps] Clinic Management System 1.0 - Unauthenticated Remote Code Execution
  214. [webapps] Hostel Management System 2.0 - 'id' SQL Injection (Unauthenticated)
  215. [local] IObit Uninstaller 9.5.0.15 - 'IObit Uninstaller Service' Unquoted Service Pat
  216. [webapps] AirControl 1.4.2 - PreAuth Remote Code Execution
  217. [remote] vCloud Director 9.7.0.15498291 - Remote Code Execution
  218. [webapps] OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated)
  219. [webapps] Clinic Management System 1.0 - Authentication Bypass
  220. [remote] Microsoft Windows - 'SMBGhost' Remote Code Execution
  221. [webapps] QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
  222. [webapps] VMware vCenter Server 6.7 - Authentication Bypass
  223. [webapps] Wordpress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
  224. [webapps] Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass
  225. [webapps] WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete
  226. [webapps] QNAP QTS and Photo Station 6.0.3 - Remote Command Execution
  227. [webapps] NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection
  228. [webapps] Online-Exam-System 2015 - 'fid' SQL Injection
  229. [webapps] EyouCMS 1.4.6 - Persistent Cross-Site Scripting
  230. [webapps] Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting
  231. [webapps] LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting
  232. [webapps] osTicket 1.14.1 - 'Ticket Queue' Persistent Cross-Site Scripting
  233. [webapps] osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting
  234. [webapps] Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting
  235. [webapps] OXID eShop 6.3.4 - 'sorting' SQL Injection
  236. [dos] BIND - 'TSIG' Denial of Service
  237. [local] StreamRipper32 2.6 - Buffer Overflow (PoC)
  238. [webapps] Joomla! Plugin XCloner Backup 3.5.3 - Local File Inclusion (Authenticated)
  239. [webapps] Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
  240. [webapps] WordPress Plugin Drag and Drop File Upload Contact Form 1.3.3.2 - Remote Co
  241. [webapps] OpenEMR 5.0.1 - Remote Code Execution
  242. [webapps] Open-AudIT 3.3.0 - Reflective Cross-Site Scripting (Authenticated)
  243. [remote] Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
  244. [remote] Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploi
  245. [local] GoldWave - Buffer Overflow (SEH Unicode)
  246. [webapps] Victor CMS 1.0 - 'add_user' Persistent Cross-Site Scripting
  247. [webapps] Online Discussion Forum Site 1.0 - Remote Code Execution
  248. [webapps] Wordpress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated)
  249. [remote] WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metas
  250. [webapps] Gym Management System 1.0 - Unauthenticated Remote Code Execution