المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 4 5 [6] 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68

  1. [webapps] CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Inject
  2. [webapps] Gym Management System 1.0 - Authentication Bypass
  3. [webapps] Gym Management System 1.0 - Stored Cross Site Scripting
  4. [webapps] TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
  5. [webapps] Bludit 3.9.2 - Auth Bruteforce Bypass
  6. [webapps] Online Library Management System 1.0 - Arbitrary File Upload
  7. [webapps] Ajenti 2.1.36 - Remote Code Execution (Authenticated)
  8. [webapps] Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
  9. [webapps] User Registration & Login and User Management System 2.1 - SQL Injection
  10. [webapps] Car Rental Management System 1.0 - Arbitrary File Upload
  11. [webapps] Point of Sales 1.0 - 'id' SQL Injection
  12. [webapps] Point of Sales 1.0 - 'username' SQL Injection
  13. [webapps] Gym Management System 1.0 - 'id' SQL Injection
  14. [webapps] Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
  15. [webapps] Lot Reservation Management System 1.0 - Authentication Bypass
  16. [webapps] School Faculty Scheduling System 1.0 - 'id' SQL Injection
  17. [webapps] School Faculty Scheduling System 1.0 - 'username' SQL Injection
  18. [webapps] Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
  19. [webapps] Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
  20. [webapps] Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scrip
  21. [webapps] Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scriptin
  22. [webapps] GOautodial 4.0 - Authenticated Shell Upload
  23. [webapps] School Faculty Scheduling System 1.0 - Authentication Bypass POC
  24. [webapps] School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
  25. [webapps] Hrsale 2.0.0 - Local File Inclusion
  26. [webapps] WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting
  27. [webapps] WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
  28. [webapps] Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
  29. [webapps] Mobile Shop System v1.0 - SQL Injection Authentication Bypass
  30. [webapps] RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
  31. [webapps] User Registration & Login and User Management System With admin panel 2.1 -
  32. [webapps] WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
  33. [webapps] Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated)
  34. [webapps] Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
  35. [webapps] Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Co
  36. [webapps] Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
  37. [webapps] Comtrend AR-5387un router - Persistent XSS (Authenticated)
  38. [webapps] Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
  39. [webapps] Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
  40. [webapps] Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
  41. [webapps] Textpattern CMS 4.6.2 - Cross-site Request Forgery
  42. [webapps] HiSilicon video encoders - RCE via unauthenticated upload of malicious firm
  43. [webapps] HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
  44. [webapps] HiSilicon Video Encoders - Full admin access via backdoor password
  45. [webapps] HiSilicon Video Encoders - RCE via unauthenticated command injection
  46. [webapps] HiSilicon Video Encoders - Unauthenticated file disclosure via path travers
  47. [webapps] Online Student's Management System 1.0 - Remote Code Execution (Authenticat
  48. [webapps] Online Discussion Forum Site 1.0 - XSS in Messaging System
  49. [webapps] Online Job Portal 1.0 - Cross Site Scripting (Stored)
  50. [webapps] Tourism Management System 1.0 - Arbitrary File Upload
  51. [webapps] Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
  52. [webapps] Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
  53. [webapps] Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
  54. [webapps] CS-Cart 1.3.3 - authenticated RCE
  55. [webapps] CS-Cart 1.3.3 - 'classes_dir' LFI
  56. [webapps] Seat Reservation System 1.0 - Unauthenticated SQL Injection
  57. [webapps] Hotel Management System 1.0 - Remote Code Execution (Authenticated)
  58. [webapps] Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
  59. [webapps] aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated
  60. [webapps] Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated)
  61. [webapps] Company Visitor Management System (CVMS) 1.0 - Authentication Bypass
  62. [webapps] Alumni Management System 1.0 - Authentication Bypass
  63. [webapps] Employee Management System 1.0 - Authentication Bypass
  64. [webapps] Employee Management System 1.0 - Cross Site Scripting (Stored)
  65. [webapps] Zoo Management System 1.0 - Authentication Bypass
  66. [webapps] Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass
  67. [webapps] rConfig 3.9.5 - Remote Code Execution (Unauthenticated)
  68. [webapps] Vehicle Parking Management System 1.0 - Authentication Bypass
  69. [local] Guild Wars 2 - Insecure Folder Permissions
  70. [webapps] NodeBB Forum 1.12.2-1.14.2 - Account Takeover
  71. [webapps] TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection
  72. [local] Battle.Net 1.27.1.12428 - Insecure File Permissions
  73. [webapps] berliCRM 1.0.24 - 'src_record' SQL Injection
  74. [webapps] Cisco ASA and FTD 9.6.4.42 - Path Traversal
  75. [webapps] Liman 0.7 - Cross-Site Request Forgery (Change Password)
  76. [webapps] Online Students Management System 1.0 - 'username' SQL Injections
  77. [webapps] MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated)
  78. [webapps] Small CRM 2.0 - 'email' SQL Injection
  79. [webapps] openMAINT 1.1-2.4.2 - Arbitrary File Upload
  80. [webapps] DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated)
  81. [webapps] Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
  82. [webapps] SEO Panel 4.6.0 - Remote Code Execution
  83. [webapps] D-Link DSR-250N 3.12 - Denial of Service (PoC)
  84. [webapps] Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting
  85. [dos] BACnet Test Server 1.01 - Remote Denial of Service (PoC)
  86. [webapps] EasyPMS 1.0.0 - Authentication Bypass
  87. [webapps] Karel IP Phone IP1211 Web Management Panel - Directory Traversal
  88. [webapps] SpamTitan 7.07 - Unauthenticated Remote Code Execution
  89. [webapps] MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
  90. [webapps] Photo Share Website 1.0 - Persistent Cross-Site Scripting
  91. [webapps] MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
  92. [webapps] Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
  93. [webapps] CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
  94. [webapps] GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated)
  95. [webapps] WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated)
  96. [webapps] MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated)
  97. [webapps] SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration
  98. [webapps] SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Adm
  99. [webapps] SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure
  100. [webapps] BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path
  101. [webapps] BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Reque
  102. [remote] Sony IPELA Network Camera 1.82.01 - 'ftpclient.cgi' Remote Stack Buffer Over
  103. [local] CloudMe 1.11.2 - Buffer Overflow ROP (DEP,ASLR)
  104. [local] BearShare Lite 5.2.5 - 'Advanced Search'Buffer Overflow in (PoC)
  105. [webapps] WebsiteBaker 2.12.2 - Remote Code Execution
  106. [webapps] Joplin 1.0.245 - Arbitrary Code Execution (PoC)
  107. [local] MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
  108. [webapps] Mida eFramework 2.8.9 - Remote Code Execution
  109. [webapps] B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure
  110. [webapps] B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Ma
  111. [webapps] Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated)
  112. [webapps] BigTree CMS 4.4.10 - Remote Code Execution
  113. [webapps] Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
  114. [webapps] Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticate
  115. [webapps] Online Food Ordering System 1.0 - Remote Code Execution
  116. [webapps] Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
  117. [webapps] Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
  118. [webapps] B-swiss 3 Digital Signage System 3.6.5 - Remote Code Execution
  119. [webapps] Mida eFramework 2.9.0 - Back Door Access
  120. [webapps] Seat Reservation System 1.0 - 'id' SQL Injection
  121. [local] ForensiTAppxService 2.2.0.4 - 'ForensiTAppxService.exe' Unquoted Service Path
  122. [webapps] BlackCat CMS 1.3.6 - Cross-Site Request Forgery
  123. [webapps] Online Shop Project 1.0 - 'p' SQL Injection
  124. [webapps] Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
  125. [webapps] SpamTitan 7.07 - Remote Code Execution (Authenticated)
  126. [remote] Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
  127. [local] Windows TCPIP Finger Command - C2 Channel and Bypassing Security Software
  128. [webapps] Piwigo 2.10.1 - Cross Site Scripting
  129. [webapps] Tailor MS 1.0 - Reflected Cross-Site Scripting
  130. [webapps] ThinkAdmin 6 - Arbitrarily File Read
  131. [webapps] Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated)
  132. [local] Pearson Vue VTS 2.3.1911 Installer - 'VUEApplicationWrapper' Unquoted Service
  133. [webapps] RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)
  134. [local] Rapid7 Nexpose Installer 6.6.39 - 'nexposeengine' Unquoted Service Path
  135. [webapps] RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
  136. [local] Internet Explorer 11 - Use-After-Free
  137. [webapps] Tea LaTex 1.0 - Remote Code Execution (Unauthenticated)
  138. [webapps] VTENEXT 19 CE - Remote Code Execution
  139. [local] Gnome Fonts Viewer 3.34.0 - Heap Corruption
  140. [webapps] ZTE Router F602W - Captcha Bypass
  141. [webapps] CuteNews 2.1.2 - Remote Code Execution
  142. [webapps] Tiandy IPC and NVR 9.12.7 - Credential Disclosure
  143. [webapps] Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin pass
  144. [webapps] Tailor Management System - 'id' SQL Injection
  145. [local] Audio Playback Recorder 3.2.2 - Local Buffer Overflow (SEH)
  146. [local] Input Director 1.4.3 - 'Input Director' Unquoted Service Path
  147. [local] ShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service Path
  148. [webapps] ManageEngine Applications Manager 14700 - Remote Code Execution (Authentica
  149. [webapps] grocy 2.7.1 - Persistent Cross-Site Scripting
  150. [webapps] Cabot 0.11.12 - Persistent Cross-Site Scripting
  151. [local] Nord VPN-6.31.13.0 - 'nordvpn-service' Unquoted Service Path
  152. [local] BarracudaDrive v6.5 - Insecure Folder Permissions
  153. [webapps] SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
  154. [webapps] Daily Tracker System 1.0 - Authentication Bypass
  155. [webapps] BloodX CMS 1.0 - Authentication Bypass
  156. [webapps] Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
  157. [webapps] Stock Management System 1.0 - Cross-Site Request Forgery (Change Username)
  158. [webapps] moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
  159. [webapps] Mara CMS 7.5 - Remote Code Execution (Authenticated)
  160. [webapps] CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated)
  161. [webapps] Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
  162. [webapps] Mara CMS 7.5 - Reflective Cross-Site Scripting
  163. [local] BlazeDVD 7.0 Professional - '.plf' Local Buffer Overflow (SEH,ASLR,DEP)
  164. [webapps] Online Book Store 1.0 - 'id' SQL Injection
  165. [webapps] Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
  166. [webapps] SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting
  167. [webapps] Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
  168. [webapps] Online Shopping Alphaware 1.0 - 'id' SQL Injection
  169. [webapps] Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
  170. [local] ASX to MP3 converter 3.1.3.7.2010.11.05 - '.wax' Local Buffer Overflow (DEP,A
  171. [webapps] Mida eFramework 2.9.0 - Remote Code Execution
  172. [webapps] Eibiz i-Media Server Digital Signage 3.8.0 - Directory Traversal
  173. [webapps] Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
  174. [webapps] Eibiz i-Media Server Digital Signage 3.8.0 - Configuration Disclosure
  175. [webapps] Eibiz i-Media Server Digital Signage 3.8.0 - Authentication Bypass
  176. [webapps] LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
  177. [webapps] vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
  178. [webapps] Seowon SlC 130 Router - Remote Code Execution
  179. [webapps] Complaint Management System 1.0 - 'cid' SQL Injection
  180. [webapps] PNPSCADA 2.200816204020 - 'interf' SQL Injection (Authenticated)
  181. [webapps] ElkarBackup 1.3.3 - Persistent Cross-Site Scripting
  182. [webapps] Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal
  183. [webapps] Savsoft Quiz 5 - Stored Cross-Site Scripting
  184. [webapps] Pharmacy Medical Store and Sale Point 1.0 - 'catid' SQL Injection
  185. [webapps] QiHang Media Web Digital Signage 3.0.9 - Remote Code Execution (Unauthentic
  186. [webapps] QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Dis
  187. [webapps] QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Del
  188. [webapps] QiHang Media Web Digital Signage 3.0.9 - Cleartext Credential Disclosure
  189. [webapps] Microsoft SharePoint Server 2019 - Remote Code Execution
  190. [webapps] Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
  191. [webapps] GetSimple CMS Plugin Multi User 1.8.2 - Cross-Site Request Forgery (Add Adm
  192. [webapps] Artica Proxy 4.3.0 - Authentication Bypass
  193. [webapps] vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
  194. [webapps] CMS Made Simple 2.2.14 - Authenticated Arbitrary File Upload
  195. [webapps] Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)
  196. [local] BarcodeOCR 19.3.6 - 'BarcodeOCR' Unquoted Service Path
  197. [webapps] ManageEngine ADSelfService Build prior to 6003 - Remote Code Execution (Una
  198. [webapps] Warehouse Inventory System 1.0 - Cross-Site Request Forgery (Change Admin P
  199. [webapps] Daily Expenses Management System 1.0 - 'item' SQL Injection
  200. [webapps] All-Dynamics Digital Signage System 2.0.2 - Cross-Site Request Forgery (Add
  201. [local] CodeMeter 6.60 - 'CodeMeter.exe' Unquoted Service Path
  202. [webapps] Victor CMS 1.0 - 'Search' SQL Injection
  203. [webapps] Stock Management System 1.0 - Authentication Bypass
  204. [dos] QlikView 12.50.20000.0 - 'FTP Server Address' Denial of Service (PoC)
  205. [dos] ACTi NVR3 Standard or Professional Server 3.0.12.42 - Denial of Service (PoC)
  206. [webapps] Daily Expenses Management System 1.0 - 'username' SQL Injection
  207. [dos] RTSP for iOS 1.0 - 'IP Address' Denial of Service (PoC)
  208. [dos] Mocha Telnet Lite for iOS 4.2 - 'User' Denial of Service (PoC)
  209. [webapps] Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
  210. [webapps] Online Shopping Alphaware 1.0 - Authentication Bypass
  211. [webapps] Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site
  212. [webapps] Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary
  213. [webapps] Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
  214. [webapps] eGroupWare 1.14 - 'spellchecker.php' Remote Command Execution
  215. [webapps] Rails 5.0.1 - Remote Code Execution
  216. [local] docPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)
  217. [webapps] F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
  218. [webapps] Sickbeard 0.1 - Cross-Site Request Forgery (Disable Authentication)
  219. [webapps] pfSense 2.4.4-p3 - Cross-Site Request Forgery
  220. [webapps] Socket.io-file 2.0.31 - Arbitrary File Upload
  221. [webapps] Virtual Airlines Manager 2.6.2 - Persistent Cross-Site Scripting
  222. [webapps] Online Course Registration 1.0 - Unauthenticated Remote Code Execution
  223. [webapps] Koken CMS 0.22.24 - Arbitrary File Upload (Authenticated)
  224. [webapps] Bio Star 2.8.2 - Local File Inclusion
  225. [webapps] Webtareas 2.1p - Arbitrary File Upload (Authenticated)
  226. [webapps] PandoraFMS 7.0 NG 746 - Persistent Cross-Site Scripting
  227. [webapps] elaniin CMS - Authentication Bypass
  228. [webapps] LibreHealth 2.0.0 - Authenticated Remote Code Execution
  229. [webapps] INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
  230. [local] Free MP3 CD Ripper 2.8 - Stack Buffer Overflow (SEH + Egghunter)
  231. [webapps] Bludit 3.9.2 - Directory Traversal
  232. [webapps] WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injecti
  233. [webapps] WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated Fi
  234. [dos] Calavera UpLoader 3.5 - 'FTP Logi' Denial of Service (PoC + SEH Overwrite)
  235. [local] Port Forwarding Wizard 4.8.0 - Buffer Overflow (SEH)
  236. [webapps] UBICOD Medivision Digital Signage 1.5.1 - Cross-Site Request Forgery (Add A
  237. [webapps] ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
  238. [local] Socusoft Photo to Video Converter Professional 8.07 - 'Output Folder' Buffer
  239. [webapps] GOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated)
  240. [local] Nidesoft DVD Ripper 5.2.18 - Local Buffer Overflow (SEH)
  241. [local] Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)
  242. [local] DiskBoss 7.7.14 - 'Reports and Data Directory' Buffer Overflow (SEH Egghunter
  243. [local] Snes9K 0.09z - 'Port Number' Buffer Overflow (SEH)
  244. [local] FTPDummy 4.80 - Local Buffer Overflow (SEH)
  245. [webapps] UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
  246. [webapps] Sophos VPN Web Panel 2020 - Denial of Service (Poc)
  247. [webapps] WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
  248. [webapps] Docsify.js 4.11.4 - Reflective Cross-Site Scripting
  249. [local] NetPCLinker 1.0.0.0 - Buffer Overflow (SEH Egghunter)
  250. [webapps] CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)