المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 4 5 6 [7] 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67

  1. [webapps] osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
  2. [webapps] BoltWire 6.03 - Local File Inclusion
  3. [remote] Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
  4. [webapps] Online Scheduling System 1.0 - Authentication Bypass
  5. [webapps] Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
  6. [webapps] HardDrive 2.1 for iOS - Arbitrary File Upload
  7. [webapps] Super Backup 2.0.5 for iOS - Directory Traversal
  8. [webapps] php-fusion 9.03.50 - Persistent Cross-Site Scripting
  9. [webapps] Online Scheduling System 1.0 - Persistent Cross-Site Scripting
  10. [dos] VirtualTablet Server 3.0.2 - Denial of Service (PoC)
  11. [webapps] ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
  12. [local] Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
  13. [webapps] hits script 1.0 - 'item_name' SQL Injection
  14. [local] EmEditor 19.8 - Insecure File Permissions
  15. [local] Internet Download Manager 6.37.11.1 - Stack Buffer Overflow (PoC)
  16. [local] Andrea ST Filters Service 1.0.64.7 - 'Andrea ST Filters Service ' Unquoted
  17. [webapps] Easy Transfer 1.7 for iOS - Directory Traversal
  18. [webapps] School ERP Pro 1.0 - Arbitrary File Read
  19. [webapps] Open-AudIT Professional 3.3.1 - Remote Code Execution
  20. [webapps] School ERP Pro 1.0 - Remote Code Execution
  21. [local] NVIDIA Update Service Daemon 1.0.21 - 'nvUpdatusService' Unquoted Service Pa
  22. [webapps] School ERP Pro 1.0 - 'es_messagesid' SQL Injection
  23. [remote] CloudMe 1.11.2 - Buffer Overflow (PoC)
  24. [local] Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
  25. [local] Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
  26. [webapps] Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
  27. [webapps] Online Course Registration 2.0 - Authentication Bypass
  28. [webapps] Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
  29. [webapps] Online shopping system advanced 1.0 - 'p' SQL Injection
  30. [webapps] Netis E1+ 1.2.32533 - Backdoor Account (root)
  31. [webapps] PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
  32. [webapps] Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
  33. [local] Popcorn Time 6.2 - 'Update service' Unquoted Service Path
  34. [webapps] Edimax EW-7438RPn 1.13 - Remote Code Execution
  35. [webapps] EspoCRM 5.8.5 - Privilege Escalation
  36. [webapps] Sky File 2.1.0 iOS - Directory Traversal
  37. [webapps] Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
  38. [webapps] Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
  39. [webapps] Complaint Management System 4.2 - Authentication Bypass
  40. [webapps] Complaint Management System 4.2 - Persistent Cross-Site Scripting
  41. [webapps] User Management System 2.0 - Authentication Bypass
  42. [webapps] User Management System 2.0 - Persistent Cross-Site Scripting
  43. [webapps] Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
  44. [webapps] Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
  45. [webapps] Edimax EW-7438RPn - Information Disclosure (WiFi Password)
  46. [local] RM Downloader 3.1.3.2.2010.06.13 - 'Load' Buffer Overflow (SEH)
  47. [remote] Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
  48. [webapps] P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
  49. [webapps] jizhi CMS 1.6.7 - Arbitrary File Download
  50. [webapps] NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
  51. [local] Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
  52. [webapps] IQrouter 3.3.1 Firmware - Remote Code Execution
  53. [webapps] CSZ CMS 1.2.7 - 'title' HTML Injection
  54. [webapps] PMB 5.6 - 'logid' SQL Injection
  55. [webapps] CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
  56. [remote] Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
  57. [local] Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path
  58. [local] Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH)
  59. [local] Nsauditor 3.2.1.0 - Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))
  60. [webapps] Fork CMS 5.8.0 - Persistent Cross-Site Scripting
  61. [local] Atomic Alarm Clock 6.3 - Stack Overflow (Unicode+SEH)
  62. [webapps] Centreon 19.10.5 - 'id' SQL Injection
  63. [local] Code Blocks 16.01 - Buffer Overflow (SEH) UNICODE
  64. [remote] Nexus Repository Manager - Java EL Injection RCE (Metasploit)
  65. [remote] Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
  66. [local] VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
  67. [remote] DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
  68. [remote] PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metas
  69. [remote] Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
  70. [remote] ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
  71. [remote] Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
  72. [remote] TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit
  73. [local] BlazeDVD 7.0.2 - Buffer Overflow (SEH)
  74. [webapps] Xeroneit Library Management System 3.0 - 'category' SQL Injection
  75. [webapps] File Transfer iFamily 2.1 - Directory Traversal
  76. [webapps] DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
  77. [webapps] Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
  78. [webapps] SeedDMS 5.1.18 - Persistent Cross-Site Scripting
  79. [webapps] Pinger 1.0 - Remote Code Execution
  80. [webapps] SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
  81. [webapps] AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
  82. [webapps] Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
  83. [webapps] WSO2 3.1.0 - Persistent Cross-Site Scripting
  84. [webapps] Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
  85. [local] B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)
  86. [webapps] MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
  87. [webapps] Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
  88. [local] Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (S
  89. [webapps] WSO2 3.1.0 - Arbitrary File Delete
  90. [webapps] Webtateas 2.0 - Arbitrary File Read
  91. [webapps] TVT NVMS 1000 - Directory Traversal
  92. [webapps] Huawei HG630 2 Router - Authentication Bypass
  93. [webapps] Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
  94. [local] Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
  95. [dos] AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
  96. [webapps] Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
  97. [webapps] Django 3.0 - Cross-Site Request Forgery Token Bypass
  98. [dos] dnsmasq-utils 2.79-1 - 'dhcp_release' Denial of Service (PoC)
  99. [dos] ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
  100. [webapps] pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
  101. [local] Microsoft NET USE win10 - Insufficient Authentication Logic
  102. [webapps] LimeSurvey 4.1.11 - 'File Manager' Path Traversal
  103. [webapps] Bolt CMS 3.7.0 - Authenticated Remote Code Execution
  104. [webapps] WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
  105. [webapps] Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metaspl
  106. [local] Triologic Media Player 8 - '.m3l' Buffer Overflow (Unicode) (SEH)
  107. [dos] ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)
  108. [dos] UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)
  109. [dos] UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)
  110. [webapps] LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
  111. [dos] UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)
  112. [dos] Frigate 3.36 - Denial of Service (PoC)
  113. [dos] Nsauditor 3.2.0.0 - 'Name' Denial of Service (PoC)
  114. [dos] SpotAuditor 5.3.4 - 'Name' Denial of Service (PoC)
  115. [dos] Product Key Explorer 4.2.2.0 - 'Key' Denial of Service (PoC)
  116. [local] Memu Play 7.1.3 - Insecure Folder Permissions
  117. [local] AIDA64 Engineer 6.20.5300 - 'Report File' filename Buffer Overflow (SEH)
  118. [webapps] Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
  119. [local] DiskBoss 7.7.14 - 'Input Directory' Local Buffer Overflow (PoC)
  120. [local] 10Strike LANState 9.32 - 'Force Check' Buffer Overflow (SEH)
  121. [dos] DiskBoss 7.7.14 - Denial of Service (PoC)
  122. [remote] SharePoint Workflows - XOML Injection (Metasploit)
  123. [remote] DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
  124. [remote] IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasp
  125. [remote] Redis - Replication Code Execution (Metasploit)
  126. [webapps] Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Inject
  127. [webapps] Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
  128. [dos] FlashFXP 4.2.0 Build 1730 - Denial of Service (PoC)
  129. [remote] Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
  130. [local] Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPA
  131. [webapps] Zen Load Balancer 3.10.1 - Remote Code Execution
  132. [local] 10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow
  133. [webapps] Joomla! com_fabrik 3.9.11 - Directory Traversal
  134. [dos] Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service (PoC)
  135. [webapps] rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
  136. [webapps] Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
  137. [dos] Everest 5.50.2100 - 'Open File' Denial of Service (PoC)
  138. [webapps] ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
  139. [local] Easy RM to MP3 Converter 2.7.3.700 - 'Input' Local Buffer Overflow (SEH)
  140. [webapps] Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
  141. [webapps] TP-Link Archer C50 3 - Denial of Service (PoC)
  142. [local] 10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)
  143. [local] 10-Strike Network Inventory Explorer - 'srvInventoryWebServer' Unquoted Servi
  144. [webapps] LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
  145. [local] AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
  146. [webapps] Joomla! Component GMapFP 3.30 - Arbitrary File Upload
  147. [webapps] UCM6202 1.0.18.13 - Remote Command Injection
  148. [local] Veyon 4.3.4 - 'VeyonService' Unquoted Service Path
  149. [webapps] Wordpress Plugin WPForms 1.5.9 - Persistent Cross-Site Scripting
  150. [webapps] UliCMS 2020.1 - Persistent Cross-Site Scripting
  151. [webapps] Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
  152. [webapps] rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
  153. [webapps] FIBARO System Home Center 5.021 - Remote File Include
  154. [remote] CyberArk PSMP 10.9.1 - Policy Restriction Bypass
  155. [dos] Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
  156. [dos] ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
  157. [local] VMware Fusion 11.5.2 - Privilege Escalation
  158. [webapps] Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
  159. [remote] Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
  160. [local] VMWare Fusion - Local Privilege Escalation
  161. [local] Microsoft VSCode Python Extension - Code Execution
  162. [remote] Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
  163. [local] NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
  164. [webapps] Netlink GPON Router 1.0.11 - Remote Code Execution
  165. [remote] Rconfig 3.x - Chained Remote Code Execution (Metasploit)
  166. [remote] ManageEngine Desktop Central - Java Deserialization (Metasploit)
  167. [webapps] PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execu
  168. [webapps] PHPKB Multi-Language 9 - Authenticated Directory Traversal
  169. [webapps] PHPKB Multi-Language 9 - Authenticated Remote Code Execution
  170. [webapps] MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
  171. [webapps] Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin
  172. [dos] Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABI
  173. [webapps] Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
  174. [remote] Drobo 5N2 4.1.1 - Remote Command Injection
  175. [webapps] Centos WebPanel 7 - 'term' SQL Injection
  176. [local] AnyBurn 4.8 - Buffer Overflow (SEH)
  177. [webapps] Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
  178. [webapps] Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
  179. [webapps] rConfig 3.9 - 'searchColumn' SQL Injection
  180. [webapps] rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
  181. [local] ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
  182. [webapps] HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
  183. [webapps] Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
  184. [webapps] WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
  185. [webapps] Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
  186. [webapps] Wordpress Plugin Search Meter 2.13.2 - CSV injection
  187. [local] ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
  188. [remote] PHPStudy - Backdoor Remote Code execution (Metasploit)
  189. [remote] Nagios XI - Authenticated Remote Command Execution (Metasploit)
  190. [webapps] Persian VIP Download Script 1.0 - 'active' SQL Injection
  191. [webapps] YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
  192. [webapps] Sysaid 20.1.11 b26 - Remote Command Execution
  193. [local] Counter Strike: GO - '.bsp' Memory Control (PoC)
  194. [remote] Google Chrome 67, 68 and 69 - Object.create Type Confusion (Metasploit)
  195. [remote] Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
  196. [local] OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
  197. [remote] Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
  198. [remote] PHP-FPM - Underflow Remote Code Execution (Metasploit)
  199. [remote] Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
  200. [local] Microsoft Windows - 'WizardOpium' Local Privilege Escalation
  201. [webapps] Sentrifugo HRMS 3.2 - 'id' SQL Injection
  202. [webapps] 60CycleCMS - 'news.php' SQL Injection
  203. [webapps] ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization
  204. [local] Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Pat
  205. [local] ASUS GiftBox Desktop 1.1.1.127 - 'ASUSGiftBoxDesktop' Unquoted Service Path
  206. [local] SpyHunter 4 - 'SpyHunter 4 Service' Unquoted Service Path
  207. [local] Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Se
  208. [remote] netkit-telnet-0.17 telnetd (Fedora 31) - 'BraveStarr' Remote Code Execution
  209. [remote] EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
  210. [remote] Exchange Control Panel - Viewstate Deserialization (Metasploit)
  211. [webapps] UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
  212. [webapps] RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
  213. [webapps] GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
  214. [webapps] Alfresco 5.2.4 - Persistent Cross-Site Scripting
  215. [webapps] RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
  216. [local] Wing FTP Server 6.2.3 - Privilege Escalation
  217. [webapps] Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
  218. [webapps] Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
  219. [remote] CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
  220. [webapps] TP LINK TL-WR849N - Remote Code Execution
  221. [webapps] Wing FTP Server 6.2.5 - Privilege Escalation
  222. [remote] Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
  223. [webapps] TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
  224. [webapps] Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
  225. [webapps] Netis WF2419 2.2.36123 - Remote Code Execution
  226. [local] Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
  227. [webapps] Joplin Desktop 1.0.184 - Cross-Site Scripting
  228. [webapps] qdPM < 9.1 - Remote Code Execution
  229. [webapps] Cacti 1.2.8 - Unauthenticated Remote Code Execution
  230. [webapps] Cacti 1.2.8 - Authenticated Remote Code Execution
  231. [webapps] Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
  232. [webapps] Comtrend VR-3033 - Command Injection
  233. [webapps] Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
  234. [remote] OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
  235. [remote] OpenSMTPD 6.6.3 - Arbitrary File Read
  236. [webapps] GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
  237. [webapps] PhpIX 2012 Professional - 'id' SQL Injection
  238. [dos] Core FTP LE 2.2 - Denial of Service (PoC)
  239. [dos] Odin Secure FTP Expert 7.6.3 - Denial of Service (PoC)
  240. [webapps] Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypas
  241. [webapps] WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Proc
  242. [dos] aSc TimeTables 2020.11.4 - Denial of Service (PoC)
  243. [dos] SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
  244. [local] Diamorphine Rootkit - Signal Privilege Escalation (Metasploit)
  245. [remote] Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Met
  246. [local] Android Binder - Use-After-Free (Metasploit)
  247. [webapps] Cacti 1.2.8 - Remote Code Execution
  248. [webapps] Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
  249. [webapps] DotNetNuke 9.5 - File Upload Restrictions Bypass
  250. [webapps] DotNetNuke 9.5 - Persistent Cross-Site Scripting