المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : exploit database


الصفحات : 1 2 3 4 5 6 7 [8] 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68

  1. [webapps] School ERP Pro 1.0 - Arbitrary File Read
  2. [webapps] Open-AudIT Professional 3.3.1 - Remote Code Execution
  3. [webapps] School ERP Pro 1.0 - Remote Code Execution
  4. [local] NVIDIA Update Service Daemon 1.0.21 - 'nvUpdatusService' Unquoted Service Pa
  5. [webapps] School ERP Pro 1.0 - 'es_messagesid' SQL Injection
  6. [remote] CloudMe 1.11.2 - Buffer Overflow (PoC)
  7. [local] Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
  8. [local] Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
  9. [webapps] Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
  10. [webapps] Online Course Registration 2.0 - Authentication Bypass
  11. [webapps] Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
  12. [webapps] Online shopping system advanced 1.0 - 'p' SQL Injection
  13. [webapps] Netis E1+ 1.2.32533 - Backdoor Account (root)
  14. [webapps] PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
  15. [webapps] Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
  16. [local] Popcorn Time 6.2 - 'Update service' Unquoted Service Path
  17. [webapps] Edimax EW-7438RPn 1.13 - Remote Code Execution
  18. [webapps] EspoCRM 5.8.5 - Privilege Escalation
  19. [webapps] Sky File 2.1.0 iOS - Directory Traversal
  20. [webapps] Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
  21. [webapps] Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
  22. [webapps] Complaint Management System 4.2 - Authentication Bypass
  23. [webapps] Complaint Management System 4.2 - Persistent Cross-Site Scripting
  24. [webapps] User Management System 2.0 - Authentication Bypass
  25. [webapps] User Management System 2.0 - Persistent Cross-Site Scripting
  26. [webapps] Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
  27. [webapps] Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
  28. [webapps] Edimax EW-7438RPn - Information Disclosure (WiFi Password)
  29. [local] RM Downloader 3.1.3.2.2010.06.13 - 'Load' Buffer Overflow (SEH)
  30. [remote] Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
  31. [webapps] P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
  32. [webapps] jizhi CMS 1.6.7 - Arbitrary File Download
  33. [webapps] NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
  34. [local] Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
  35. [webapps] IQrouter 3.3.1 Firmware - Remote Code Execution
  36. [webapps] CSZ CMS 1.2.7 - 'title' HTML Injection
  37. [webapps] PMB 5.6 - 'logid' SQL Injection
  38. [webapps] CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
  39. [remote] Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
  40. [local] Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path
  41. [local] Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH)
  42. [local] Nsauditor 3.2.1.0 - Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))
  43. [webapps] Fork CMS 5.8.0 - Persistent Cross-Site Scripting
  44. [local] Atomic Alarm Clock 6.3 - Stack Overflow (Unicode+SEH)
  45. [webapps] Centreon 19.10.5 - 'id' SQL Injection
  46. [local] Code Blocks 16.01 - Buffer Overflow (SEH) UNICODE
  47. [remote] Nexus Repository Manager - Java EL Injection RCE (Metasploit)
  48. [remote] Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
  49. [local] VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
  50. [remote] DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
  51. [remote] PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metas
  52. [remote] Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
  53. [remote] ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
  54. [remote] Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
  55. [remote] TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit
  56. [local] BlazeDVD 7.0.2 - Buffer Overflow (SEH)
  57. [webapps] Xeroneit Library Management System 3.0 - 'category' SQL Injection
  58. [webapps] File Transfer iFamily 2.1 - Directory Traversal
  59. [webapps] DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
  60. [webapps] Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
  61. [webapps] SeedDMS 5.1.18 - Persistent Cross-Site Scripting
  62. [webapps] Pinger 1.0 - Remote Code Execution
  63. [webapps] SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
  64. [webapps] AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
  65. [webapps] Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
  66. [webapps] WSO2 3.1.0 - Persistent Cross-Site Scripting
  67. [webapps] Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
  68. [local] B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)
  69. [webapps] MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
  70. [webapps] Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
  71. [local] Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (S
  72. [webapps] WSO2 3.1.0 - Arbitrary File Delete
  73. [webapps] Webtateas 2.0 - Arbitrary File Read
  74. [webapps] TVT NVMS 1000 - Directory Traversal
  75. [webapps] Huawei HG630 2 Router - Authentication Bypass
  76. [webapps] Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
  77. [local] Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
  78. [dos] AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
  79. [webapps] Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
  80. [webapps] Django 3.0 - Cross-Site Request Forgery Token Bypass
  81. [dos] dnsmasq-utils 2.79-1 - 'dhcp_release' Denial of Service (PoC)
  82. [dos] ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
  83. [webapps] pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
  84. [local] Microsoft NET USE win10 - Insufficient Authentication Logic
  85. [webapps] LimeSurvey 4.1.11 - 'File Manager' Path Traversal
  86. [webapps] Bolt CMS 3.7.0 - Authenticated Remote Code Execution
  87. [webapps] WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
  88. [webapps] Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metaspl
  89. [local] Triologic Media Player 8 - '.m3l' Buffer Overflow (Unicode) (SEH)
  90. [dos] ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)
  91. [dos] UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)
  92. [dos] UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)
  93. [webapps] LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
  94. [dos] UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)
  95. [dos] Frigate 3.36 - Denial of Service (PoC)
  96. [dos] Nsauditor 3.2.0.0 - 'Name' Denial of Service (PoC)
  97. [dos] SpotAuditor 5.3.4 - 'Name' Denial of Service (PoC)
  98. [dos] Product Key Explorer 4.2.2.0 - 'Key' Denial of Service (PoC)
  99. [local] Memu Play 7.1.3 - Insecure Folder Permissions
  100. [local] AIDA64 Engineer 6.20.5300 - 'Report File' filename Buffer Overflow (SEH)
  101. [webapps] Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
  102. [local] DiskBoss 7.7.14 - 'Input Directory' Local Buffer Overflow (PoC)
  103. [local] 10Strike LANState 9.32 - 'Force Check' Buffer Overflow (SEH)
  104. [dos] DiskBoss 7.7.14 - Denial of Service (PoC)
  105. [remote] SharePoint Workflows - XOML Injection (Metasploit)
  106. [remote] DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
  107. [remote] IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasp
  108. [remote] Redis - Replication Code Execution (Metasploit)
  109. [webapps] Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Inject
  110. [webapps] Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
  111. [dos] FlashFXP 4.2.0 Build 1730 - Denial of Service (PoC)
  112. [remote] Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
  113. [local] Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPA
  114. [webapps] Zen Load Balancer 3.10.1 - Remote Code Execution
  115. [local] 10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow
  116. [webapps] Joomla! com_fabrik 3.9.11 - Directory Traversal
  117. [dos] Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service (PoC)
  118. [webapps] rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
  119. [webapps] Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
  120. [dos] Everest 5.50.2100 - 'Open File' Denial of Service (PoC)
  121. [webapps] ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
  122. [local] Easy RM to MP3 Converter 2.7.3.700 - 'Input' Local Buffer Overflow (SEH)
  123. [webapps] Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
  124. [webapps] TP-Link Archer C50 3 - Denial of Service (PoC)
  125. [local] 10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)
  126. [local] 10-Strike Network Inventory Explorer - 'srvInventoryWebServer' Unquoted Servi
  127. [webapps] LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
  128. [local] AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
  129. [webapps] Joomla! Component GMapFP 3.30 - Arbitrary File Upload
  130. [webapps] UCM6202 1.0.18.13 - Remote Command Injection
  131. [local] Veyon 4.3.4 - 'VeyonService' Unquoted Service Path
  132. [webapps] Wordpress Plugin WPForms 1.5.9 - Persistent Cross-Site Scripting
  133. [webapps] UliCMS 2020.1 - Persistent Cross-Site Scripting
  134. [webapps] Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
  135. [webapps] rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
  136. [webapps] FIBARO System Home Center 5.021 - Remote File Include
  137. [remote] CyberArk PSMP 10.9.1 - Policy Restriction Bypass
  138. [dos] Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
  139. [dos] ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
  140. [local] VMware Fusion 11.5.2 - Privilege Escalation
  141. [webapps] Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
  142. [remote] Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
  143. [local] VMWare Fusion - Local Privilege Escalation
  144. [local] Microsoft VSCode Python Extension - Code Execution
  145. [remote] Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
  146. [local] NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
  147. [webapps] Netlink GPON Router 1.0.11 - Remote Code Execution
  148. [remote] ManageEngine Desktop Central - Java Deserialization (Metasploit)
  149. [remote] Rconfig 3.x - Chained Remote Code Execution (Metasploit)
  150. [webapps] PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execu
  151. [webapps] PHPKB Multi-Language 9 - Authenticated Directory Traversal
  152. [webapps] PHPKB Multi-Language 9 - Authenticated Remote Code Execution
  153. [webapps] MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
  154. [webapps] Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin
  155. [dos] Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABI
  156. [webapps] Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
  157. [remote] Drobo 5N2 4.1.1 - Remote Command Injection
  158. [webapps] Centos WebPanel 7 - 'term' SQL Injection
  159. [local] AnyBurn 4.8 - Buffer Overflow (SEH)
  160. [webapps] Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
  161. [webapps] Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
  162. [webapps] rConfig 3.9 - 'searchColumn' SQL Injection
  163. [webapps] rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
  164. [local] ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
  165. [webapps] HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
  166. [webapps] Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
  167. [webapps] WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
  168. [webapps] Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
  169. [webapps] Wordpress Plugin Search Meter 2.13.2 - CSV injection
  170. [local] ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
  171. [remote] PHPStudy - Backdoor Remote Code execution (Metasploit)
  172. [remote] Nagios XI - Authenticated Remote Command Execution (Metasploit)
  173. [webapps] Persian VIP Download Script 1.0 - 'active' SQL Injection
  174. [webapps] YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
  175. [webapps] Sysaid 20.1.11 b26 - Remote Command Execution
  176. [local] Counter Strike: GO - '.bsp' Memory Control (PoC)
  177. [remote] Google Chrome 67, 68 and 69 - Object.create Type Confusion (Metasploit)
  178. [remote] Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
  179. [local] OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
  180. [remote] Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
  181. [remote] PHP-FPM - Underflow Remote Code Execution (Metasploit)
  182. [remote] Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
  183. [local] Microsoft Windows - 'WizardOpium' Local Privilege Escalation
  184. [webapps] Sentrifugo HRMS 3.2 - 'id' SQL Injection
  185. [webapps] 60CycleCMS - 'news.php' SQL Injection
  186. [webapps] ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization
  187. [local] Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Pat
  188. [local] ASUS GiftBox Desktop 1.1.1.127 - 'ASUSGiftBoxDesktop' Unquoted Service Path
  189. [local] SpyHunter 4 - 'SpyHunter 4 Service' Unquoted Service Path
  190. [local] Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Se
  191. [remote] netkit-telnet-0.17 telnetd (Fedora 31) - 'BraveStarr' Remote Code Execution
  192. [remote] EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
  193. [remote] Exchange Control Panel - Viewstate Deserialization (Metasploit)
  194. [webapps] UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
  195. [webapps] RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
  196. [webapps] GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
  197. [webapps] Alfresco 5.2.4 - Persistent Cross-Site Scripting
  198. [webapps] RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
  199. [local] Wing FTP Server 6.2.3 - Privilege Escalation
  200. [webapps] Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
  201. [webapps] Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
  202. [remote] CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
  203. [webapps] TP LINK TL-WR849N - Remote Code Execution
  204. [webapps] Wing FTP Server 6.2.5 - Privilege Escalation
  205. [remote] Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
  206. [webapps] TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
  207. [webapps] Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
  208. [webapps] Netis WF2419 2.2.36123 - Remote Code Execution
  209. [local] Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
  210. [webapps] Joplin Desktop 1.0.184 - Cross-Site Scripting
  211. [webapps] qdPM < 9.1 - Remote Code Execution
  212. [webapps] Cacti 1.2.8 - Unauthenticated Remote Code Execution
  213. [webapps] Cacti 1.2.8 - Authenticated Remote Code Execution
  214. [webapps] Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
  215. [webapps] Comtrend VR-3033 - Command Injection
  216. [webapps] Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
  217. [remote] OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
  218. [remote] OpenSMTPD 6.6.3 - Arbitrary File Read
  219. [webapps] GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
  220. [webapps] PhpIX 2012 Professional - 'id' SQL Injection
  221. [dos] Core FTP LE 2.2 - Denial of Service (PoC)
  222. [dos] Odin Secure FTP Expert 7.6.3 - Denial of Service (PoC)
  223. [webapps] Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypas
  224. [webapps] WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Proc
  225. [dos] aSc TimeTables 2020.11.4 - Denial of Service (PoC)
  226. [dos] SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
  227. [local] Diamorphine Rootkit - Signal Privilege Escalation (Metasploit)
  228. [remote] Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Met
  229. [local] Android Binder - Use-After-Free (Metasploit)
  230. [webapps] Cacti 1.2.8 - Remote Code Execution
  231. [webapps] Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
  232. [webapps] DotNetNuke 9.5 - File Upload Restrictions Bypass
  233. [webapps] DotNetNuke 9.5 - Persistent Cross-Site Scripting
  234. [webapps] eLection 2.0 - 'id' SQL Injection
  235. [dos] Go SSH servers 0.0.2 - Denial of Service (PoC)
  236. [webapps] ManageEngine EventLog Analyzer 10.0 - Information Disclosure
  237. [webapps] I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure
  238. [webapps] ATutor 2.2.4 - 'id' SQL Injection
  239. [webapps] SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure
  240. [webapps] AMSS++ 4.7 - Backdoor Admin Account
  241. [webapps] CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
  242. [dos] Quick N Easy Web Server 3.3.8 - Denial of Service (PoC)
  243. [webapps] SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure
  244. [webapps] AMSS++ v 4.31 - 'id' SQL Injection
  245. [webapps] Real Web Pentesting Tutorial Step by Step - [Persian]
  246. [webapps] ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure
  247. [webapps] Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripti
  248. [dos] Core FTP Lite 1.3 - Denial of Service (PoC)
  249. [webapps] Easy2Pilot 7 - Cross-Site Request Forgery (Add User)
  250. [webapps] Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak