Exploits (Total: 98608)

    
    
    
Advanced Comment System 1.0 - Remote Command Execution (RCE)
2021-12-01
MilleGPG5 5.7.2 Luglio 2021 - Local Privilege Escalation
2021-12-01
Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
2021-12-01
Laundry Booking Management System 1.0 - Remote Code Execution (RCE)
2021-11-30
opencart 3.0.3.8 - Sessjion Injection
2021-11-29
orangescrum 1.8.0 - 'Multiple' Cross-Site Scripting (XSS) (Authenticated)
2021-11-29
orangescrum 1.8.0 - 'Multiple' SQL Injection (Authenticated)
2021-11-29
Apache HTTP Server 2.4.50 Path Traversal and Code Execution - Paper
2021-11-29
orangescrum 1.8.0 - Privilege escalation (Authenticated)
2021-11-29
Polkit Authentication bypass Local Privesc - Paper
2021-11-29
Bagisto 1.3.3 - Client-Side Template Injection
2021-11-26
CMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated)
2021-11-24
Remote code execution in WhatsApp - Paper (Spanish)
2021-11-24
HTTPDebuggerPro 9.11 - Unquoted Service Path
2021-11-24
FLEX 1085 Web 1.6.0 - HTML Injection
2021-11-23
Bus Pass Management System 1.0 - 'Search' SQL injection
2021-11-23
Webrun 3.6.0.42 - 'P_0' SQL Injection
2021-11-23
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
2021-11-23
Wordpress Plugin WP Guppy 1.1 - WP-JSON API Sensitive Information Disclosure
2021-11-23
GNU gdbserver 9.2 - Remote Command Execution (RCE)
2021-11-23
Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection
2021-11-22
Print Nightmare - Paper
2021-11-22
Modbus Slave 7.3.1 - Buffer Overflow (DoS)
2021-11-22
Pinkie 2.15 - TFTP Remote Buffer Overflow (PoC)
2021-11-22
Wordpress Plugin Smart Product Review 1.0.4 - Arbitrary File Upload
2021-11-17
GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
2021-11-17
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
2021-11-17
Quick.CMS 6.7 - Cross Site Request Forgery (CSRF) to Cross Site Scripting (XSS) (Authenticated)
2021-11-17
Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
2021-11-17
Pass-the-Hash attack on named pipes against ESET Server Security - Paper (Spanish)
2021-11-16
CMDBuild 3.3.2 - 'Multiple' Cross Site Scripting (XSS)
2021-11-16
Online Learning System 2.0 - Remote Code Execution (RCE)
2021-11-16
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
2021-11-15
WordPress Plugin Contact Form to Email 1.3.24 - Stored Cross Site Scripting (XSS) (Authenticated)
2021-11-15
Fuel CMS 1.4.13 - 'col' Blind SQL Injection (Authenticated)
2021-11-15
Simple Subscription Website 1.0 - SQLi Authentication Bypass
2021-11-15
KONGA 0.14.9 - Privilege Escalation
2021-11-15
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
2021-11-15
Mumara Classic 2.93 - 'license' SQL Injection (Unauthenticated)
2021-11-12
Windows MultiPoint Server 2011 SP1 - RpcEptMapper and Dnschade Local Privilege Escalation
2021-11-12
Xlight FTP 3.9.3.1 - Buffer Overflow (PoC)
2021-11-12
WordPress Plugin AccessPress Social Icons 1.8.2 - 'icon title' Stored Cross-Site Scripting (XSS)
2021-11-12
WordPress Plugin WP Symposium Pro 2021.10 - 'wps_admin_forum_add_name' Stored Cross-Site Scripting (XSS)
2021-11-12
FormaLMS 2.4.4 - Authentication Bypass
2021-11-11
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
2021-11-11
AbsoluteTelnet 11.24 - 'Phone' Denial of Service (PoC)
2021-11-11
AbsoluteTelnet 11.24 - 'Username' Denial of Service (PoC)
2021-11-11
YeaLink SIP-TXXXP 53.84.0.15 - 'cmd' Command Injection (Authenticated)
2021-11-11
Employee and Visitor Gate Pass Logging System 1.0 - 'name' Stored Cross-Site Scripting (XSS)
2021-11-10
Employee Daily Task Management System 1.0 - 'Name' Stored Cross-Site Scripting (XSS)
2021-11-10
Exploits/page:


Page:
1-4-2 (www02)