Exploits (Total: 98348)

    
    
    
Purchase Order Management System 1.0 - Remote File Upload
2021-09-14
Windows/x64 - Reverse TCP (192.168.201.11:4444) Shellcode (330 Bytes)
2021-09-13
Facebook ParlAI 1.0.0 - Deserialization of Untrusted Data in parlai
2021-09-13
Apartment Visitor Management System (AVMS) 1.0 - SQLi to RCE
2021-09-13
Wordpress Plugin Download From Files 1.48 - Arbitrary File Upload
2021-09-13
ECOA Building Automation System - Arbitrary File Deletion
2021-09-13
ECOA Building Automation System - Local File Disclosure
2021-09-13
ECOA Building Automation System - Remote Privilege Escalation
2021-09-13
ECOA Building Automation System - Missing Encryption Of Sensitive Information
2021-09-13
ECOA Building Automation System - Hard-coded Credentials SSH Access
2021-09-13
ECOA Building Automation System - Hidden Backdoor Accounts and backdoor() Function
2021-09-13
ECOA Building Automation System - Configuration Download Information Disclosure
2021-09-13
ECOA Building Automation System - Cookie Poisoning Authentication Bypass
2021-09-13
ECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF)
2021-09-13
ECOA Building Automation System - Directory Traversal Content Disclosure
2021-09-13
ECOA Building Automation System - Path Traversal Arbitrary File Upload
2021-09-13
ECOA Building Automation System - Weak Default Credentials
2021-09-13
Men Salon Management System 1.0 - Multiple Vulnerabilities
2021-09-13
Active WebCam 11.5 - Unquoted Service Path
2021-09-13
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
2021-09-09
Backdooring Wordpress to get text-clear passwords - Paper (Brazilian-Portuguese)
2021-09-08
WordPress Plugin TablePress 1.14 - CSV Injection
2021-09-08
WordPress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection (2)
2021-09-07
WordPress Plugin WP Sitemap Page 1.6.4 - Stored Cross-Site Scripting (XSS)
2021-09-07
Antminer Monitor 0.5.0 - Authentication Bypass
2021-09-06
SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Service
2021-09-06
Patient Appointment Scheduler System 1.0 - Persistent/Stored XSS
2021-09-06
Patient Appointment Scheduler System 1.0 - Unauthenticated File Upload & Remote Code Execution (RCE)
2021-09-06
Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
2021-09-06
FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated)
2021-09-06
Argus Surveillance DVR 4.0 - Unquoted Service Path
2021-09-06
OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)
2021-09-06
OpenSIS 8.0 'modname' - Directory/Path Traversal
2021-09-03
Remote Mouse 4.002 - Unquoted Service Path
2021-09-03
CRACKING WiFi WPA2 HANDSHAKE - Paper (Turkish)
2021-09-02
WordPress Plugin Duplicate Page 4.4.1 - Stored Cross-Site Scripting (XSS)
2021-09-02
WPanel 4.3.1 - Remote Code Execution (RCE) (Authenticated)
2021-09-02
Compro Technology IP Camera - ' mjpegStreamer.cgi' Screenshot Disclosure
2021-09-02
Compro Technology IP Camera - ' index_MJpeg.cgi' Stream Disclosure
2021-09-02
Compro Technology IP Camera - 'Multiple' Credential Disclosure
2021-09-02
Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated)
2021-09-02
Compro Technology IP Camera - 'killps.cgi' Denial-of-Service (DoS)
2021-09-02
OpenSIS Community 8.0 - 'cp_id_miss_attn' SQL Injection
2021-09-02
Dolibarr ERP/CRM 14.0.1 - Privilege Escalation
2021-09-02
Telegram Desktop 2.9.2 - Denial of Service (PoC)
2021-09-01
WordPress Plugin Payments Plugin | GetPaid 2.4.6 - HTML Injection
2021-09-01
Traffic Offense Management System 1.0 - SQLi to Remote Code Execution (RCE) (Unauthenticated)
2021-09-01
Confluence Server 7.12.4 - 'OGNL injection' Remote Code Execution (RCE) (Unauthenticated)
2021-09-01
WordPress Plugin ProfilePress 3.1.3 - Privilege Escalation (Unauthenticated)
2021-08-31
Umbraco CMS 8.9.1 - Path traversal and Arbitrary File Write (Authenticated)
2021-08-31
Projectsend r1295 - 'name' Stored XSS
2021-08-30
Strapi CMS 3.0.0-beta.17.4 - Remote Code Execution (RCE) (Unauthenticated)
2021-08-30
Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated)
2021-08-30
Strapi 3.0.0-beta - Set Password (Unauthenticated)
2021-08-30
MySQL User-Defined (Linux) x32 / x86_64 - 'sys_exec' Local Privilege Escalation (2)
2021-08-30
Bus Pass Management System 1.0 - 'viewid' SQL Injection
2021-08-30
Usermin 1.820 - Remote Code Execution (RCE) (Authenticated)
2021-08-30
ZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated)
2021-08-30
COMMAX UMS Client ActiveX Control 1.7.0.2 - 'CNC_Ctrl.dll' Heap Buffer Overflow
2021-08-27
COMMAX WebViewer ActiveX Control 2.1.4.5 - 'Commax_WebViewer.ocx' Buffer Overflow
2021-08-27
CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated)
2021-08-27
ProcessMaker 3.5.4 - Local File inclusion
2021-08-26
Online Leave Management System 1.0 - Arbitrary File Upload to Shell (Unauthenticated)
2021-08-25
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
2021-08-25
WordPress Plugin Mail Masta 1.0 - Local File Inclusion (2)
2021-08-25
Local administrator is not just with Razer.. it is possible for ALL - Paper
2021-08-25
RaspAP 2.6.6 - Remote Code Execution (RCE) (Authenticated)
2021-08-23
Simple Phone book/directory 1.0 - 'Username' SQL Injection (Unauthenticated)
2021-08-23
JavaScript Static Analysis - Paper (Arabic)
2021-08-23
Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
2021-08-23
Laundry Booking Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
2021-08-20
Laundry Booking Management System 1.0 - 'Multiple' SQL Injection
2021-08-20
Online Traffic Offense Management System 1.0 - 'id' SQL Injection (Authenticated)
2021-08-20
Charity Management System CMS 1.0 - Multiple Vulnerabilities
2021-08-19
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
2021-08-18
COVID19 Testing Management System 1.0 - 'Multiple' SQL Injections
2021-08-18
Simple Image Gallery 1.0 - Remote Code Execution (RCE) (Unauthenticated)
2021-08-18
Crime records Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
2021-08-18
SonicWall NetExtender 10.2.0.300 - Unquoted Service Path
2021-08-17
GeoVision Geowebserver 5.3.3 - LFI / XSS / HHI / RCE
2021-08-17
COMMAX CVD-Axx DVR 5.1.4 - Weak Default Credentials Stream Disclosure
2021-08-17
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - Config Write / DoS (Unauthenticated)
2021-08-17
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - RTSP Credentials Disclosure
2021-08-17
COMMAX Smart Home IoT Control System CDP-1020n - SQL Injection Authentication Bypass
2021-08-17
COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass
2021-08-17
Simple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File Upload
2021-08-17
Simple Water Refilling Station Management System 1.0 - Authentication Bypass
2021-08-17
NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS)
2021-08-17
CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS)
2021-08-17
RATES SYSTEM 1.0 - Authentication Bypass
2021-08-17
Simple Image Gallery System 1.0 - 'id' SQL Injection
2021-08-17
Care2x Open Source Hospital Information Management 2.7 Alpha - 'Multiple' Stored XSS
2021-08-17
Police Crime Record Management System 1.0 - 'casedetails' SQL Injection
2021-08-17
Police Crime Record Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
2021-08-17
easy-mock 1.6.0 - Remote Code Execution (RCE) (Authenticated)
2021-08-17
4images 1.8 - 'limitnumber' SQL Injection (Authenticated)
2021-08-17
RATES SYSTEM 1.0 - 'Multiple' SQL Injections
2021-08-17
Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)
2021-08-17
COVID19 Testing Management System 1.0 - 'searchdata' SQL Injection
2021-08-17
Simple Library Management System 1.0 - 'rollno' SQL Injection
2021-08-10
Exploits/page:


Page:
1-4-2 (www02)