Exploits (Total: 97559)

    
    
    
Windows/x86 - Stager Generic MSHTA Shellcode (143 bytes)
2021-01-22
Atlassian Confluence Widget Connector Macro - SSTI
2021-01-22
ERPNext 12.14.0 - SQL Injection (Authenticated)
2021-01-22
CASAP Automated Enrollment System 1.0 - Authentication Bypass
2021-01-22
Library System 1.0 - Authentication Bypass Via SQL Injection
2021-01-22
Oracle WebLogic Server 14.1.1.0 - RCE (Authenticated)
2021-01-22
Selea Targa IP OCR-ANPR Camera - 'addr' Remote Code Execution (Unauthenticated)
2021-01-22
Selea Targa IP OCR-ANPR Camera - RTP/RTSP/M-JPEG Stream Disclosure (Unauthenticated)
2021-01-22
Selea Targa IP OCR-ANPR Camera - CSRF Add Admin
2021-01-22
Selea Targa IP OCR-ANPR Camera - Multiple SSRF (Unauthenticated)
2021-01-22
Selea Targa IP OCR-ANPR Camera - Directory Traversal File Disclosure (Unauthenticated)
2021-01-22
Selea Targa IP OCR-ANPR Camera - Developer Backdoor Config Overwrite
2021-01-22
Selea Targa IP OCR-ANPR Camera - 'files_list' Remote Stored XSS
2021-01-22
Selea CarPlateServer (CPS) 4.0.1.6 - Local Privilege Escalation
2021-01-22
Selea CarPlateServer (CPS) 4.0.1.6 - Remote Program Execution
2021-01-22
Anchor CMS 0.12.7 - CSRF (Delete user)
2021-01-21
Wordpress Plugin Simple Job Board 2.9.3 - Authenticated File Read (Metasploit)
2021-01-21
Nagios XI 5.7.5 - Multiple Persistent Cross-Site Scripting
2021-01-21
Apartment Visitors Management System 1.0 - 'email' SQL Injection
2021-01-21
Online Documents Sharing Platform 1.0 - 'user' SQL Injection
2021-01-21
Linux/x86 - Socat Bind Shellcode (113 bytes)
2021-01-20
Voting System 1.0 - File Upload RCE (Authenticated Remote Code Execution)
2021-01-20
Oracle Business Intelligence Enterprise Edition 11.1.1.7.140715 - Stored XSS
2021-01-20
ChurchRota 2.6.4 - RCE (Authenticated)
2021-01-20
Linux/x64 - Reverse (127.1.1.1:4444) Shell (/bin/sh) Shellcode (123 Bytes)
2021-01-19
osTicket 1.14.2 - SSRF
2021-01-19
Life Insurance Management System 1.0 - File Upload RCE (Authenticated)
2021-01-18
Life Insurance Management System 1.0 - 'client_id' SQL Injection
2021-01-18
Inteno IOPSYS 3.16.4 - root filesystem access via sambashare (Authenticated)
2021-01-18
Xwiki CMS 12.10.2 - Cross Site Scripting (XSS)
2021-01-18
Cisco UCS Manager 2.2(1d) - Remote Command Execution
2021-01-18
Netsia SEBA+ 0.16.1 - Authentication Bypass and Add Root User (Metasploit)
2021-01-15
E-Learning System 1.0 - Authentication Bypass & RCE POC
2021-01-15
Alumni Management System 1.0 - "Last Name field in Registration page" Stored XSS
2021-01-15
EyesOfNetwork 5.3 - File Upload Remote Code Execution
2021-01-15
Online Hotel Reservation System 1.0 - 'person' time-based SQL Injection
2021-01-15
Online Hotel Reservation System 1.0 - Cross-site request forgery (CSRF)
2021-01-15
Online Hotel Reservation System 1.0 - 'id' Time-based SQL Injection
2021-01-15
Online Hotel Reservation System 1.0 - 'description' Stored Cross-site Scripting
2021-01-15
WordPress Plugin Easy Contact Form 1.1.7 - 'Name' Stored Cross-Site Scripting (XSS)
2021-01-15
PHP-Fusion CMS 9.03.90 - Cross-Site Request Forgery (Delete admin shoutbox message)
2021-01-15
Cisco RV110W 1.2.1.7 - 'vpn_account' Denial of Service (PoC)
2021-01-14
Laravel 8.4.2 debug mode - Remote code execution
2021-01-14
Online Shopping Cart System 1.0 - 'id' SQL Injection
2021-01-14
Nagios XI 5.7.X - Remote Code Exection RCE (Authenticated)
2021-01-14
Online Movie Streaming 1.0 - Admin Authentication Bypass
2021-01-14
Online Hotel Reservation System 1.0 - Admin Authentication Bypass
2021-01-13
Erlang Cookie - Remote Code Execution
2021-01-13
Practical Insight Into Injections - Paper
2021-01-13
Linux/x86 - bind shell on port 13377 Shellcode (65 bytes)
2021-01-12
SmartAgent 3.1.0 - Privilege Escalation
2021-01-12
Cemetry Mapping and Information System 1.0 - Multiple SQL Injections
2021-01-12
Gila CMS 2.0.0 - Remote Code Execution (Unauthenticated)
2021-01-12
Prestashop 1.7.7.0 - 'id_product' Time Based Blind SQL Injection
2021-01-11
PortableKanban 4.3.6578.38136 - Encrypted Password Retrieval
2021-01-11
OpenCart 3.0.36 - ATO via Cross Site Request Forgery
2021-01-11
WordPress Plugin Custom Global Variables 1.0.5 - 'name' Stored Cross-Site Scripting (XSS)
2021-01-11
Cemetry Mapping and Information System 1.0 - Multiple Stored Cross-Site Scripting
2021-01-11
EyesOfNetwork 5.3 - LFI
2021-01-11
Anchor CMS 0.12.7 - 'markdown' Stored Cross-Site Scripting
2021-01-11
EyesOfNetwork 5.3 - RCE & PrivEsc
2021-01-11
Wordpress Plugin wpDiscuz 7.0.4 - Unauthenticated Arbitrary File Upload (Metasploit)
2021-01-08
WordPress Plugin Autoptimize 2.7.6 - Authenticated Arbitrary File Upload (Metasploit)
2021-01-08
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
2021-01-08
Cockpit Version 234 - Server-Side Request Forgery (Unauthenticated)
2021-01-08
Online Doctor Appointment System 1.0 - Multiple Stored XSS
2021-01-08
Life Insurance Management System 1.0 - Multiple Stored XSS
2021-01-08
dnsrecon 0.10.0 - CSV Injection
2021-01-08
CRUD Operation 1.0 - Multiple Stored XSS
2021-01-07
ECSIMAGING PACS 6.21.5 - SQL injection
2021-01-07
Curfew e-Pass Management System 1.0 - Stored XSS
2021-01-07
Cockpit CMS 0.6.1 - Remote Code Execution
2021-01-07
Employee Record System 1.0 - Unrestricted File Upload to Remote Code Execution
2021-01-07
ECSIMAGING PACS 6.21.5 - Remote code execution
2021-01-07
iBall-Baton WRA150N Rom-0 Backup - File Disclosure (Sensitive Information)
2021-01-07
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
2021-01-06
H2 Database 1.4.199 - JNI Code Execution
2021-01-06
Gitea 1.7.5 - Remote Code Execution
2021-01-06
PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
2021-01-06
Resumes Management and Job Application Website 1.0 - Multiple Stored XSS
2021-01-06
Resumes Management and Job Application Website 1.0 - RCE (Unauthenticated)
2021-01-06
WinAVR Version 20100110 - Insecure Folder Permissions
2021-01-06
Newgen Correspondence Management System (corms) eGov 12.0 - IDOR
2021-01-06
WordPress Plugin WP24 Domain Check 1.6.2 - 'fieldnameDomain' Stored Cross Site Scripting
2021-01-06
Responsive E-Learning System 1.0 - Stored Cross Site Scripting
2021-01-06
Responsive E-Learning System 1.0 - Unrestricted File Upload to RCE
2021-01-06
WordPress Plugin litespeed cache 3.6 - 'server_ip' Cross-Site Scripting
2021-01-06
Expense Tracker 1.0 - 'Expense Name' Stored Cross-Site Scripting
2021-01-06
IPeakCMS 3.5 - Boolean-based blind SQLi
2021-01-06
IObit Uninstaller 10 Pro - Unquoted Service Path
2021-01-06
dirsearch 0.4.1 - CSV Injection
2021-01-06
Advanced Webhost Billing System 3.7.0 - Cross-Site Request Forgery (CSRF)
2021-01-06
EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Multiple Stored Cross-Site Scripting
2021-01-05
Klog Server 2.4.1 - Command Injection (Unauthenticated)
2021-01-05
Online Learning Management System 1.0 - RCE (Authenticated)
2021-01-05
CSZ CMS 1.2.9 - Multiple Cross-Site Scripting
2021-01-05
Fluentd TD-agent plugin 4.0.1 - Insecure Folder Permission
2021-01-05
Cassandra Web 0.5.0 - Remote File Read
2021-01-05
HPE Edgeline Infrastructure Manager 1.0 - Multiple Remote Vulnerabilities
2021-01-05
Zoom Meeting Connector 4.6.239.20200613 - Remote Root Exploit (Authenticated)
2021-01-05
Responsive FileManager 9.13.4 - 'path' Path Traversal
2021-01-05
Baby Care System 1.0 - 'Post title' Stored XSS
2021-01-05
Responsive ELearning System 1.0 - 'id' Sql Injection
2021-01-05
Online Movie Streaming 1.0 - Authentication Bypass
2021-01-05
WordPress Plugin WP-Paginate 2.1.3 - 'preset' Stored XSS
2021-01-05
WordPress Plugin Stripe Payments 2.0.39 - 'AcceptStripePayments-settings[currency_code]' Stored XSS
2021-01-05
Resumes Management and Job Application Website 1.0 - Authentication Bypass (Sql Injection)
2021-01-05
House Rental and Property Listing 1.0 - Multiple Stored XSS
2021-01-05
IncomCMS 2.0 - Insecure File Upload
2021-01-05
Intel(R) Matrix Storage Event Monitor x86 8.0.0.1039 - 'IAANTMON' Unquoted Service Path
2021-01-05
Parallels Remote Application Server (RAS) 18 IP Disclosure - Paper
2021-01-04
Arteco Web Client DVR/NVR - 'SessionId' Brute Force
2021-01-04
Click2Magic 1.1.5 - Stored Cross-Site Scripting
2021-01-04
Subrion CMS 4.2.1 - 'avatar[path]' XSS
2021-01-04
CMS Made Simple 2.2.15 - RCE (Authenticated)
2021-01-04
sar2html 3.2.1 - 'plot' Remote Code Execution
2021-01-04
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
2021-01-04
Knockpy 4.1.1 - CSV Injection
2021-01-04
A Hands-On Introduction to Insecure Deserialization - Paper
2021-01-04
Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
2021-01-04
4images v1.7.11 - 'Profile Image' Stored Cross-Site Scripting
2021-01-04
Wordpress Core 5.2.2 - 'post previews' XSS
2021-01-04
Easy CD & DVD Cover Creator 4.13 - Denial of Service (PoC)
2021-01-04
MiniTool ShadowMaker 3.2 - 'MTAgentService' Unquoted Service Path
2021-01-04
Apartment Visitors Management System 1.0 - Authentication Bypass
2020-12-24
GitLab 11.4.7 - RCE (Authenticated)
2020-12-24
WordPress Plugin WP-PostRatings 1.86 - 'postratings_image' Cross-Site Scripting
2020-12-24
WordPress Plugin Adning Advertising 1.5.5 - Arbitrary File Upload
2020-12-24
Baby Care System 1.0 - 'roleid' SQL Injection
2020-12-23
TerraMaster TOS 4.2.06 - Unauthenticated Remote Code Execution (Metasploit)
2020-12-23
Sales and Inventory System for Grocery Store 1.0 - Multiple Stored XSS
2020-12-23
Wordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection
2020-12-23
Online Learning Management System 1.0 - 'id' SQL Injection
2020-12-23
Online Learning Management System 1.0 - Multiple Stored XSS
2020-12-23
Online Learning Management System 1.0 - Authentication Bypass
2020-12-23
Class Scheduling System 1.0 - Multiple Stored XSS
2020-12-23
10-Strike Network Inventory Explorer Pro 9.05 - Buffer Overflow (SEH)
2020-12-22
TerraMaster TOS 4.2.06 - RCE (Unauthenticated)
2020-12-22
Faculty Evaluation System 1.0 - Stored XSS
2020-12-22
Artworks Gallery Management System 1.0 - 'id' SQL Injection
2020-12-22
Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit)
2020-12-22
WordPress Plugin W3 Total Cache - Unauthenticated Arbitrary File Read (Metasploit)
2020-12-22
Multi Branch School Management System 3.5 - "Create Branch" Stored XSS
2020-12-22
Library Management System 3.0 - "Add Category" Stored XSS
2020-12-22
CSE Bookstore 1.0 - Multiple SQL Injection
2020-12-22
Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated)
2020-12-22
Victor CMS 1.0 - File Upload To RCE
2020-12-22
Sony Playstation 4 (PS4) < 7.02 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code Execution (PoC)
2020-12-21
Sony Playstation 4 (PS4) < 6.72 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code Execution (PoC)
2020-12-21
Online Marriage Registration System 1.0 - 'searchdata' SQL Injection
2020-12-21
Point of Sale System 1.0 - Multiple Stored XSS
2020-12-21
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
2020-12-21
Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS
2020-12-21
Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
2020-12-21
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
2020-12-21
SCO Openserver 5.0.7 - 'outputform' Command Injection
2020-12-21
SCO Openserver 5.0.7 - 'section' Reflected XSS
2020-12-21
Spiceworks 7.5 - HTTP Header Injection
2020-12-21
Academy-LMS 4.3 - Stored XSS
2020-12-21
Spotweb 1.4.9 - 'search' SQL Injection
2020-12-21
Queue Management System 4.0.0 - "Add User" Stored XSS
2020-12-21
Wordpress Plugin Contact Form 7 5.3.1 - Unrestricted File Upload
2020-12-21
FRITZ!Box 7.20 - DNS Rebinding Protection Bypass
2020-12-19
Xeroneit Library Management System 3.1 - "Add Book Category " Stored XSS
2020-12-19
SyncBreeze 10.0.28 - 'login' Denial of Service (Poc)
2020-12-19
Smart Hospital 3.1 - "Add Patient" Stored XSS
2020-12-19
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read (Metasploit)
2020-12-19
Alumni Management System 1.0 - 'id' SQL Injection
2020-12-19
Alumni Management System 1.0 - "Course Form" Stored XSS
2020-12-19
Alumni Management System 1.0 - Unrestricted File Upload To RCE
2020-12-19
Point of Sale System 1.0 - Authentication Bypass
2020-12-19
Nxlog Community Edition 2.10.2150 - DoS (Poc)
2020-12-19
Victor CMS 1.0 - Multiple SQL Injection (Authenticated)
2020-12-19
PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting)
2020-12-19
Employee Record System 1.0 - Multiple Stored XSS
2020-12-19
Interview Management System 1.0 - 'id' SQL Injection
2020-12-19
Interview Management System 1.0 - Stored XSS in Add New Question
2020-12-19
Online Tours & Travels Management System 1.0 - "id" SQL Injection
2020-12-19
Customer Support System 1.0 - 'id' SQL Injection
2020-12-19
Customer Support System 1.0 - "First Name" & "Last Name" Stored XSS
2020-12-19
Medical Center Portal Management System 1.0 - 'id' SQL Injection
2020-12-19
Content Management System 1.0 - 'id' SQL Injection
2020-12-19
Content Management System 1.0 - 'email' SQL Injection
2020-12-19
Content Management System 1.0 - 'First Name' Stored XSS
2020-12-19
Linksys RE6500 1.0.11.001 - Unauthenticated RCE
2020-12-19
Dolibarr ERP-CRM 12.0.3 - Remote Code Execution (Authenticated)
2020-12-19
Seotoaster 3.2.0 - Stored XSS on Edit page properties
2020-12-19
PrestaShop ProductComments 4.2.0 - 'id_products' Time Based Blind SQL Injection
2020-12-19
Magic Home Pro 1.5.1 - Authentication Bypass
2020-12-19
Raysync 3.3.3.8 - RCE
2020-12-19
Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
2020-12-19
GitLab 11.4.7 - Remote Code Execution (Authenticated)
2020-12-19
Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
2020-12-19
Solaris SunSSH 11.0 x86 - libpam Remote Root
2020-12-19
Online Marriage Registration System (OMRS) 1.0 - Remote Code Execution (Authenticated)
2020-12-19
libbabl 0.1.62 - Broken Double Free Detection (PoC)
2020-12-19
Task Management System 1.0 - 'page' Local File Inclusion
2020-12-19
Gitlab 11.4.7 - Remote Code Execution
2020-12-19
Macally WIFISD2-2A82 2.000.010 - Guest to Root Privilege Escalation
2020-12-19
Rumble Mail Server 0.51.3135 - 'username' Stored XSS
2020-12-19
Rumble Mail Server 0.51.3135 - 'domain and path' Stored XSS
2020-12-19
Rumble Mail Server 0.51.3135 - 'servername' Stored XSS
2020-12-19
WordPress Plugin Total Upkeep 1.14.9 - Database and Files Backup Download
2020-12-19
Seacms 11.1 - 'checkuser' Stored XSS
2020-12-19
Seacms 11.1 - 'file' Local File Inclusion
2020-12-19
Seacms 11.1 - 'ip and weburl' Remote Command Execution
2020-12-19
System Explorer 7.0.0 - 'SystemExplorerHelpService' Unquoted Service Path
2020-12-19
MiniWeb HTTP Server 0.8.19 - Buffer Overflow (PoC)
2020-12-19
LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection
2020-12-19
Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change password)
2020-12-19
Courier Management System 1.0 - 'ref_no' SQL Injection
2020-12-19
Courier Management System 1.0 - 'MULTIPART street ((custom) ' SQL Injection
2020-12-19
Courier Management System 1.0 - 'First Name' Stored XSS
2020-12-19
Dolibarr 12.0.3 - SQLi to RCE
2020-12-19
Supply Chain Management System - Auth Bypass SQL Injection
2020-12-19
Rukovoditel 2.6.1 - RCE
2020-12-19
Jenkins 2.235.3 - 'Description' Stored XSS
2020-12-19
Medical Center Portal Management System 1.0 - Multiple Stored XSS
2020-12-19
Openfire 4.6.0 - 'sql' Stored XSS
2020-12-19
Openfire 4.6.0 - 'users' Stored XSS
2020-12-19
Openfire 4.6.0 - 'groupchatJID' Stored XSS
2020-12-19
Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting
2020-12-19
WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting
2020-12-19
Library Management System 2.0 - Auth Bypass SQL Injection
2020-12-19
Openfire 4.6.0 - 'path' Stored XSS
2020-12-19
OpenCart 3.0.3.6 - Cross Site Request Forgery
2020-12-19
Barcodes generator 1.0 - 'name' Stored Cross Site Scripting
2020-12-19
PDF Complete 3.5.310.2002 - 'pdfsvc.exe' Unquoted Service Path
2020-12-19
Task Management System 1.0 - 'id' SQL Injection
2020-12-19
Task Management System 1.0 - Unrestricted File Upload to Remote Code Execution
2020-12-19
Task Management System 1.0 - 'First Name and Last Name' Stored XSS
2020-12-19
Tibco ObfuscationEngine 5.11 - Fixed Key Password Decryption
2020-12-19
VestaCP 0.9.8-26 - 'backup' Information Disclosure
2020-12-19
VestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation
2020-12-19
Huawei HedEx Lite 200R006C00SPC005 - Path Traversal
2020-12-19
Dup Scout Enterprise 10.0.18 - 'sid' Remote Buffer Overflow (SEH)
2020-12-19
SmarterMail Build 6985 - Remote Code Execution
2020-12-19
Employee Performance Evaluation System 1.0 - 'Task and Description' Persistent Cross Site Scripting
2020-12-08
Online Bus Ticket Reservation 1.0 - SQL Injection
2020-12-08
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell)
2020-12-07
Dup Scout Enterprise 10.0.18 - 'online_registration' Remote Buffer Overflow
2020-12-07
vBulletin 5.6.3 - 'group' Cross Site Scripting
2020-12-07
Savsoft Quiz 5 - 'Skype ID' Stored XSS
2020-12-07
RarmaRadio 2.72.5 - Denial of Service (PoC)
2020-12-07
TapinRadio 2.13.7 - Denial of Service (PoC)
2020-12-07
Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path
2020-12-07
User Registration & Login and User Management System 2.1 - Cross Site Request Forgery
2020-12-07
Employee Record Management System 1.1 - Login Bypass SQL Injection
2020-12-07
Realtek Andrea RT Filters 1.0.64.7 - 'AERTSr64.EXE' Unquoted Service Path
2020-12-07
Joomla Plugin Simple Image Gallery Extended (SIGE) 3.5.3 - Multiple Vulnerabilities
2020-12-07
Exploits/page:


Page:
1-4-2 (www01)