Exploits (Total: 96673)

    
    
    
Online-Exam-System 2015 - 'feedback' SQL Injection
2020-06-05
Online Course Registration 1.0 - Authentication Bypass
2020-06-05
Cayin Digital Signage System xPost 2.5 - Remote Command Injection
2020-06-04
Cayin Signage Media Player 3.0 - Remote Command Injection (root)
2020-06-04
Secure Computing SnapGear Management Console SG560 3.1.5 - Arbitrary File Read
2020-06-04
SnapGear Management Console SG560 3.1.5 - Cross-Site Request Forgery (Add Super User)
2020-06-04
Cayin Content Management Server 11.0 - Remote Command Injection (root)
2020-06-04
Online Marriage Registration System 1.0 - Remote Code Execution
2020-06-04
D-Link DIR-615 T1 20.10 - CAPTCHA Bypass
2020-06-04
Navigate CMS 2.8.7 - Authenticated Directory Traversal
2020-06-04
VMWAre vCloud Director 9.7.0.15498291 - Remote Code Execution
2020-06-04
Navigate CMS 2.8.7 - Cross-Site Request Forgery (Add Admin)
2020-06-04
Clinic Management System 1.0 - Authenticated Arbitrary File Upload
2020-06-04
Oriol Espinal CMS 1.0 - 'id' SQL Injection
2020-06-04
Navigate CMS 2.8.7 - ''sidx' SQL Injection (Authenticated)
2020-06-04
Clinic Management System 1.0 - Unauthenticated Remote Code Execution
2020-06-04
IObit Uninstaller 9.5.0.15 - 'IObit Uninstaller Service' Unquoted Service Path
2020-06-04
Hostel Management System 2.0 - 'id' SQL Injection (Unauthenticated)
2020-06-04
AirControl 1.4.2 - PreAuth Remote Code Execution
2020-06-04
vCloud Director 9.7.0.15498291 - Remote Code Execution
2020-06-03
OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated)
2020-06-02
Clinic Management System 1.0 - Authentication Bypass
2020-06-02
Microsoft Windows - 'SMBGhost' Remote Code Execution
2020-06-02
QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
2020-06-01
VMware vCenter Server 6.7 - Authentication Bypass
2020-06-01
Wordpress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
2020-06-01
Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass
2020-05-29
WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)
2020-05-29
QNAP QTS and Photo Station 6.0.3 - Remote Command Execution
2020-05-28
EyouCMS 1.4.6 - Persistent Cross-Site Scripting
2020-05-28
Online-Exam-System 2015 - 'fid' SQL Injection
2020-05-28
NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection
2020-05-28
OXID eShop 6.3.4 - 'sorting' SQL Injection
2020-05-27
Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting
2020-05-27
osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting
2020-05-27
osTicket 1.14.1 - 'Ticket Queue' Persistent Cross-Site Scripting
2020-05-27
LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting
2020-05-27
Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting
2020-05-27
BIND - 'TSIG' Denial of Service
2020-05-27
WordPress Plugin Drag and Drop File Upload Contact Form 1.3.3.2 - Remote Code Execution
2020-05-26
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
2020-05-26
Joomla! Plugin XCloner Backup 3.5.3 - Local File Inclusion (Authenticated)
2020-05-26
StreamRipper32 2.6 - Buffer Overflow (PoC)
2020-05-26
Open-AudIT 3.3.0 - Reflective Cross-Site Scripting (Authenticated)
2020-05-26
OpenEMR 5.0.1 - Remote Code Execution
2020-05-26
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
2020-05-25
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
2020-05-25
Online Discussion Forum Site 1.0 - Remote Code Execution
2020-05-25
Victor CMS 1.0 - 'add_user' Persistent Cross-Site Scripting
2020-05-25
GoldWave - Buffer Overflow (SEH Unicode)
2020-05-25
Wordpress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated)
2020-05-25
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
2020-05-23
VUPlayer 2.49 .m3u - Local Buffer Overflow (DEP,ASLR)
2020-05-23
Gym Management System 1.0 - Unauthenticated Remote Code Execution
2020-05-23
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
2020-05-23
Dolibarr 11.0.3 - Persistent Cross-Site Scripting
2020-05-23
Filetto 1.0 - 'FEAT' Denial of Service (PoC)
2020-05-23
Konica Minolta FTP Utility 1.0 - 'NLST' Denial of Service (PoC)
2020-05-23
Konica Minolta FTP Utility 1.0 - 'LIST' Denial of Service (PoC)
2020-05-23
OpenEDX platform Ironwood 2.5 - Remote Code Execution
2020-05-23
CloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)
2020-05-23
PHPFusion 9.03.50 - Persistent Cross-Site Scripting
2020-05-23
Composr CMS 10.0.30 - Persistent Cross-Site Scripting
2020-05-23
forma.lms 5.6.40 - Cross-Site Request Forgery (Change Admin Email)
2020-05-23
AbsoluteTelnet 11.21 - 'Username' Denial of Service (PoC)
2020-05-23
CraftCMS 3 vCard Plugin 1.0.0 - Remote Code Execution
2020-05-23
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
2020-05-23
Victor CMS 1.0 - Authenticated Arbitrary File Upload
2020-05-23
NukeViet VMS 4.4.00 - Cross-Site Request Forgery (Change Admin Password)
2020-05-23
Submitty 20.04.01 - Persistent Cross-Site Scripting
2020-05-23
php-fusion 9.03.50 - 'ctype' SQL Injection
2020-05-23
qdPM 9.1 - 'cfg[app_app_name]' Persistent Cross-Site Scripting
2020-05-23
Victor CMS 1.0 - 'cat_id' SQL Injection
2020-05-23
Victor CMS 1.0 - 'comment_author' Persistent Cross-Site Scripting
2020-05-23
HP LinuxKI 6.01 - Remote Command Injection
2020-05-23
Online Healthcare management system 1.0 - Authentication Bypass
2020-05-23
Online Healthcare Patient Record Management System 1.0 - Authentication Bypass
2020-05-23
online Chatting System 1.0 - 'id' SQL Injection
2020-05-23
Monstra CMS 3.0.4 - Authenticated Arbitrary File Upload
2020-05-23
forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting
2020-05-23
Oracle Hospitality RES 3700 5.7 - Remote Code Execution
2020-05-23
Online Examination System 1.0 - 'eid' SQL Injection
2020-05-23
Wordpress Plugin Ajax Load More 5.3.1 - '#1' Authenticated SQL Injection
2020-05-23
Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
2020-05-23
ManageEngine Service Desk 10.0 - Cross-Site Scripting
2020-05-23
vBulletin 5.6.1 - 'nodeId' SQL Injection
2020-05-23
E-Commerce System 1.0 - Unauthenticated Remote Code Execution
2020-05-23
Netlink XPON 1GE WiFi V2801RGW - Remote Command Execution
2020-05-23
Dameware Remote Support 12.1.1.273 - Buffer Overflow (SEH)
2020-05-23
Complaint Management System 1.0 - 'username' SQL Injection
2020-05-23
Sellacious eCommerce 4.6 - Persistent Cross-Site Scripting
2020-05-13
Tryton 5.4 - Persistent Cross-Site Scripting
2020-05-13
Remote Desktop Audit 2.3.0.157 - Buffer Overflow (SEH)
2020-05-13
MacOS 320.whatis Script - Privilege Escalation
2020-05-12
TylerTech Eagle 2018.3.11 - Remote Code Execution
2020-05-12
LanSend 3.2 - Buffer Overflow (SEH)
2020-05-12
qdPM 9.1 - Arbitrary File Upload
2020-05-12
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
2020-05-12
CuteNews 2.1.2 - Authenticated Arbitrary File Upload
2020-05-12
ChopSlider3 Wordpress Plugin3.4 - 'id' SQL Injection
2020-05-12
Orchard Core RC1 - Persistent Cross-Site Scripting
2020-05-12
Phase Botnet - Blind SQL Injection
2020-05-12
LibreNMS 1.46 - 'search' SQL Injection
2020-05-11
Complaint Management System 1.0 - Authentication Bypass
2020-05-11
Victor CMS 1.0 - 'post' SQL Injection
2020-05-11
OpenZ ERP 3.6.60 - Persistent Cross-Site Scripting
2020-05-11
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
2020-05-11
CuteNews 2.1.2 - Arbitrary File Deletion
2020-05-11
Sentrifugo CMS 3.2 - Persistent Cross-Site Scripting
2020-05-11
Kartris 1.6 - Arbitrary File Upload
2020-05-11
Online AgroCulture Farm Management System 1.0 - 'uname' SQL Injection
2020-05-11
Pi-hole < 4.4 - Remote Code Execution / Privileges Escalation
2020-05-11
Pi-hole < 4.4 - Remote Code Execution
2020-05-11
Extreme Networks Aerohive HiveOS 11.0 - Remote Denial of Service (PoC)
2020-05-08
Online AgroCulture Farm Management System 1.0 - 'pid' SQL Injection
2020-05-07
Pisay Online E-Learning System 1.0 - Remote Code Execution
2020-05-07
Online Clothing Store 1.0 - Arbitrary File Upload
2020-05-07
School File Management System 1.0 - 'username' SQL Injection
2020-05-07
Draytek VigorAP 1000C - Persistent Cross-Site Scripting
2020-05-07
Car Park Management System 1.0 - Authentication Bypass
2020-05-07
FlashGet 1.9.6 - Denial of Service (PoC)
2020-05-07
MPC Sharj 3.11.1 - Arbitrary File Download
2020-05-06
YesWiki cercopitheque 2020.04.18.1 - 'id' SQL Injection
2020-05-06
GitLab 12.9.0 - Arbitrary File Read
2020-05-06
webTareas 2.0.p8 - Arbitrary File Deletion
2020-05-06
Online Clothing Store 1.0 - 'username' SQL Injection
2020-05-06
Booked Scheduler 2.7.7 - Authenticated Directory Traversal
2020-05-06
i-doit Open Source CMDB 1.14.1 - Arbitrary File Deletion
2020-05-06
Online Clothing Store 1.0 - Persistent Cross-Site Scripting
2020-05-06
NEC Electra Elite IPK II WebPro 01.03.01 - Session Enumeration
2020-05-05
SimplePHPGal 0.7 - Remote File Inclusion
2020-05-05
PhreeBooks ERP 5.2.5 - Remote Command Execution
2020-05-05
BlogEngine 3.3 - 'syndication.axd' XML External Entity Injection
2020-05-05
Saltstack 3000.2 - Remote Code Execution
2020-05-05
webERP 4.15.1 - Unauthenticated Backup File Access
2020-05-05
Online Scheduling System 1.0 - 'username' SQL Injection
2020-05-05
Oracle Database 11g Release 2 - 'OracleDBConsoleorcl' Unquoted Service Path
2020-05-05
Fishing Reservation System 7.5 - 'uid' SQL Injection
2020-05-05
addressbook 9.0.0.1 - 'id' SQL Injection
2020-05-04
Frigate 3.36 - Buffer Overflow (SEH)
2020-05-04
Outline Service 1.3.3 - 'Outline Service ' Unquoted Service Path
2020-05-04
osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
2020-05-04
BoltWire 6.03 - Local File Inclusion
2020-05-04
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
2020-05-01
Online Scheduling System 1.0 - Authentication Bypass
2020-05-01
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
2020-05-01
HardDrive 2.1 for iOS - Arbitrary File Upload
2020-05-01
Super Backup 2.0.5 for iOS - Directory Traversal
2020-05-01
php-fusion 9.03.50 - Persistent Cross-Site Scripting
2020-05-01
Online Scheduling System 1.0 - Persistent Cross-Site Scripting
2020-05-01
VirtualTablet Server 3.0.2 - Denial of Service (PoC)
2020-05-01
ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
2020-05-01
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
2020-04-29
hits script 1.0 - 'item_name' SQL Injection
2020-04-29
EmEditor 19.8 - Insecure File Permissions
2020-04-29
Internet Download Manager 6.37.11.1 - Stack Buffer Overflow (PoC)
2020-04-29
Andrea ST Filters Service 1.0.64.7 - 'Andrea ST Filters Service ' Unquoted Service Path
2020-04-29
Easy Transfer 1.7 for iOS - Directory Traversal
2020-04-29
School ERP Pro 1.0 - Arbitrary File Read
2020-04-29
Open-AudIT Professional 3.3.1 - Remote Code Execution
2020-04-29
School ERP Pro 1.0 - Remote Code Execution
2020-04-29
NVIDIA Update Service Daemon 1.0.21 - 'nvUpdatusService' Unquoted Service Path
2020-04-29
School ERP Pro 1.0 - 'es_messagesid' SQL Injection
2020-04-29
CloudMe 1.11.2 - Buffer Overflow (PoC)
2020-04-29
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
2020-04-29
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
2020-04-29
Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
2020-04-29
Online Course Registration 2.0 - Authentication Bypass
2020-04-29
Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
2020-04-29
Online shopping system advanced 1.0 - 'p' SQL Injection
2020-04-29
Netis E1+ 1.2.32533 - Backdoor Account (root)
2020-04-29
PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
2020-04-29
Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
2020-04-29
Linux/x64 - Password Protected Bindshell + Null-free Shellcode (272 Bytes)
2020-04-29
Popcorn Time 6.2 - 'Update service' Unquoted Service Path
2020-04-29
Edimax EW-7438RPn 1.13 - Remote Code Execution
2020-04-29
EspoCRM 5.8.5 - Privilege Escalation
2020-04-29
Sky File 2.1.0 iOS - Directory Traversal
2020-04-29
Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
2020-04-23
Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
2020-04-23
Complaint Management System 4.2 - Authentication Bypass
2020-04-23
Complaint Management System 4.2 - Persistent Cross-Site Scripting
2020-04-23
User Management System 2.0 - Authentication Bypass
2020-04-23
User Management System 2.0 - Persistent Cross-Site Scripting
2020-04-23
Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
2020-04-22
Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
2020-04-22
Edimax EW-7438RPn - Information Disclosure (WiFi Password)
2020-04-22
RM Downloader 3.1.3.2.2010.06.13 - 'Load' Buffer Overflow (SEH)
2020-04-22
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
2020-04-21
P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
2020-04-21
jizhi CMS 1.6.7 - Arbitrary File Download
2020-04-21
NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
2020-04-21
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
2020-04-21
IQrouter 3.3.1 Firmware - Remote Code Execution
2020-04-21
CSZ CMS 1.2.7 - 'title' HTML Injection
2020-04-21
PMB 5.6 - 'logid' SQL Injection
2020-04-21
Windows/x86 - MSVCRT System + Dynamic Null-free + Add RDP Admin + Disable Firewall + Enable RDP Shellcode (644 Bytes)
2020-04-21
CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
2020-04-21
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
2020-04-20
Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path
2020-04-20
Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH)
2020-04-20
Nsauditor 3.2.1.0 - Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))
2020-04-20
Fork CMS 5.8.0 - Persistent Cross-Site Scripting
2020-04-20
Atomic Alarm Clock 6.3 - Stack Overflow (Unicode+SEH)
2020-04-20
Centreon 19.10.5 - 'id' SQL Injection
2020-04-20
Code Blocks 16.01 - Buffer Overflow (SEH) UNICODE
2020-04-18
Nexus Repository Manager - Java EL Injection RCE (Metasploit)
2020-04-18
Cisco IP Phone 11.7 - Denial of service (PoC)
2020-04-18
TAO Open Source Assessment Platform 3.3.0 RC02 - HTML Injection
2020-04-18
Playable 9.18 iOS - Persistent Cross-Site Scripting
2020-04-18
Easy MPEG to DVD Burner 1.7.11 - Buffer Overflow (SEH + DEP)
2020-04-18
Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
2020-04-18
VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
2020-04-18
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
2020-04-18
PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metasploit)
2020-04-18
Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
2020-04-18
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
2020-04-18
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
2020-04-18
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
2020-04-18
BlazeDVD 7.0.2 - Buffer Overflow (SEH)
2020-04-15
Xeroneit Library Management System 3.0 - 'category' SQL Injection
2020-04-15
File Transfer iFamily 2.1 - Directory Traversal
2020-04-15
DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
2020-04-15
Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
2020-04-15
SeedDMS 5.1.18 - Persistent Cross-Site Scripting
2020-04-15
Pinger 1.0 - Remote Code Execution
2020-04-15
SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
2020-04-15
AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
2020-04-15
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
2020-04-14
WSO2 3.1.0 - Persistent Cross-Site Scripting
2020-04-14
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
2020-04-14
B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)
2020-04-14
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
2020-04-13
Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
2020-04-13
Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (SEH)
2020-04-13
WSO2 3.1.0 - Arbitrary File Delete
2020-04-13
Webtateas 2.0 - Arbitrary File Read
2020-04-13
TVT NVMS 1000 - Directory Traversal
2020-04-13
Huawei HG630 2 Router - Authentication Bypass
2020-04-13
Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
2020-04-10
Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
2020-04-10
AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
2020-04-10
Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
2020-04-08
Django 3.0 - Cross-Site Request Forgery Token Bypass
2020-04-08
dnsmasq-utils 2.79-1 - 'dhcp_release' Denial of Service (PoC)
2020-04-07
ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
2020-04-07
pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
2020-04-06
Microsoft NET USE win10 - Insufficient Authentication Logic
2020-04-06
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
2020-04-06
Bolt CMS 3.7.0 - Authenticated Remote Code Execution
2020-04-06
Exploits/page:


Page:
1-4-2 (www01)