Exploits (Total: 96398)

    
    
    
Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
2020-03-30
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation
2020-03-30
Zen Load Balancer 3.10.1 - Remote Code Execution
2020-03-30
10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow (SEH)(ROP)
2020-03-30
Joomla! com_fabrik 3.9.11 - Directory Traversal
2020-03-30
Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service (PoC)
2020-03-30
rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
2020-03-27
Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
2020-03-27
Everest 5.50.2100 - 'Open File' Denial of Service (PoC)
2020-03-27
ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
2020-03-27
Easy RM to MP3 Converter 2.7.3.700 - 'Input' Local Buffer Overflow (SEH)
2020-03-27
Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
2020-03-26
TP-Link Archer C50 3 - Denial of Service (PoC)
2020-03-26
10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)
2020-03-25
Windows/x64 - WinExec Add-Admin Dynamic Null-Free Shellcode (210 Bytes)
2020-03-25
10-Strike Network Inventory Explorer - 'srvInventoryWebServer' Unquoted Service Path
2020-03-25
LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
2020-03-25
AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
2020-03-25
Joomla! Component GMapFP 3.30 - Arbitrary File Upload
2020-03-25
UCM6202 1.0.18.13 - Remote Command Injection
2020-03-24
Veyon 4.3.4 - 'VeyonService' Unquoted Service Path
2020-03-24
Wordpress Plugin WPForms 1.5.9 - Persistent Cross-Site Scripting
2020-03-24
UliCMS 2020.1 - Persistent Cross-Site Scripting
2020-03-24
Linux\x86 - 'reboot' polymorphic Shellcode (26 bytes)
2020-03-23
Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
2020-03-23
rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
2020-03-23
FIBARO System Home Center 5.021 - Remote File Include
2020-03-23
CyberArk PSMP 10.9.1 - Policy Restriction Bypass
2020-03-23
Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
2020-03-23
ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
2020-03-23
VMware Fusion 11.5.2 - Privilege Escalation
2020-03-20
Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
2020-03-20
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
2020-03-19
VMWare Fusion - Local Privilege Escalation
2020-03-18
Microsoft VSCode Python Extension - Code Execution
2020-03-18
Windows\x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
2020-03-18
Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
2020-03-18
NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
2020-03-18
Netlink GPON Router 1.0.11 - Remote Code Execution
2020-03-18
ManageEngine Desktop Central - Java Deserialization (Metasploit)
2020-03-17
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
2020-03-17
PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
2020-03-16
PHPKB Multi-Language 9 - Authenticated Directory Traversal
2020-03-16
PHPKB Multi-Language 9 - Authenticated Remote Code Execution
2020-03-16
MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
2020-03-16
Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
2020-03-16
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)
2020-03-14
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
2020-03-14
Drobo 5N2 4.1.1 - Remote Command Injection
2020-03-13
Centos WebPanel 7 - 'term' SQL Injection
2020-03-13
AnyBurn 4.8 - Buffer Overflow (SEH)
2020-03-13
Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
2020-03-12
Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
2020-03-12
rConfig 3.9 - 'searchColumn' SQL Injection
2020-03-12
rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
2020-03-12
ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
2020-03-12
HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
2020-03-12
Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
2020-03-12
WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
2020-03-12
Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
2020-03-12
Wordpress Plugin Search Meter 2.13.2 - CSV injection
2020-03-11
ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
2020-03-11
PHPStudy - Backdoor Remote Code execution (Metasploit)
2020-03-11
Nagios XI - Authenticated Remote Command Execution (Metasploit)
2020-03-11
Persian VIP Download Script 1.0 - 'active' SQL Injection
2020-03-11
YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
2020-03-11
Sysaid 20.1.11 b26 - Remote Command Execution
2020-03-11
Counter Strike: GO - '.bsp' Memory Control (PoC)
2020-03-11
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
2020-03-11
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
2020-03-11
Google Chrome 67, 68 and 69 - Object.create Type Confusion (Metasploit)
2020-03-11
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
2020-03-11
PHP-FPM - Underflow Remote Code Execution (Metasploit)
2020-03-11
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
2020-03-11
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
2020-03-11
Sentrifugo HRMS 3.2 - 'id' SQL Injection
2020-03-11
60CycleCMS - 'news.php' SQL Injection
2020-03-11
ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization / Unauthenticated Remote Code Execution
2020-03-11
Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Path
2020-03-11
ASUS GiftBox Desktop 1.1.1.127 - 'ASUSGiftBoxDesktop' Unquoted Service Path
2020-03-11
SpyHunter 4 - 'SpyHunter 4 Service' Unquoted Service Path
2020-03-11
Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Service Path
2020-03-11
netkit-telnet-0.17 telnetd (Fedora 31) - 'BraveStarr' Remote Code Execution
2020-03-11
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
2020-03-11
Exchange Control Panel - Viewstate Deserialization (Metasploit)
2020-03-11
UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
2020-03-11
RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
2020-03-04
GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
2020-03-04
Alfresco 5.2.4 - Persistent Cross-Site Scripting
2020-03-04
RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
2020-03-04
Wing FTP Server 6.2.3 - Privilege Escalation
2020-03-02
Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
2020-03-02
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
2020-03-02
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
2020-03-02
TP LINK TL-WR849N - Remote Code Execution
2020-03-02
Wing FTP Server 6.2.5 - Privilege Escalation
2020-03-02
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
2020-03-02
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
2020-03-02
Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
2020-03-02
Netis WF2419 2.2.36123 - Remote Code Execution
2020-03-02
Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
2020-03-02
Joplin Desktop 1.0.184 - Cross-Site Scripting
2020-03-02
qdPM < 9.1 - Remote Code Execution
2020-02-28
Cacti 1.2.8 - Unauthenticated Remote Code Execution
2020-02-27
Cacti 1.2.8 - Authenticated Remote Code Execution
2020-02-27
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
2020-02-27
Comtrend VR-3033 - Command Injection
2020-02-27
Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
2020-02-27
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
2020-02-26
OpenSMTPD 6.6.3 - Arbitrary File Read
2020-02-26
PhpIX 2012 Professional - 'id' SQL Injection
2020-02-26
Core FTP LE 2.2 - Denial of Service (PoC)
2020-02-26
GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
2020-02-26
Odin Secure FTP Expert 7.6.3 - Denial of Service (PoC)
2020-02-25
Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
2020-02-25
WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
2020-02-25
aSc TimeTables 2020.11.4 - Denial of Service (PoC)
2020-02-25
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
2020-02-25
Diamorphine Rootkit - Signal Privilege Escalation (Metasploit)
2020-02-24
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
2020-02-24
Android Binder - Use-After-Free (Metasploit)
2020-02-24
Cacti 1.2.8 - Remote Code Execution
2020-02-24
Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
2020-02-24
DotNetNuke 9.5 - File Upload Restrictions Bypass
2020-02-24
DotNetNuke 9.5 - Persistent Cross-Site Scripting
2020-02-24
eLection 2.0 - 'id' SQL Injection
2020-02-24
Go SSH servers 0.0.2 - Denial of Service (PoC)
2020-02-24
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
2020-02-24
I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure
2020-02-24
ATutor 2.2.4 - 'id' SQL Injection
2020-02-24
Windows\x86 - Null-Free WinExec Calc.exe Shellcode (195 bytes)
2020-02-24
SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure
2020-02-24
AMSS++ 4.7 - Backdoor Admin Account
2020-02-24
CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
2020-02-24
Quick N Easy Web Server 3.3.8 - Denial of Service (PoC)
2020-02-24
SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure
2020-02-24
AMSS++ v 4.31 - 'id' SQL Injection
2020-02-24
ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure
2020-02-24
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
2020-02-24
Core FTP Lite 1.3 - Denial of Service (PoC)
2020-02-20
Easy2Pilot 7 - Cross-Site Request Forgery (Add User)
2020-02-20
Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
2020-02-20
DBPower C300 HD Camera - Remote Configuration Disclosure
2020-02-20
Virtual Freer 1.58 - Remote Command Execution
2020-02-20
Anviz CrossChex - Buffer Overflow (Metasploit)
2020-02-20
LabVantage 8.3 - Information Disclosure
2020-02-20
SOPlanning 1.45 - 'users' SQL Injection
2020-02-20
Cuckoo Clock v5.0 - Buffer Overflow
2020-02-20
SOPlanning 1.45 - Cross-Site Request Forgery (Add User)
2020-02-20
TFTP Turbo 4.6.1273 - 'TFTP Turbo 4' Unquoted Service Path
2020-02-20
WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
2020-02-20
Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
2020-02-20
DHCP Turbo 4.61298 - 'DHCP Turbo 4' Unquoted Service Path
2020-02-20
MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation
2020-02-20
BOOTP Turbo 2.0.1214 - 'BOOTP Turbo' Unquoted Service Path
2020-02-20
Avaya Aura Communication Manager 5.2 - Remote Code Execution
2020-02-20
Wordpress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting
2020-02-20
HP System Event 1.2.9.0 - 'HPWMISVC' Unquoted Service Path
2020-02-20
SOPlanning 1.45 - 'by' SQL Injection
2020-02-20
Hypervisor Necromancy; Reanimating Kernel Protectors
2020-02-20
PHP 7.0 < 7.4 (Unix) - 'debug_backtrace' disable_functions Bypass
2020-02-20
Windows Kernel - Information Disclosure
2020-02-20
SprintWork 2.3.1 - Local Privilege Escalation
2020-02-20
EPSON EasyMP Network Projection 2.81 - 'EMP_NSWLSV' Unquoted Service Path
2020-02-20
HomeGuard Pro 9.3.1 - Insecure Folder Permissions
2020-02-20
phpMyChat Plus 1.98 - 'pmc_username' SQL Injection
2020-02-20
PANDORAFMS 7.0 - Authenticated Remote Code Execution
2020-02-20
OpenTFTP 1.66 - Local Privilege Escalation
2020-02-20
HP System Event Utility - Local Privilege Escalation
2020-02-12
MyVideoConverter Pro 3.14 - 'TVSeries' Buffer Overflow
2020-02-12
MyVideoConverter Pro 3.14 - 'Output Folder' Buffer Overflow
2020-02-12
MyVideoConverter Pro 3.14 - 'Movie' Buffer Overflow
2020-02-12
Microsoft SharePoint - Deserialization Remote Code Execution
2020-02-11
Sudo 1.8.25p - 'pwfeedback' Buffer Overflow
2020-02-11
OpenSMTPD 6.6.1 - Local Privilege Escalation
2020-02-11
Wedding Slideshow Studio 1.36 - 'Name' Buffer Overflow
2020-02-11
Disk Savvy Enterprise 12.3.18 - Unquoted Service Path
2020-02-11
Disk Sorter Enterprise 12.4.16 - 'Disk Sorter Enterprise' Unquoted Service Path
2020-02-11
WordPress InfiniteWP - Client Authentication Bypass (Metasploit)
2020-02-11
DVD Photo Slideshow Professional 8.07 - 'Name' Buffer Overflow
2020-02-11
Sync Breeze Enterprise 12.4.18 - 'Sync Breeze Enterprise' Unquoted Service Path
2020-02-11
FreeSSHd 1.3.1 - 'FreeSSHDService' Unquoted Service Path
2020-02-11
freeFTPd v1.0.13 - 'freeFTPdService' Unquoted Service Path
2020-02-11
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
2020-02-11
DVD Photo Slideshow Professional 8.07 - 'Key' Buffer Overflow
2020-02-11
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
2020-02-11
Torrent iPod Video Converter 1.51 - Stack Overflow
2020-02-11
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
2020-02-10
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
2020-02-10
Ricoh Driver - Privilege Escalation (Metasploit)
2020-02-10
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
2020-02-10
usersctp - Out-of-Bounds Reads in sctp_load_addresses_from_init
2020-02-10
Linux/x86 - Bind Shell Generator Shellcode (114 bytes)
2020-02-10
Dota 2 7.23f - Denial of Service (PoC)
2020-02-10
LearnDash WordPress LMS Plugin 3.1.2 - Reflective Cross-Site Scripting
2020-02-10
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
2020-02-10
Wedding Slideshow Studio 1.36 - 'Key' Buffer Overflow
2020-02-10
Google Invisible RECAPTCHA 3 - Spoof Bypass
2020-02-07
ExpertGPS 6.38 - XML External Entity Injection
2020-02-07
EyesOfNetwork 5.3 - Remote Code Execution
2020-02-07
PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection
2020-02-07
VehicleWorkshop 1.0 - 'bookingid' SQL Injection
2020-02-07
QuickDate 1.3.2 - SQL Injection
2020-02-07
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
2020-02-07
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
2020-02-06
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
2020-02-06
Cisco Data Center Network Manager 11.2 - Remote Code Execution
2020-02-06
Ecommerce Systempay 1.0 - Production KEY Brute Force
2020-02-06
Online Job Portal 1.0 - Cross Site Request Forgery (Add User)
2020-02-06
RarmaRadio 2.72.4 - 'server' Denial of Service (PoC)
2020-02-06
RarmaRadio 2.72.4 - 'username' Denial of Service (PoC)
2020-02-06
TapinRadio 2.12.3 - 'username' Denial of Service (PoC)
2020-02-06
Online Job Portal 1.0 - Remote Code Execution
2020-02-06
TapinRadio 2.12.3 - 'address' Denial of Service (PoC)
2020-02-06
AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service (PoC)
2020-02-06
ELAN Smart-Pad 11.10.15.1 - 'ETDService' Unquoted Service Path
2020-02-06
VIM 8.2 - Denial of Service (PoC)
2020-02-06
Online Job Portal 1.0 - 'user_email' SQL Injection
2020-02-06
AbsoluteTelnet 11.12 - 'license name' Denial of Service (PoC)
2020-02-06
AbsoluteTelnet 11.12 - "license name" Denial of Service (PoC)
2020-02-06
HiSilicon DVR/NVR hi3520d firmware - Remote Backdoor Account
2020-02-05
AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
2020-02-05
Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
2020-02-05
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
2020-02-05
xglance-bin 11.00 - Privilege Escalation
2020-02-05
Socat 1.7.3.4 - Heap-Based Overflow (PoC)
2020-02-05
Wago PFC200 - Authenticated Remote Code Execution (Metasploit)
2020-02-05
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
2020-02-05
F-Secure Internet Gatekeeper 5.40 - Heap Overflow (PoC)
2020-02-04
Sudo 1.8.25p - Buffer Overflow
2020-02-04
Centreon 19.10.5 - 'Pollers' Remote Command Execution (Metasploit)
2020-02-04
P2PWIFICAM2 for iOS 10.4.1 - 'Camera ID' Denial of Service (PoC)
2020-02-03
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
2020-02-03
Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
2020-02-03
ira 8.3.4 - Information Disclosure (Username Enumeration)
2020-02-03
phpList 3.5.0 - Authentication Bypass
2020-02-03
IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
2020-02-03
BearFTP 0.1.0 - 'PASV' Denial of Service
2020-02-03
FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)
2020-01-31
Lotus Core CMS 1.0.1 - Local File Inclusion
2020-01-31
OpenSMTPD 6.6.2 - Remote Code Execution
2020-01-30
rConfig 3.9.3 - Authenticated Remote Code Execution
2020-01-30
Windows/x86 - Dynamic Bind Shell + Null-Free Shellcode (571 Bytes)
2020-01-30
Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
2020-01-29
Centreon 19.10.5 - 'centreontrapd' Remote Command Execution
2020-01-29
Centreon 19.10.5 - 'Pollers' Remote Command Execution
2020-01-29
Satellian 1.12 - Remote Code Execution
2020-01-29
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
2020-01-29
XMLBlueprint 16.191112 - XML External Entity Injection
2020-01-29
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
2020-01-29
Exploits/page:


Page:
1-4-2 (www01)