Exploits (Total: 98598)

    
    
    
Projectsend r1295 - 'name' Stored XSS
2021-08-30
Strapi CMS 3.0.0-beta.17.4 - Remote Code Execution (RCE) (Unauthenticated)
2021-08-30
Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated)
2021-08-30
Strapi 3.0.0-beta - Set Password (Unauthenticated)
2021-08-30
MySQL User-Defined (Linux) x32 / x86_64 - 'sys_exec' Local Privilege Escalation (2)
2021-08-30
Bus Pass Management System 1.0 - 'viewid' SQL Injection
2021-08-30
Usermin 1.820 - Remote Code Execution (RCE) (Authenticated)
2021-08-30
ZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated)
2021-08-30
COMMAX UMS Client ActiveX Control 1.7.0.2 - 'CNC_Ctrl.dll' Heap Buffer Overflow
2021-08-27
COMMAX WebViewer ActiveX Control 2.1.4.5 - 'Commax_WebViewer.ocx' Buffer Overflow
2021-08-27
CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated)
2021-08-27
ProcessMaker 3.5.4 - Local File inclusion
2021-08-26
Online Leave Management System 1.0 - Arbitrary File Upload to Shell (Unauthenticated)
2021-08-25
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
2021-08-25
WordPress Plugin Mail Masta 1.0 - Local File Inclusion (2)
2021-08-25
Local administrator is not just with Razer.. it is possible for ALL - Paper
2021-08-25
RaspAP 2.6.6 - Remote Code Execution (RCE) (Authenticated)
2021-08-23
Simple Phone book/directory 1.0 - 'Username' SQL Injection (Unauthenticated)
2021-08-23
JavaScript Static Analysis - Paper (Arabic)
2021-08-23
Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
2021-08-23
Laundry Booking Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
2021-08-20
Laundry Booking Management System 1.0 - 'Multiple' SQL Injection
2021-08-20
Online Traffic Offense Management System 1.0 - 'id' SQL Injection (Authenticated)
2021-08-20
Charity Management System CMS 1.0 - Multiple Vulnerabilities
2021-08-19
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
2021-08-18
COVID19 Testing Management System 1.0 - 'Multiple' SQL Injections
2021-08-18
Simple Image Gallery 1.0 - Remote Code Execution (RCE) (Unauthenticated)
2021-08-18
Crime records Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
2021-08-18
SonicWall NetExtender 10.2.0.300 - Unquoted Service Path
2021-08-17
GeoVision Geowebserver 5.3.3 - LFI / XSS / HHI / RCE
2021-08-17
COMMAX CVD-Axx DVR 5.1.4 - Weak Default Credentials Stream Disclosure
2021-08-17
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - Config Write / DoS (Unauthenticated)
2021-08-17
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - RTSP Credentials Disclosure
2021-08-17
COMMAX Smart Home IoT Control System CDP-1020n - SQL Injection Authentication Bypass
2021-08-17
COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass
2021-08-17
Simple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File Upload
2021-08-17
Simple Water Refilling Station Management System 1.0 - Authentication Bypass
2021-08-17
NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS)
2021-08-17
CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS)
2021-08-17
RATES SYSTEM 1.0 - Authentication Bypass
2021-08-17
Simple Image Gallery System 1.0 - 'id' SQL Injection
2021-08-17
Care2x Open Source Hospital Information Management 2.7 Alpha - 'Multiple' Stored XSS
2021-08-17
Police Crime Record Management System 1.0 - 'casedetails' SQL Injection
2021-08-17
Police Crime Record Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
2021-08-17
easy-mock 1.6.0 - Remote Code Execution (RCE) (Authenticated)
2021-08-17
4images 1.8 - 'limitnumber' SQL Injection (Authenticated)
2021-08-17
RATES SYSTEM 1.0 - 'Multiple' SQL Injections
2021-08-17
Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)
2021-08-17
COVID19 Testing Management System 1.0 - 'searchdata' SQL Injection
2021-08-17
Simple Library Management System 1.0 - 'rollno' SQL Injection
2021-08-10
Xiaomi browser 10.2.4.g - Browser Search History Disclosure
2021-08-10
WordPress Plugin Picture Gallery 1.4.2 - 'Edit Content URL' Stored Cross-Site Scripting (XSS)
2021-08-10
WordPress Plugin LifterLMS 4.21.1 - Access Other Student Grades/Answers via IDOR
2021-08-10
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
2021-08-10
Amica Prodigy 1.7 - Privilege Escalation
2021-08-10
IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated)
2021-08-10
Pass-the-Hash Attack Over Named Pipes Against ESET Server Security - Paper
2021-08-05
GFI Mail Archiver 15.1 - Telerik UI Component Arbitrary File Upload (Unauthenticated)
2021-08-05
Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)
2021-08-05
CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated)
2021-08-05
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE) via Unsafe Deserialization of XMLRPC arguments
2021-08-04
Client Management System 1.1 - 'cname' Stored Cross-site scripting (XSS)
2021-08-04
qdPM 9.2 - DB Connection String and Password Exposure (Unauthenticated)
2021-08-04
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated)
2021-08-04
WordPress Plugin WP Customize Login 1.1 - 'Change Logo Title' Stored Cross-Site Scripting (XSS)
2021-08-04
Hotel Management System 1.0 - Cross-Site Scripting (XSS) Arbitrary File Upload Remote Code Execution (RCE)
2021-08-03
Panasonic Sanyo CCTV Network Camera 2.03-0x - 'Disable Authentication / Change Password' CSRF
2021-08-02
Online Hotel Reservation System 1.0 - 'Multiple' Cross-site scripting (XSS)
2021-08-02
Neo4j 3.4.18 - RMI based Remote Code Execution (RCE)
2021-08-02
Men Salon Management System 1.0 - SQL Injection Authentication Bypass
2021-08-02
Demystifying Nmap Scans on packet level - Paper
2021-07-30
Oracle Fatwire 6.3 - Multiple Vulnerabilities
2021-07-29
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF) to Remote Code Execution (RCE)
2021-07-29
Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection
2021-07-29
IntelliChoice eFORCE Software Suite 2.5.9 - Username Enumeration
2021-07-29
Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download
2021-07-29
Denver IP Camera SHO-110 - Unauthenticated Snapshot
2021-07-29
TripSpark VEO Transportation - Blind SQL Injection
2021-07-28
Denver Smart Wifi Camera SHC-150 - 'Telnet' Remote Code Execution (RCE)
2021-07-28
Event Registration System with QR Code 1.0 - Authentication Bypass & RCE
2021-07-28
Customer Relationship Management System (CRM) 1.0 - Sql Injection Authentication Bypass
2021-07-27
PHP 7.3.15-3 - 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection
2021-07-27
XOS Shop 1.0.9 - 'Multiple' Arbitrary File Deletion (Authenticated)
2021-07-26
NoteBurner 2.35 - Denial Of Service (DoS) (PoC)
2021-07-26
Leawo Prof. Media 11.0.0.1 - Denial of Service (DoS) (PoC)
2021-07-26
Elasticsearch ECE 7.13.3 - Anonymous Database Dump
2021-07-26
Microsoft SharePoint Server 2019 - Remote Code Execution (2)
2021-07-23
WordPress Plugin Simple Post 1.1 - 'Text field' Stored Cross-Site Scripting (XSS)
2021-07-23
ElasticSearch 7.13.3 - Memory disclosure
2021-07-23
CSZ CMS 1.2.9 - 'Multiple' Arbitrary File Deletion
2021-07-23
KevinLAB BEMS 1.0 - File Path Traversal Information Disclosure (Authenticated)
2021-07-23
KevinLAB BEMS 1.0 - Unauthenticated SQL Injection / Authentication Bypass
2021-07-23
KevinLAB BEMS 1.0 - Undocumented Backdoor Account
2021-07-23
Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF)
2021-07-23
WordPress Plugin KN Fix Your Title 1.0.1 - 'Separator' Stored Cross-Site Scripting (XSS)
2021-07-23
PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection
2021-07-23
Linux/x86 - Egghunter Reverse TCP Shell dynamic IP and port Shellcode
2021-07-23
Dolibarr ERP/CRM 10.0.6 - Login Brute Force
2021-07-23
WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher ID field' Stored Cross-Site Scripting (XSS)
2021-07-23
WordPress Plugin LearnPress 3.2.6.8 - Privilege Escalation
2021-07-23
Exploits/page:


Page:
1-4-2 (www01)