Exploits (Total: 96786)

    
    
    
elaniin CMS 1.0 - Authentication Bypass
2020-01-06
BlueAuditor 1.7.2.0 - 'Name' Denial of Service (PoC)
2020-01-06
Dnss Domain Name Search Software - 'Key' Denial of Service (PoC)
2020-01-06
SpotIE 2.9.5 - 'Key' Denial of Service (PoC)
2020-01-06
Hostel Management System 2.0 - 'id' SQL Injection
2020-01-06
NetworkSleuth 3.0.0.0 - 'Key' Denial of Service (PoC)
2020-01-06
Adaware Web Companion 4.9.2159 - 'WCAssistantService' Unquoted Service Path
2020-01-06
Subrion CMS 4.0.5 - Cross-Site Request Forgery (Add Admin)
2020-01-06
IBM RICOH Infoprint 1532 Printer - Persistent Cross-Site Scripting
2020-01-06
NetShareWatcher 1.5.8.0 - 'Name' Denial Of Service
2020-01-06
Complaint Management System 4.0 - 'cid' SQL injection
2020-01-06
Dairy Farm Shop Management System 1.0 - 'username' SQL Injection
2020-01-06
Plantronics Hub 3.13.2 - Local Privilege Escalation
2020-01-03
Karakuzu ERP Management Web 5.7.0 - 'k_adi_duz' SQL Injection
2020-01-03
Online Course Registration 2.0 - Remote Code Execution
2020-01-03
BloodX 1.0 - Authentication Bypass
2020-01-02
Hospital Management System 4.0 - Persistent Cross-Site Scripting
2020-01-02
Hospital Management System 4.0 - 'searchdata' SQL Injection
2020-01-02
MSN Password Recovery 1.30 - Denial of Service (PoC)
2020-01-02
Microsoft Windows .Group File - Code Execution
2020-01-01
nostromo 1.9.6 - Remote Code Execution
2020-01-01
Hospital Management System 4.0 - Authentication Bypass
2020-01-01
IBM InfoPrint 4247-Z03 Impact Matrix Printer - Directory Traversal
2020-01-01
Shopping Portal ProVersion 3.0 - Authentication Bypass
2020-01-01
Wordpress Ultimate Addons for Beaver Builder 1.2.4.1 - Authentication Bypass
2019-12-31
NextVPN v4.10 - Insecure File Permissions
2019-12-31
FreeBSD-SA-19:15.mqueuefs - Privilege Escalation
2019-12-30
FreeBSD-SA-19:02.fd - Privilege Escalation
2019-12-30
Heatmiser Netmonitor 3.03 - HTML Injection
2019-12-30
RICOH Web Image Monitor 1.09 - HTML Injection
2019-12-30
RICOH SP 4510SF Printer - HTML Injection
2019-12-30
Domain Quester Pro 6.02 - Stack Overflow (SEH)
2019-12-30
MyDomoAtHome REST API Domoticz ISS Gateway 0.2.40 - Information Disclosure
2019-12-30
Heatmiser Netmonitor 3.03 - Hardcoded Credentials
2019-12-30
AVE DOMINAplus 1.10.x - Authentication Bypass
2019-12-30
AVE DOMINAplus 1.10.x - Cross-Site Request Forgery (enable/disable alarm)
2019-12-30
AVE DOMINAplus 1.10.x - Unauthenticated Remote Reboot
2019-12-30
AVE DOMINAplus 1.10.x - Credential Disclosure
2019-12-30
Wing FTP Server 6.0.7 - Unquoted Service Path
2019-12-30
WEMS BEMS 21.3.1 - Undocumented Backdoor Account
2019-12-30
XEROX WorkCentre 7830 Printer - Cross-Site Request Forgery (Add Admin)
2019-12-30
XEROX WorkCentre 7855 Printer - Cross-Site Request Forgery (Add Admin)
2019-12-30
Thrive Smart Home 1.1 - Authentication Bypass
2019-12-30
XEROX WorkCentre 6655 Printer - Cross-Site Request Forgery (Add Admin)
2019-12-30
FTP Navigator 8.03 - Stack Overflow (SEH)
2019-12-30
elearning-script 1.0 - Authentication Bypass
2019-12-30
AVS Audio Converter 9.1.2.600 - Stack Overflow (PoC)
2019-12-30
HomeAutomation 3.3.2 - Remote Code Execution
2019-12-30
HomeAutomation 3.3.2 - Cross-Site Request Forgery (Add Admin)
2019-12-30
HomeAutomation 3.3.2 - Authentication Bypass
2019-12-30
HomeAutomation 3.3.2 - Persistent Cross-Site Scripting
2019-12-30
Microsoft UPnP - Local Privilege Elevation (Metasploit)
2019-12-30
Reptile Rootkit - reptile_cmd Privilege Escalation (Metasploit)
2019-12-30
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
2019-12-30
Prime95 Version 29.8 build 6 - Buffer Overflow (SEH)
2019-12-24
WordPress Core < 5.3.x - 'xmlrpc.php' Denial of Service
2019-12-21
FreeSWITCH 1.10.1 - Command Execution
2019-12-21
phpMyChat-Plus 1.98 - 'pmc_username' Reflected Cross-Site Scripting
2019-12-21
Microsoft Windows 10 BasicRender.sys - Denial of Service (PoC)
2019-12-21
Deutsche Bahn Ticket Vending Machine Local Kiosk - Privilege Escalation
2019-12-19
FTP Navigator 8.03 - 'Custom Command' Denial of Service (SEH)
2019-12-19
Telerik UI - Remote Code Execution via Insecure Deserialization
2019-12-18
OpenMRS - Java Deserialization RCE (Metasploit)
2019-12-18
macOS 10.14.6 (18G87) - Kernel Use-After-Free due to Race Condition in wait_for_namespace_event()
2019-12-18
Rumpus FTP Web File Manager 8.2.9.1 - Reflected Cross-Site Scripting
2019-12-18
AVS Audio Converter 9.1 - 'Exit folder' Buffer Overflow
2019-12-18
Xerox AltaLink C8035 Printer - Cross-Site Request Forgery (Add Admin)
2019-12-18
XnView 2.49.1 - 'Research' Denial of Service (PoC)
2019-12-18
Tautulli 2.1.9 - Cross-Site Request Forgery (ShutDown)
2019-12-18
Linux/x64 - Reverse TCP Stager Shellcode (188 bytes)
2019-12-17
NopCommerce 4.2.0 - Privilege Escalation
2019-12-17
Netgear R6400 - Remote Code Execution
2019-12-17
Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting
2019-12-17
Roxy Fileman 1.4.5 - Directory Traversal
2019-12-17
D-Link DIR-615 Wireless Router  -  Persistent Cross-Site Scripting
2019-12-17
OpenBSD 6.x - Dynamic Loader Privilege Escalation
2019-12-16
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
2019-12-16
D-Link DIR-615 - Privilege Escalation
2019-12-16
FTP Commander Pro 8.03 - Local Stack Overflow
2019-12-13
NVMS 1000 - Directory Traversal
2019-12-13
Bullwark Momentum Series JAWS 1.0 - Directory Traversal
2019-12-12
OpenNetAdmin 18.1.1 - Command Injection Exploit (Metasploit)
2019-12-12
Lenovo Power Management Driver 1.67.17.48 - 'pmdrvs.sys' Denial of Service (PoC)
2019-12-12
Apache Olingo OData 4.0 - XML External Entity Injection
2019-12-11
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
2019-12-11
AppXSvc 17763 - Arbitrary File Overwrite (DoS)
2019-12-11
Product Key Explorer 4.2.0.0 - 'Key' Denial of Service (PoC)
2019-12-11
Product Key Explorer 4.2.0.0 - 'Name' Denial of Service (POC)
2019-12-11
Inim Electronics Smartliving SmartLAN 6.x - Remote Command Execution
2019-12-10
Inim Electronics Smartliving SmartLAN 6.x - Unauthenticated Server-Side Request Forgery
2019-12-10
Inim Electronics Smartliving SmartLAN 6.x - Hard-coded Credentials
2019-12-10
Oracle Siebel Sales 8.1 - Persistent Cross-Site Scripting
2019-12-09
Alcatel-Lucent Omnivista 8770 - Remote Code Execution
2019-12-09
Yachtcontrol Webapplication 1.0 - Unauthenticated Remote Code Execution
2019-12-09
SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)
2019-12-09
PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass
2019-12-09
Omron PLC 1.0.0 - Denial of Service (PoC)
2019-12-09
Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting
2019-12-09
Microsoft Windows 10 - 'WSReset' UAC Protection Bypass (propsys.dll)
2019-12-09
Microsoft Windows - 'WSReset' UAC Protection Bypass (Registry)
2019-12-09
Microsoft Windows - Multiple UAC Protection Bypasses
2019-12-09
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
2019-12-09
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
2019-12-06
Integard Pro NoJs 2.2.0.9026 - Remote Buffer Overflow
2019-12-06
Verot 2.0.3 - Remote Code Execution
2019-12-06
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
2019-12-05
Amiti Antivirus 25.0.640 - Unquoted Service Path
2019-12-05
NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path
2019-12-05
OwnCloud 8.1.8 - Username Disclosure
2019-12-04
Cisco WLC 2504 8.9 - Denial of Service (PoC)
2019-12-04
Microsoft Visual Basic 2010 Express - XML External Entity Injection
2019-12-04
SSDWLAB 6.1 - Authentication Bypass
2019-12-04
Online Clinic Management System 2.2 - HTML Injection
2019-12-04
Microsoft Windows Media Center 2002 - XML External Entity MotW Bypass
2019-12-03
Revive Adserver 4.2 - Remote Code Execution
2019-12-03
Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
2019-12-03
Online Invoicing System 2.6 - 'description' Persistent Cross-Site Scripting
2019-12-03
Xinet Elegant 6 Asset Library Web Interface 6.1.655 - 'username' SQL Injection
2019-12-02
Microsoft Excel 2016 1901 - XML External Entity Injection
2019-12-02
Anviz CrossChex 4.3.12 - Local Buffer Overflow
2019-12-02
Max Secure Anti Virus Plus 19.0.4.020 - Insecure File Permissions
2019-12-02
Nsauditor 3.1.8.0 - 'Key' Denial of Service (PoC)
2019-12-02
Dokuwiki 2018-04-22b - Username Enumeration
2019-12-02
SmartHouse Webapp 6.5.33 - Cross-Site Request Forgery
2019-12-02
Visual Studio 2008 - XML External Entity Injection
2019-12-02
Nsauditor 3.1.8.0 - 'Name' Denial of Service (PoC)
2019-12-02
SpotAuditor 5.3.2 - 'Name' Denial of Service
2019-11-29
Bash 5.0 Patch 11 - SUID Priv Drop Exploit
2019-11-29
Online Inventory Manager 3.2 - Persistent Cross-Site Scripting
2019-11-29
TexasSoft CyberPlanet 6.4.131 - 'CCSrvProxy' Unquoted Service Path
2019-11-29
SpotAuditor 5.3.2 - 'Key' Denial of Service
2019-11-29
Mersive Solstice 2.8.0 - Remote Code Execution
2019-11-28
GHIA CamIP 1.2 for iOS - 'Password' Denial of Service (PoC)
2019-11-28
Wordpress 5.3 - User Disclosure
2019-11-28
SpotAuditor 5.3.2 - 'Base64' Denial Of Service (PoC)
2019-11-27
Microsoft DirectX SDK 2010 - '.PIXrun' Denial Of Service (PoC)
2019-11-27
InduSoft Web Studio 8.1 SP1 - "Atributos" Denial of Service (PoC)
2019-11-26
iNetTools for iOS 8.20 - 'Whois' Denial of Service (PoC)
2019-11-26
VMware WorkStation 12.5.3 - Virtual Machine Escape
2019-11-25
VMware WorkStation 12.5.5 - Virtual Machine Escape
2019-11-25
ClamAV < 0.102.0 - 'bytecode_vm' Code Execution
2019-11-25
Microsoft Windows AppXsvc Deployment Extension - Privilege Escalation
2019-11-25
Easy-Hide-IP 5.0.0.3 - 'EasyRedirect' Unquoted Service Path
2019-11-25
InTouch Machine Edition 8.1 SP1 - 'Atributos' Denial of Service (PoC)
2019-11-25
Waves MaxxAudio Drivers 1.1.6.0 - 'WavesSysSvc64' Unquoted Service Path
2019-11-25
SMPlayer 19.5.0 - Denial of Service (PoC)
2019-11-25
macOS 10.14.6 - root->kernel Privilege Escalation via update_dyld_shared_cache
2019-11-22
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
2019-11-22
LiteManager 4.5.0 - Insecure File Permissions
2019-11-22
ProShow Producer 9.0.3797 - ('ScsiAccess') Unquoted Service Path
2019-11-22
Network Management Card 6.2.0 - Host Header Injection
2019-11-21
GNU Mailutils 3.7 - Privilege Escalation
2019-11-21
TestLink 1.9.19 - Persistent Cross-Site Scripting
2019-11-21
Xorg X11 Server - Local Privilege Escalation (Metasploit)
2019-11-20
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
2019-11-20
Bludit - Directory Traversal Image File Upload (Metasploit)
2019-11-20
FreeSWITCH - Event Socket Command Execution (Metasploit)
2019-11-20
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
2019-11-20
Windows - Escalate UAC Protection Bypass (Via Shell Open Registry Key) (Metasploit)
2019-11-20
Windows - Escalate UAC Protection Bypass (Via dot net profiler) (Metasploit)
2019-11-20
iOS 12.4 - Sandbox Escape due to Integer Overflow in mediaserverd
2019-11-20
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
2019-11-20
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
2019-11-20
OpenNetAdmin 18.1.1 - Remote Code Execution
2019-11-20
WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts
2019-11-19
Apache Httpd mod_rewrite - Open Redirects
2019-11-19
Apache Httpd mod_proxy - Error Page Cross-Site Scripting
2019-11-19
Cisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Execution
2019-11-19
DOUBLEPULSAR (x64) - Hooking 'srv!SrvTransactionNotImplemented' in 'srv!SrvTransaction2DispatchTable'
2019-11-19
Microsoft Windows 10 Build 1803 < 1903 - 'COMahawk' Local Privilege Escalation
2019-11-19
Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free
2019-11-19
HackBack - A DIY guide to rob banks
2019-11-19
[Spanish] HackBack - A DIY guide to rob banks
2019-11-19
XMedia Recode 3.4.8.6 - '.m3u' Denial Of Service
2019-11-19
scadaApp for iOS 1.1.4.0 - 'Servername' Denial of Service (PoC)
2019-11-19
Centova Cast 3.2.12 - Denial of Service (PoC)
2019-11-19
Studio 5000 Logix Designer 30.01.00 - 'FactoryTalk Activation Service' Unquoted Service Path
2019-11-19
BartVPN 1.2.2 - 'BartVPNService' Unquoted Service Path
2019-11-19
ipPulse 1.92 - 'Enter Key' Denial of Service (PoC)
2019-11-19
nipper-ng 0.11.10 - Remote Buffer Overflow (PoC)
2019-11-18
TemaTres 3.0 - 'value' Persistent Cross-site Scripting
2019-11-18
Foscam Video Management System 1.1.4.9 - 'Username' Denial of Service (PoC)
2019-11-18
TemaTres 3.0 - Cross-Site Request Forgery (Add Admin)
2019-11-18
Centova Cast 3.2.11 - Arbitrary File Download
2019-11-18
NCP_Secure_Entry_Client 9.2 - Unquoted Service Paths
2019-11-18
MobileGo 8.5.0 - Insecure File Permissions
2019-11-18
Crystal Live HTTP Server 6.01 - Directory Traversal
2019-11-18
Open Proficy HMI-SCADA 5.0.0.25920 - 'Password' Denial of Service (PoC)
2019-11-18
ASUS HM Com Service 1.00.31 - 'asHMComSvc' Unquoted Service Path
2019-11-18
Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal
2019-11-18
iSmartViewPro 1.3.34 - Denial of Service (PoC)
2019-11-18
Emerson PAC Machine Edition 9.70 Build 8595 - 'FxControlRuntime' Unquoted Service Path
2019-11-18
Shrew Soft VPN Client 2.2.2 - 'iked' Unquoted Service Path
2019-11-15
Xfilesharing 2.5.1 - Arbitrary File Upload
2019-11-14
oXygen XML Editor 21.1.1 - XML External Entity Injection
2019-11-14
Siemens Desigo PX 6.00 - Denial of Service (PoC)
2019-11-14
ScanGuard Antivirus 2020 - Insecure Folder Permissions
2019-11-13
Fastweb Fastgate 0.00.81 - Remote Code Execution
2019-11-13
gSOAP 2.8 - Directory Traversal
2019-11-13
Technicolor TC7300.B0 - 'hostname' Persistent Cross-Site Scripting
2019-11-13
Technicolor TD5130.2 - Remote Command Execution
2019-11-13
FUDForum 3.0.9 - Remote Code Execution
2019-11-13
Linear eMerge E3 1.00-06 - Remote Code Execution
2019-11-13
Bematech Printer MP-4200 - Denial of Service
2019-11-12
Wondershare Application Framework Service - "WsAppService" Unquote Service Path
2019-11-12
Control Center PRO 6.2.9 - Local Stack Based Buffer Overflow (SEH)
2019-11-12
FlexAir Access Control 2.3.35 - Authentication Bypass
2019-11-12
Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
2019-11-12
RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path
2019-11-12
Optergy 2.3.0a - Remote Code Execution (Backdoor)
2019-11-12
Optergy 2.3.0a - Username Disclosure
2019-11-12
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
2019-11-12
FlexAir Access Control 2.4.9api3 - Remote Code Execution
2019-11-12
Alps Pointing-device Controller 8.1202.1711.04 - 'ApHidMonitorService' Unquoted Service Path
2019-11-12
Optergy 2.3.0a - Remote Code Execution
2019-11-12
Atlassian Confluence 6.15.1 - Directory Traversal (Metasploit)
2019-11-12
Prima Access Control 2.3.35 - Arbitrary File Upload
2019-11-12
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
2019-11-12
Joomla 3.9.13 - 'Host' Header Injection
2019-11-12
CBAS-Web 19.0.0 - 'id' Boolean-based Blind SQL Injection
2019-11-12
CBAS-Web 19.0.0 - Username Enumeration
2019-11-12
CBAS-Web 19.0.0 - Information Disclosure
2019-11-12
CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
2019-11-12
CBAS-Web 19.0.0 - Remote Code Execution
2019-11-12
eMerge E3 Access Controller 4.6.07 - Remote Code Execution (Metasploit)
2019-11-12
eMerge E3 Access Controller 4.6.07 - Remote Code Execution
2019-11-12
eMerge50P 5000P 4.6.07 - Remote Code Execution
2019-11-12
eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
2019-11-12
eMerge E3 1.00-06 - Arbitrary File Upload
2019-11-12
Atlassian Confluence 6.15.1 - Directory Traversal
2019-11-12
eMerge E3 1.00-06 - Cross-Site Request Forgery
2019-11-12
eMerge E3 1.00-06 - Remote Code Execution
2019-11-12
eMerge E3 1.00-06 - Privilege Escalation
2019-11-12
Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path
2019-11-12
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
2019-11-12
Acronis True Image OEM 19.0.5128 - 'afcdpsrv' Unquoted Service Path
2019-11-12
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
2019-11-12
Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
2019-11-12
Prima FlexAir Access Control 2.3.38 - Remote Code Execution
2019-11-12
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
2019-11-12
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
2019-11-11
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
2019-11-11
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
2019-11-11
iOS IOUSBDeviceFamily 12.4.1 - 'IOInterruptEventSource' Heap Corruption (PoC)
2019-11-11
XML Notepad 2.8.0.4 - XML External Entity Injection
2019-11-11
Alps HID Monitor Service 8.1.0.10 - 'ApHidMonitorService' Unquote Service Path
2019-11-11
_GCafé 3.0 - 'gbClienService' Unquoted Service Path
2019-11-11
Nextcloud 17 - Cross-Site Request Forgery
2019-11-08
rConfig - install Command Execution (Metasploit)
2019-11-08
Android Janus - APK Signature Bypass (Metasploit)
2019-11-08
Exploits/page:


Page:
1-4-2 (www02)