Exploits (Total: 97839)

    
    
    
Online Shopping Alphaware 1.0 - Error Based SQL injection
2020-12-01
Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting
2020-12-01
Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload
2020-12-01
TypeSetter 5.1 - CSRF (Change admin e-mail)
2020-12-01
YATinyWinFTP - Denial of Service (PoC)
2020-11-30
Intelbras Router RF 301K 1.1.2 - Authentication Bypass
2020-11-30
Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
2020-11-30
ATX MiniCMTS200a Broadband Gateway 2.0 - Credential Disclosure
2020-11-30
Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated)
2020-11-27
ElkarBackup 1.3.3 - 'Policy[name]' and 'Policy[Description]' Stored Cross-site Scripting
2020-11-27
libupnp 1.6.18 - Stack-based buffer overflow (DoS)
2020-11-27
House Rental 1.0 - 'keywords' SQL Injection
2020-11-27
Foxit Reader 9.0.1.1049 - Arbitrary Code Execution
2020-11-27
Wordpress Theme Accesspress Social Icons 1.7.9 - SQL injection (Authenticated)
2020-11-27
Moodle 3.8 - Unrestricted File Upload
2020-11-27
Acronis Cyber Backup 12.5 Build 16341 - Unauthenticated SSRF
2020-11-27
FrozenNode Laravel-Administrator 4 - Unrestricted File Upload (Authenticated)
2020-11-27
Ruckus IoT Controller (Ruckus vRIoT) 1.5.1.0.21 - Remote Code Execution
2020-11-27
WonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting
2020-11-27
SAP Lumira 1.31 - Stored Cross-Site Scripting
2020-11-27
Wordpress Theme Wibar 1.1.8 - 'Brand Component' Stored Cross Site Scripting
2020-11-27
Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
2020-11-26
Pure-FTPd 1.0.48 - Remote Denial of Service
2020-11-26
SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow
2020-11-25
osCommerce 2.3.4.1 - 'title' Persistent Cross-Site Scripting
2020-11-25
WonderCMS 3.1.3 - 'page' Persistent Cross-Site Scripting
2020-11-25
Wondershare Driver Install Service help 10.7.1.321 - 'ElevationService' Unquote Service Path
2020-11-25
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
2020-11-24
OpenCart 3.0.3.6 - 'Profile Image' Stored Cross Site Scripting (Authenticated)
2020-11-24
Seowon 130-SLC router 1.0.11 - 'ipAddr' RCE (Authenticated)
2020-11-24
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
2020-11-24
Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
2020-11-24
nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting
2020-11-24
TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
2020-11-23
LifeRay 7.2.1 GA2 - Stored XSS
2020-11-23
VTiger v7.0 CRM - 'To' Persistent XSS
2020-11-23
Boxoft Audio Converter 2.3.0 - '.wav' Buffer Overflow (SEH)
2020-11-23
Boxoft Convert Master 1.3.0 - 'wav' SEH Local Exploit
2020-11-20
Free MP3 CD Ripper 2.8 - Multiple File Buffer Overflow (Metasploit)
2020-11-20
IBM Tivoli Storage Manager Command Line Administrative Interface 5.2.0.1 - id' Field Stack Based Buffer Overflow
2020-11-20
WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
2020-11-20
Zortam Mp3 Media Studio 27.60 - Remote Code Execution (SEH)
2020-11-20
Internet Download Manager 6.38.12 - Scheduler Downloads Scheduler Buffer Overflow (PoC)
2020-11-19
Nagios Log Server 2.1.7 - Persistent Cross-Site Scripting
2020-11-19
M/Monit 3.7.4 - Password Disclosure
2020-11-19
M/Monit 3.7.4 - Privilege Escalation
2020-11-19
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
2020-11-19
TestBox CFML Test Framework 4.1.0 - Directory Traversal
2020-11-19
TestBox CFML Test Framework 4.1.0 - Arbitrary File Write and Remote Code Execution
2020-11-19
Gitlab 12.9.0 - Arbitrary File Read (Authenticated)
2020-11-19
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
2020-11-19
Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
2020-11-19
xuucms 3 - 'keywords' SQL Injection
2020-11-19
PESCMS TEAM 2.3.2 - Multiple Reflected XSS
2020-11-19
ZeroLogon - Netlogon Elevation of Privilege
2020-11-18
BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
2020-11-18
Wordpress Plugin WPForms 1.6.3.1 - Persistent Cross Site Scripting (Authenticated)
2020-11-18
Apache Struts 2.5.20 - Double OGNL evaluation
2020-11-17
Aerospike Database 5.1.0.3 - OS Command Execution
2020-11-17
LCD_Service 1.0.1.0 - 'LCD_Service' Unquote Service Path
2020-11-17
Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting
2020-11-17
Microsoft Internet Explorer 11 - Use-After-Free
2020-11-17
WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting
2020-11-17
SugarCRM 6.5.18 - Persistent Cross-Site Scripting
2020-11-17
Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Injection
2020-11-17
EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass
2020-11-17
Cisco 7937G - DoS/Privilege Escalation
2020-11-16
Car Rental Management System 1.0 - 'car_id' Sql Injection
2020-11-16
Car Rental Management System 1.0 - Remote Code Execution (Authenticated)
2020-11-16
PMB 5.6 - 'chemin' Local File Disclosure
2020-11-16
Atheros Coex Service Application 8.0.0.255 - 'ZAtheros Bt&Wlan Coex Agent' Unquoted Service Path
2020-11-16
User Registration & Login and User Management System 2.1 - Login Bypass SQL Injection
2020-11-16
Car Rental Management System 1.0 - 'id' SQL Injection (Authenticated)
2020-11-16
Logitech Solar Keyboard Service - 'L4301_Solar' Unquoted Service Path
2020-11-16
Advanced System Care Service 13 - 'AdvancedSystemCareService13' Unquoted Service Path
2020-11-16
Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
2020-11-16
KiteService 1.2020.1113.1 - 'KiteService.exe' Unquoted Service Path
2020-11-16
Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
2020-11-16
October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
2020-11-13
OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
2020-11-13
IDT PC Audio 1.0.6425.0 - 'STacSV' Unquoted Service Path
2020-11-13
SAntivirus IC 10.0.21.61 - 'SAntivirusIC' Unquoted Service Path
2020-11-13
DigitalPersona 5.1.0.656 'DpHostW' - Unquoted Service Path
2020-11-13
Touchbase.io 1.10 - Stored Cross Site Scripting
2020-11-13
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
2020-11-13
Citrix ADC NetScaler - Local File Inclusion (Metasploit)
2020-11-13
Bludit 3.9.2 - Authentication Bruteforce Bypass (Metasploit)
2020-11-13
ASUS TM-AC1900 - Arbitrary Command Execution (Metasploit)
2020-11-13
Nidesoft 3GP Video Converter 2.6.18 - Local Stack Buffer Overflow
2020-11-12
Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection
2020-11-12
Water Billing System 1.0 - 'username' and 'password' parameters SQL Injection
2020-11-12
WordPress Plugin Simple File List 4.2.2 - Remote Code Execution
2020-11-12
CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated)
2020-11-11
Customer Support System 1.0 - 'username' Authentication Bypass
2020-11-11
Customer Support System 1.0 - Cross-Site Request Forgery
2020-11-11
Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel
2020-11-11
Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
2020-11-10
ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting
2020-11-10
Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload
2020-11-10
Joplin 1.2.6 - 'link' Cross Site Scripting
2020-11-09
Exploits/page:


Page:
1-4-2 (www01)