strongSwan 5.9.13 – DoS
# Exploit Title: strongSwan 5.9.13 - DoS
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: strongSwan 5.9.13 - DoS
# Exploit Title: CubeCart < 6.7.0 - Reflected Cross-Site Scripting
# Exploit Title: Wing FTP Server 8.1.3 - Authenticated Remote Code Execution
# Exploit Title: MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution
# Titles:** Linux Kernel Local Privilege Escalation (CVE-2026-43284 /
# Exploit Title: ZTE H298A / H108N - Unauthenticated Credential Exposure
# Exploit Title: ZTE ZXHN H188A V6 - Authentication Bypass
# Exploit Title: ZTE Routers - Unauthenticated Denial of Service
# Exploit Title: ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
# Exploit Title: Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution
# Exploit Title: Langflow 1.3.0 - Remote Code Execution
# Exploit Title: Prodigy Commerce 3.3.0 - Local File Inclusion
# Exploit Title: MikroORM 7.0.13 - SQL Injection
# Titles: Microsoft - NTLMv2 Hash Capture
# Exploit Title: OpenCATS 0.9.7.4 - SQL Injection
#include
# Exploit Title: MeiG Smart FORGE_SLT711 - OS Command Injection
# Exploit Title: scramble - Remote Code Execution
# Exploit Title: EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation
# Exploit Title: Casdoor 3.54.1 - Arbitrary File Write via Path Traversal
# Titles:** Linux Kernel Local Privilege Escalation (CVE-2026-43284 /
use std::{env, fs, io};
# ExploitTitle: cPanel 11.40 - CRLF Injection
# Exploit Title: Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover
# Exploit Title: D-Link DSL2600U - 'rom-0' Admin Password Disclosure
# Exploit Title: Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service
# Exploit Title: Grav CMS < 2.0.0-beta.2 - Remote Code Execution (RCE)
# Exploit Title: FUXA 1.2.9 - RCE
# Titles: solaredge - (CSRF-OOB-Injection)
# Exploit Title: Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path
# Exploit Title: BookStack 25.12.1 - Denial of Service
# Exploit Title: Cockpit 359 - RCE
# Exploit Title: Remote Sunrise Helper for Windows 2026.14 -
#!/usr/bin/env python3
# Exploit Title: Windows Snipping Tool - NTLMv2 Hash Hijack
# Exploit Title: PJPROJECT 2.16 - Heap Bufferoverflow
# Exploit Title: ePati Antikor NGFW 2.0.1301 - Authentication Bypass
# Exploit Title: Apache HertzBeat 1.8.0 - Remote Code Execution
# Exploit Title: WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI
# Exploit Title: Flowise < 3.0.5 - Missing Authentication for Critical Function
# Exploit Title: coreruleset 4.21.0 - Firewall Bypass
#!/usr/bin/env python3
# Exploit Title: Ninja Forms Uploads - Unauthenticated PHP File Upload
# Exploit Title: ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)
# Exploit Title: NocoBase 2.0.27 - VM Sandbox Escape
# Exploit Title: Bludit CMS 3.18.4 - RCE
-- Exploit Title: LuaJIT 2.1.1774638290 - Arbitrary Code Execution
# Exploit Title: Ghost CMS 6.19.0 - SQLi
# Exploit Title: telnetd 2.7 - Buffer Overflow