jQuery 3.3.1 – Prototype Pollution & XSS Exploit
# Exploit Title: jQuery Prototype Pollution & XSS Exploit (CVE-2019-11358 & CVE-2020-7656)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: jQuery Prototype Pollution & XSS Exploit (CVE-2019-11358 & CVE-2020-7656)
# Exploit Title: InfluxDB OSS Operator Privilege Escalation via BusinessLogic Flaw
# Exploit Title: Sony XAV-AX5500 Firmware Update Validation Remote Code Execution
# Exploit Title: Information Disclosure in GeoVision GV-ASManager
# Exploit Title: Apache Tomcat Path Equivalence - Remote Code Execution
# Exploit Title: YesWiki < 4.5.2 - Unauthenticated Path Traversal
# Exploit Title: XWiki Platform - Remote Code Execution
# Exploit Title: DataEase 2.4.0 - Database Configuration Information Exposure
# Exploit Title: Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
# Exploit Title : Watcharr 1.43.0 - Remote Code Execution (RCE)
# Exploit Title: WordPress Backup and Staging Plugin ≤ 1.21.16 - Arbitrary File Upload to RCE
# Exploit Title: WBCE CMS
# Exploit Title: Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
# Exploit Title : IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
# Exploit Title: Next.js Middleware Bypass Vulnerability (CVE-2025-29927)
# Exploit Title: Kubio AI Page Builder
# Exploit Title: Exclusive Addons for Elementor ≤ 2.6.9 - Authenticated Stored Cross-Site Scripting (XSS)
# Exploit Title: WordPress Plugin Royal Elementor Addons
# Exploit Title: Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
# Exploit Title: Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting ...
# Exploit Title: Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
# Exploit Title : ABB Cylon Aspect 3.07.02 - File Disclosure
# Exploit Title: Vite Arbitrary File Read - CVE-2025-30208
# Exploit Title : ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
# Exploit Title: Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
# Exploit Title: Webmin Usermin 2.100 - Username Enumeration
# Exploit Title: ollama 0.6.4 - SSRF
# Exploit Title: Stored XSS Vulnerability in Nagios Log Server (Privilege Escalation to Admin)
# Exploit Title: AppSmith 1.47 - Remote Code Execution (RCE)
# Exploit Title: Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
# Exploit Title : ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
# Exploit Title : ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
# Exploit Title: SAPGateBreaker Exploit - CVE-2022-22536 - HTTP Request Smuggling Through SAP's Front Door
# Exploit Title: Solstice Pod API Session Key Extraction via API Endpoint
# Exploit Title: CVE-2023-48292 Remote Code Execution Exploit
# Exploit Title: Litespeed Cache 6.5.0.1 - Authentication Bypass
# Exploit Title: CodeCanyon RISE CRM 3.7.0 - SQL Injection
# Exploit Title: Sonatype Nexus Repository 3.53.0-01 - Path Traversal
# Exploit Title: Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
# Exploit Title: Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
# Exploit Title: MoziloCMS 3.0 - Remote Code Execution (RCE)
# Exploit Title: KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
# Exploit Title: X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
# Exploit Title: Container Breakout with NVIDIA Container Toolkit
# Exploit Title: CVE-2024-21320 - NTLM Hash Leak via Malicious Windows Theme
# Exploit Title: Aztech DSL5005EN Router - 'sysAccess.asp' Admin Password Change (Unauthenticated)
# Exploit Title: TeamPass SQL Injection
# Exploit Title: Jasmin Ransomware SQL Injection Login Bypass
# Exploit Title: JUX Real Estate 3.4.0 - SQL Injection
# Exploit Title: FluxBB 1.5.11 Stored xss