Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 124
FreshRSS 1.11.1 – Cross-Site Scripting
Multiple Cross-Site Scripting Vulnerabilities in FreshRSS 1.11.1
CyberArk 9.7 – Memory Disclosure
# Exploit Title: CyberArk 9.7 - Memory Disclosure
Fleetco Fleet Maintenance Management 1.2 – Remote Code Execution
# Exploit Title: Fleetco Fleet Maintenance Management 1.2 - Remote Code Execution
Rockwell Automation Allen-Bradley PowerMonitor 1000 – Cross-Site Scripting
# Exploit Title: Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting
PaloAlto Networks Expedition Migration Tool 1.0.106 – Information Disclosure
# Exploit Title: PaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure
Joomla! Component JE Photo Gallery 1.1 – ‘categoryid’ SQL Injection
# Exploit Title: Joomla! Component JE Photo Gallery 1.1 - SQL Injection
Mozilla Firefox 63.0.1 – Denial of Service (PoC)
# Exploit Title: Mozilla Firefox 63.0.1 - Denial of Service (PoC)
PHP Server Monitor 3.3.1 – Cross-Site Request Forgery
# Exploit Title: PHP Server Monitor 3.3.1 - Cross-Site Request Forgery
Apache Superset < 0.23 - Remote Code Execution
# Exploit Title: Apache Superset < 0.23 - Remote Code Execution
Budabot 4.0 – Denial of Service (PoC)
# Exploit Title: Budabot 4.0 - Denial of Service (PoC)
WordPress Plugin Advanced-Custom-Fields 5.7.7 – Cross-Site Scripting
# Exploit Title: Wordpress Plugins Advanced-custom-fields 5.7.7 - Cross-Site Scripting
Schneider Electric PLC – Session Calculation Authentication Bypass
#!/usr/bin/env python
Linux Kernel 4.8 (Ubuntu 16.04) – Leak sctp Kernel Pointer
# Exploit Title: Linux Kernel 4.8 (Ubuntu 16.04) - Leak sctp kernel pointer
Synaccess netBooter NP-02x/NP-08x 6.8 – Authentication Bypass
Synaccess netBooter NP-02x/NP-08x 6.8 Authentication Bypass
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
# Product Description
WebKit JSC JIT – ‘JSPropertyNameEnumerator’ Type Confusion
When a for-in loop is executed, a JSPropertyNameEnumerator object is created at the beginning and used to store the i...
WebKit JIT – ‘ByteCodeParser::handleIntrinsicCall’ Type Confusion
case ArrayPushIntrinsic: {
WebKit JSC – BytecodeGenerator::hoistSloppyModeFunctionIfNecessary Does not Invalidate the ‘ForInContext’ Object
This is simillar to issue 1263 . When hoisting a function onto the outer scope, if it overwrites the iteration varia...
Ricoh myPrint 2.9.2.4 – Hard-Coded Credentials
# Exploit Title: Ricoh myPrint 2.9.2.4 - Hard-Coded Credentials
WordPress Plugin Easy Testimonials 3.2 – Cross-Site Scripting
# Exploit Title: Wordpress Plugins Easy Testimonials 3.2 - Cross-Site Scripting
MariaDB Client 10.1.26 – Denial of Service (PoC)
# Exploit Title: MariaDB Client 10.1.26 - Denial of Service (PoC)
Ticketly 1.0 – ‘kind_id’ SQL Injection
# Exploit Title: Ticketly 1.0 – Multiple SQL Injection
No-Cms 1.0 – ‘order_by’ SQL Injection
# Exploit Title: No-Cms 1.0 - 'order_by' SQL Injection
Zyxel VMG1312-B10D 5.13AAXA.8 – Directory Traversal
# Exploit Title: Zyxel VMG1312-B10D 5.13AAXA.8 - Directory Traversal
ELBA5 5.8.0 – Remote Code Execution
# Exploit Title: ELBA5 5.8.0 - Remote Code Execution
Arm Whois 3.11 – Buffer Overflow (ASLR)
# Exploit Title: Arm Whois 3.11 - Buffer Overflow (ASLR)
Synaccess netBooter NP-0801DU 7.4 – Cross-Site Request Forgery (Add Admin)
# Title: Synaccess netBooter NP-0801DU 7.4 - Cross-Site Request Forgery (Add Admin)
Ticketly 1.0 – ‘name’ SQL Injection
# Exploit Title: Ticketly 1.0 – 'name' SQL Injection
WordPress Theme CherryFramework 3.1.4 – Backup File Download
# Exploit Title: Wordpress CherryFramework Themes 3.1.4 - Backup File Download
WebOfisi E-Ticaret V4 – ‘urun’ SQL Injection
# Exploit Title: WebOfisi E-Ticaret V4 - 'urun' SQL Injection
Apple macOS 10.13 – ‘workq_kernreturn’ Denial of Service (PoC)
# Exploit Title: MacOS 10.13 - 'workq_kernreturn' Denial of Service (PoC)
Ticketly 1.0 – Cross-Site Request Forgery (Add Admin)
# Exploit Title: Ticketly 1.0 - Cross-Site Request Forgery (Add Admin)
Microsoft Windows – DfMarshal Unsafe Unmarshaling Privilege Escalation
Windows: DfMarshal Unsafe Unmarshaling Elevation of Privilege (Master)
XMPlay 3.8.3 – ‘.m3u’ Denial of Service (PoC)
# Exploit Title: XMPlay 3.8.3 - '.m3u' Denial of Service (PoC)
HTML Video Player 1.2.5 – Buffer-Overflow (SEH)
# Exploit Title: HTML Video Player 1.2.5 - Buffer-Overflow (SEH)