Apple macOS Kernel – Use-After-Free Due to Lack of Locking in nvidia GeForce Driver
nvDevice::SetAppSupportBits is external method 0x107 of the nvAccelerator IOService.
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
nvDevice::SetAppSupportBits is external method 0x107 of the nvAccelerator IOService.
getvolattrlist takes a user controlled bufferSize argument via the fgetattrlist syscall.
mptcp_usr_connectx is the handler for the connectx syscall for the AP_MULTIPATH socket family.
ext4 can store data for small regular files as "inline data", meaning that the
# Exploit Title: MyBB Recent Threads Plugin v1.0 - Cross-Site Scripting
#!/usr/bin/python
# Title: Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
# Exploit Title : 10-Strike Network Inventory Explorer 8.54 - Local Buffer Overflow (SEH)
# Exploit Title: 10-Strike Network Inventory Explorer 8.54 - 'Registration Key' Buffer Overflow (SEH)
# Exploit Title: 10-Strike Network Scanner 3.0 - Local Buffer Overflow (SEH)
# Title: WebKitGTK+ < 2.21.3 - Crash (PoC)
# Exploit Title : Jenkins mailer plugin < 1.20 - Cross-Site Request Forgery
# Exploit Title: SearchBlox 8.6.7 Out-Of-Band XML eXternal Entity (OOB-XXE)
#!/usr/bin/python
# Exploit Title: CyberArk < 10 - Memory Disclosure
# Exploit Title: EMS Master Calendar < 8.0.0.20180520 - Reflected Cross-Site Scripting
# Exploit Title: [ XSS at Brother HL series printers]
# Exploit Title: Smartshop 1 - SQL Injection
# Exploit Title: Smartshop 1 - Cross site request forgery
# Exploit Title: GreenCMS v2.3.0603 CSRF vulnerability get webshell
# Exploit Title: GreenCMS v2.3.0603 CSRF vulnerability add admin
# Exploit Title: TAC Xenta 511 and 911 Credentials Disclosure
# Exploit Title: New STAR 2.1 - SQL Injection / Cross-Site Scripting
# Exploit Title: PHP Dashboards NEW v5.5 - 'Login' SQL Injection
# Exploit Title: CSV Import & Export v1.1.0 - SQL Injection / Cross-Site
# Exploit Title: Grid Pro Big Data 1.0 - 'test.php' SQL Injection
function opt(w, arr) {
# Exploit Title: CSRF Privilege Escalation (Creation of an administrator
# Exploit Title: Siemens SIMATIC S7-300 CPU - Remote Denial Of Service
# Exploit title: Yosoro 1.0.4 - Remote Code Execution
Vendor: Appnitro
# [CVE-2018-10094] Dolibarr SQL Injection vulnerability
Qualys Security Advisory
================
# Exploit Title: NUUO NVRmini2 / NVRsolo Arbitrary File Upload Vulnerability
# Exploit Title: MyBB ChangUonDyU Advanced Statistics Plugin v1.0.2 - Cross-Site Scripting
# GNU Barcode 0.99 - Buffer Overflow
# GNU Barcode 0.99 - Memory Leak
# Exploit Title: Facebook Clone Script 1.0.5 - 'search' SQL Injection
# Exploit Title: Facebook Clone Script 1.0.5 - Cross-Site Request Forgery
Title: TP-Link Multiple Router(TL-WR840N and TL-WR841N) Unauthenticated
# Exploit Title: DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter
# Exploit Title: DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter
# Exploit: CloudMe Sync < 1.11.0 - Buffer Overflow (SEH) (DEP Bypass)
# Exploit Title: Wordpress Plugin Events Calendar - SQL Injection
# Exploit Title: Joomla! extension Full Social 1.1.0 - 'search_query' SQL