Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2017-07-13

OrientDB – Code Execution

  • remote
  • windows
  • SecuriTeam
    2017-07-13

    Dasan Networks GPON ONT WiFi Router H64X Series – Configuration Download

  • webapps
  • hardware
  • LiquidWorm
    2017-07-13

    Dasan Networks GPON ONT WiFi Router H64X Series – Privilege Escalation

  • webapps
  • hardware
  • LiquidWorm
    2017-07-12

    WordPress Plugin Sabai Discuss – Cross-Site Scripting

  • webapps
  • php
  • Hesam Bazvand
    2017-07-12

    Skype for Business 2016 – Cross-Site Scripting

  • remote
  • windows
  • nyxgeek
    2017-07-12

    360 Total Security – Local Privilege Escalation

  • remote
  • windows
  • SecuriTeam
    2017-07-11

    Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 – ‘EternalBlue’ SMB Remote Code Execution (MS17-010)

  • remote
  • windows
  • sleepya
    2017-07-11

    NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection

  • webapps
  • linux
  • Paul Taylor
    2017-07-11

    DataTaker DT80 dEX 1.50.012 – Information Disclosure

  • webapps
  • hardware
  • Nassim Asrir
    2017-07-10

    Pelco VideoXpert 1.12.105 – Information Disclosure

  • webapps
  • windows
  • LiquidWorm
    2017-07-10

    Pelco VideoXpert 1.12.105 – Directory Traversal

  • webapps
  • windows
  • LiquidWorm
    2017-07-10

    Pelco VideoXpert 1.12.105 – Local Privilege Escalation

  • local
  • windows
  • LiquidWorm
    2017-07-10

    Pelco Sarix/Spectra Cameras – Remote Code Execution

  • webapps
  • hardware
  • LiquidWorm
    2017-07-10

    Pelco Sarix/Spectra Cameras – Cross-Site Request Forgery (Enable SSH Root Access)

  • webapps
  • hardware
  • LiquidWorm
    2017-07-10

    Pelco Sarix/Spectra Cameras – Cross-Site Request Forgery / Cross-Site Scripting

  • webapps
  • hardware
  • LiquidWorm
    2017-07-10

    NfSen < 1.3.7 / AlienVault OSSIM 5.3.4 - Command Injection

  • webapps
  • linux
  • Paul Taylor
    2017-07-10

    NfSen < 1.3.7 / AlienVault OSSIM < 5.3.6 - Local Privilege Escalation

  • local
  • linux
  • Paul Taylor
    2017-07-08

    Easy File Sharing Web Server 7.2 – GET ‘PassWD’ Remote Buffer Overflow (DEP Bypass)

  • remote
  • windows
  • Sungchul Park
    2017-07-07

    Yaws 1.91 – Remote File Disclosure

  • remote
  • multiple
  • hyp3rlinx
    2017-07-07

    Firefox 54.0.1 – Denial of Service

  • dos
  • windows
  • hyp3rlinx
    2017-07-07

    Counter Strike: Condition Zero – ‘.BSP’ Map File Code Execution

  • local
  • windows
  • Grant Hernandez
    2017-07-07

    Apache Struts 2.3.x Showcase – Remote Code Execution

  • webapps
  • multiple
  • Vex Woo
    2017-07-06

    LibTIFF – ‘_TIFFVGetField (tiffsplit)’ Out-of-Bounds Read

  • dos
  • linux
  • zhangtan
    2017-07-06

    LibTIFF – ‘tif_jbig.c’ Denial of Service

  • dos
  • linux
  • team OWL337
    2017-07-06

    LibTIFF – ‘tif_dirwrite.c’ Denial of Service

  • dos
  • linux
  • team OWL337
    2017-07-05

    Lepide Auditor Suite – ‘createdb()’ Web Console Database Injection / Remote Code Execution

  • remote
  • php
  • mr_me
    2017-07-05

    GoAutoDial CE 3.3 – Authentication Bypass / Command Injection (Metasploit)

  • remote
  • unix
  • Metasploit
    2017-07-04

    Joomla! 3.7 – SQL Injection

  • remote
  • php
  • Manish Tanwar
    2017-07-03

    OpenDreamBox 2.0.0 Plugin WebAdmin – Remote Code Execution

  • webapps
  • hardware
  • Jonatas Fil
    2017-07-03

    WordPress Plugin WatuPRO 5.5.1 – SQL Injection

  • webapps
  • php
  • Manich Koomsusi
    2017-07-02

    Zookeeper 3.5.2 Client – Denial of Service

  • dos
  • multiple
  • Brandon Dennis
    2017-07-01

    Joomla! Component Joomanager 2.0.0 – ‘com_Joomanager’ Arbitrary File Download

  • webapps
  • php
  • Luth1er
    2017-06-30

    LG MRA58K – ‘ASFParser::SetMetaData’ Stack Overflow

  • dos
  • android
  • Google Security Research
    2017-06-30

    Humax HG100R 2.0.6 – Backup File Download

  • webapps
  • hardware
  • gambler
    2017-06-30

    Odoo CRM 10.0 – Code Execution

  • local
  • linux
  • SecuriTeam
    2017-06-30

    Australian Education App – Remote Code Execution

  • remote
  • android
  • intern0t
    2017-06-30

    BestSafe Browser – Man In The Middle Remote Code Execution

  • remote
  • android
  • intern0t
    2017-06-30

    eVestigator Forensic PenTester – Man In The Middle Remote Code Execution

  • remote
  • android
  • intern0t
    2017-06-30

    Google Chrome – Out-of-Bounds Access in RegExp Stubs

  • dos
  • multiple
  • Google Security Research
    2017-06-29

    Veritas/Symantec Backup Exec – SSL NDMP Connection Use-After-Free (Metasploit)

  • remote
  • windows
  • Metasploit
    2017-06-29

    ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit)

  • remote
  • java
  • Metasploit
    2017-06-28

    Flat Assembler 1.7.21 – Local Buffer Overflow

  • local
  • linux
  • Juan Sacco
    2017-06-28

    FreeBSD – ‘setrlimit’ Stack Clash (PoC)

  • dos
  • freebsd_x86
  • Qualys Corporation
    2017-06-28

    FreeBSD – ‘FGPE’ Stack Clash (PoC)

  • dos
  • freebsd_x86
  • Qualys Corporation
    2017-06-28

    FreeBSD – ‘FGPU’ Stack Clash (PoC)

  • dos
  • freebsd_x86
  • Qualys Corporation
    2017-06-28

    Linux Kernel (Debian 9/10 / Ubuntu 14.04.5/16.04.2/17.04 / Fedora 23/24/25) – ‘ldso_dynamic Stack Clash’ Local Privilege Escalation

  • local
  • linux_x86
  • Qualys Corporation
    2017-06-28

    Linux Kernel (Debian 7.7/8.5/9.0 / Ubuntu 14.04.2/16.04.2/17.04 / Fedora 22/25 / CentOS 7.3.1611) – ‘ldso_hwcap_64 Stack Clash’ Local Privilege Escalation

  • local
  • linux_x86-64
  • Qualys Corporation
    2017-06-28

    Linux Kernel (Debian 7/8/9/10 / Fedora 23/24/25 / CentOS 5.3/5.11/6.0/6.8/7.2.1511) – ‘ldso_hwcap Stack Clash’ Local Privilege Escalation

  • local
  • linux_x86
  • Qualys Corporation
    2017-06-28

    Linux Kernel – ‘offset2lib’ Stack Clash

  • local
  • linux_x86
  • Qualys Corporation
    2017-06-28

    NetBSD – ‘Stack Clash’ (PoC)

  • dos
  • netbsd_x86
  • Qualys Corporation