Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2016-11-13

ATutor 2.2.2 – Cross-Site Request Forgery (Add New Course)

  • webapps
  • php
  • Saravana Kumar
    2016-11-13

    Schoolhos CMS 2.29 – Remote Code Execution / SQL Injection

  • webapps
  • php
  • 0x4148
    2016-11-12

    WordPress Plugin BBS e-Franchise 1.1.1 – SQL Injection

  • webapps
  • php
  • Lenon Leite
    2016-11-12

    WordPress Plugin Product Catalog 8 1.2.0 – SQL Injection

  • webapps
  • php
  • Lenon Leite
    2016-11-11

    InvoicePlane 1.4.8 – Password Reset

  • webapps
  • php
  • feedersec
    2016-11-10

    4Images 1.7.13 – SQL Injection

  • webapps
  • php
  • 0x4148
    2016-11-10

    MyBB 1.8.6 – Cross-Site Scripting

  • webapps
  • php
  • Curesec Research Team
    2016-11-10

    Microsoft Internet Explorer 11/10/9 – MSHTML ‘PROPERTYDESC::Handle­Style­Component­Property’ Out-of-Bounds Read (MS16-104)

  • dos
  • windows
  • Skylined
    2016-11-10

    Microsoft WININET.dll – ‘CHttp­Header­Parser::Parse­Status­Line’ Out-of-Bounds Read (MS16-104/MS16-105)

  • dos
  • windows
  • Skylined
    2016-11-09

    Microsoft Windows – LSASS SMB NTLM Exchange Null-Pointer Dereference (MS16-137)

  • dos
  • windows
  • laurent gaffie
    2016-11-09

    VBScript 5.8.7600.16385/5.8.9600.16384 – RegExpComp::PnodeParse Out-of-Bounds Read

  • dos
  • windows
  • Skylined
    2016-11-09

    Adobe Connect 9.5.7 – Cross-Site Scripting

  • webapps
  • windows
  • Vulnerability-Lab
    2016-11-09

    e107 CMS 2.1.2 – Privilege Escalation

  • webapps
  • php
  • Kacper Szurek
    2016-11-09

    Microsoft Windows Kernel – ‘win32k’ Denial of Service (MS16-135)

  • dos
  • windows
  • TinySec
    2016-11-08

    Microsoft Windows Server 2008/2012 – LDAP RootDSE Netlogon Denial of Service

  • dos
  • windows
  • Todor Donev
    2016-11-08

    Avira Antivirus 15.0.21.86 – ‘.zip’ Directory Traversal / Command Execution

  • local
  • windows
  • R-73eN
    2016-11-08

    Eir D1000 Wireless Router – WAN Side Remote Command Injection (Metasploit)

  • remote
  • linux_mips
  • Kenzo
    2016-11-08

    PLANET ADSL Router AND-4101 – Remote File Disclosure

  • remote
  • hardware
  • Todor Donev
    2016-11-08

    Netgear WNR500/WNR612v3/JNR1010/JNR2010 ADSL Router – (Authenticated) Remote File Disclosure

  • remote
  • hardware
  • Todor Donev
    2016-11-08

    Netgear JNR1010 ADSL Router – (Authenticated) Remote File Disclosure

  • remote
  • hardware
  • Todor Donev
    2016-11-08

    D-Link DSL-2730U/2750U/2750E ADSL Router – Remote File Disclosure

  • remote
  • hardware
  • Todor Donev
    2016-11-08

    MOVISTAR BHS_RTA ADSL Router – Remote File Disclosure

  • remote
  • hardware
  • Todor Donev
    2016-11-08

    WordPress Plugin WassUp Real Time Analytics 1.9 – Persistent Cross-Site Scripting

  • webapps
  • php
  • Burak Kelebek
    2016-11-08

    WordPress Plugin 404 to 301 2.2.8 – Persistent Cross-Site Scripting

  • webapps
  • php
  • Alyssa Milburn
    2016-11-07

    Microsoft Internet Explorer 9 – MSHTML CPtsTextParaclient::CountApes Out-of-Bounds Read

  • dos
  • windows
  • Skylined
    2016-11-07

    Microsoft Internet Explorer 8/9/10/11 / IIS / CScript.exe/WScript.exe VBScript – CRegExp..Execute Use of Uninitialized Memory (MS14-080/MS14-084)

  • remote
  • windows
  • Skylined
    2016-11-07

    Acoem 01dB CUBE/DUO Smart Noise Monitor – Password Change

  • remote
  • hardware
  • Todor Donev
    2016-11-07

    Schoolhos CMS 2.29 – ‘kelas’ SQL Injection

  • webapps
  • php
  • Vulnerability-Lab
    2016-11-07

    Sophos Web Appliance 4.2.1.3 – Remote Code Execution

  • webapps
  • php
  • KoreLogic
    2016-11-07

    Piwik 2.16.0 – ‘layout’ PHP Object Injection

  • webapps
  • php
  • Egidio Romano
    2016-11-07

    NodCMS – PHP Code Execution

  • webapps
  • php
  • Ashiyane Digital Security Team
    2016-11-06

    SweetRice 1.5.1 – Backup Disclosure

  • webapps
  • php
  • Ashiyane Digital Security Team
    2016-11-06

    SweetRice 1.5.1 – Arbitrary File Upload

  • webapps
  • php
  • Ashiyane Digital Security Team
    2016-11-04

    BolinTech DreamFTP Server 1.02 – ‘RETR’ Remote Buffer Overflow

  • remote
  • windows
  • ScrR1pTK1dd13
    2016-11-04

    PCMan FTP Server 2.0.7 – ‘PORT’ Remote Buffer Overflow

  • remote
  • windows
  • Pablo González
    2016-11-04

    PCMan FTP Server 2.0.7 – ‘SITE CHMOD’ Remote Buffer Overflow

  • remote
  • windows
  • Luis Noriega
    2016-11-04

    PCMan FTP Server 2.0.7 – ‘NLST’ Remote Buffer Overflow

  • remote
  • windows
  • Karri93
    2016-11-04

    Freefloat FTP Server 1.0 – ‘SITE ZONE’ Remote Buffer Overflow

  • remote
  • windows
  • Luis Noriega
    2016-11-04

    IBM AIX 5.3/6.1/7.1/7.2 – ‘lquerylv’ Local Privilege Escalation

  • local
  • aix
  • Hector X. Monsegur
    2016-11-04

    IBM AIX 6.1/7.1/7.2.0.2 – ‘lsmcode’ Local Privilege Escalation

  • local
  • aix
  • Hector X. Monsegur
    2016-11-03

    sNews 1.7.1 – Cross-Site Request Forgery

  • webapps
  • php
  • Amir.ght
    2016-11-03

    PCMan FTP Server 2.0.7 – ‘ACCT’ Remote Buffer Overflow

  • remote
  • windows
  • Cybernetic
    2016-11-03

    ETchat 3.7 – Cross-Site Request Forgery

  • webapps
  • php
  • Hesam Bazvand
    2016-11-03

    SweetRice 1.5.1 – Cross-Site Request Forgery / PHP Code Execution

  • webapps
  • php
  • Ashiyane Digital Security Team
    2016-11-03

    Axessh 4.2 – Denial of Service

  • dos
  • windows
  • hyp3rlinx
    2016-11-03

    SweetRice 1.5.1 – Arbitrary File Download

  • webapps
  • php
  • Ashiyane Digital Security Team
    2016-11-03

    Rapid PHP Editor 14.1 – Remote Command Execution

  • remote
  • windows
  • hyp3rlinx
    2016-11-03

    WinaXe 7.7 ‘FTP client’ – Remote Buffer Overflow

  • remote
  • windows
  • hyp3rlinx
    2016-11-03

    Redaxo 5.2.0 – Cross-Site Request Forgery

  • webapps
  • php
  • Amir.ght
    2016-11-03

    nodCMS – Cross-Site Request Forgery

  • webapps
  • php
  • Amir.ght