Traccar GPS Tracking System 6.11.1 – Cross-Site WebSocket Hijacking (CSWSH)
# Exploit Title: Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)
# Exploit Title: Windows 11 24H2 - Local Privilege Escalation
# Exploit Title: MindsDB 25.9.1.1 - Path Traversal
# Exploit Title: Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)
#define _GNU_SOURCE
#define _GNU_SOURCE
# Exploit Title: SUSE Manager 4.3.15 - Code Execution
# Exploit Title: deephas 1.0.7 - Prototype Pollution
# Exploit Title: Erugo <= 0.2.14 - Authenticated Remote Code Execution (RCE)
# Exploit Title: Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection
# Exploit Title: Camaleon CMS v2.9.0 - Path Traversal
Exploit Title: Js2Py 0.74 - RCE
# Exploit Title: Frigate NVR 0.16.3 - Remote Code Execution
# Exploit Title: NiceGUI 3.6.1 - Path Traversal
# Exploit Title: SumatraPDF 3.5.2 - Remote Code Execution
# Exploit Title: JUNG Smart Visu Server 1.1.1050- Dos
# Exploit Title: Windows 11 25H2 - Heap Overflow
# Exploit Title: BusyBox 1.37.0 - Path Traversal
# Exploit Title: HUSTOJ Zip-Slip v26.01.24 - RCE
# Exploit Title: Repetier-Server 1.4.10 - Path Traversal
# Exploit Title: Windows 11 23H2 - Denial of Service (DoS)
# Exploit Title: Google Chrome 145.0.7632.75 - CSSFontFeatureValuesMap
# Exploit Title: Python-Multipart 0.0.22 - Path Traversal
# Exploit Title: FUXA 1.2.8 - Authentication Bypass + RCE Exploit
// Exploit Title: Atlona AT-OME-RX21 Authenticated Command Injection
# Exploit Title: LangChain Core - SSTI/RCE
Exploit Title: Fedora Local Privilege Escalation via ABRT
# Exploit Title: Xibo CMS - Authenticated Remote Code Execution via SSTI
# Exploit Title: FacturaScripts 2025.43 - XSS
# Exploit Title: JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution
# Exploit Title: GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)
# Exploit Title: OpenKM Multiple Critical Zero-Day
# Exploit Title: OpenWrt 23.05 - Authenticated Remote Code Execution (RCE)
Exploit title: GeographicLib v2.5.1 - stack buffer overflow
# Exploit Title: phpMyFAQ <= 4.0.16 - Improper Authorization
# Exploit Title: GNU InetUtils telnetd - Remote Privilege Escalation
# Exploit Title: Craft CMS 5.6.16 - RCE
# Exploit Title: HAX CMS 24.x - Stored Cross-Site Scripting (XSS)
# Exploit Title: AVAST Antivirus 25.11 - Unquoted Service Path
# Exploit Title: WordPress Plugin 5.2.0 - Broken Access Control
# Exploit Title: Throttlestop Kernel Driver - Kernel Out-of-Bounds Write Privilege Escalation
# Exploit Title: D-Link DIR-650IN - Authenticated Command Injection
# Exploit Title: NetBT e-Fatura - Privilege Escalation
# Exploit ZSH 5.9 - RCE
#Exploit Title: Jumbo Website Manager - Remote Code Execution
# Exploit Title: RomM < 4.4.1 - XSS_CSRF Chain
# Exploit Title: React Server 19.2.0 - Remote Code Execution
# Exploit Title: Horilla v1.3 - RCE
#!/usr/bin/env python3
# Exploit Title: SQLite 3.50.1 - Heap Overflow