Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2016-09-13

Open-Xchange Guard 2.4.2 – Multiple Cross-Site Scripting Vulnerabilities

  • webapps
  • linux
  • Benjamin Daniel Mussler
    2016-09-13

    Multiple Icecream Apps – Insecure File Permissions Privilege Escalation

  • local
  • windows
  • Tulpa
    2016-09-13

    WinSMS 3.43 – Insecure File Permissions Privilege Escalation

  • local
  • windows
  • Tulpa
    2016-09-13

    Microsoft Internet Explorer 11.0.9600.18482 – Use After Free

  • dos
  • windows
  • Marcin Ressel
    2016-09-13

    ASUS DSL-X11 ADSL Router – DNS Change

  • webapps
  • cgi
  • Todor Donev
    2016-09-13

    COMTREND ADSL Router CT-5367 C01_R12 / CT-5624 C01_R03 – DNS Change

  • webapps
  • cgi
  • Todor Donev
    2016-09-13

    Tenda ADSL2/2+ Modem 963281TAN – DNS Change

  • webapps
  • cgi
  • Todor Donev
    2016-09-13

    PLANET VDR-300NU ADSL Router – DNS Change

  • webapps
  • cgi
  • Todor Donev
    2016-09-13

    PIKATEL 96338WS, 96338L-2M-8M – DNS Change

  • webapps
  • cgi
  • Todor Donev
    2016-09-13

    Inteno EG101R1 VoIP Router – DNS Change

  • webapps
  • cgi
  • Todor Donev
    2016-09-12

    MySQL / MariaDB / PerconaDB 5.5.51/5.6.32/5.7.14 – Code Execution / Privilege Escalation

  • local
  • linux
  • Dawid Golunski
    2016-09-09

    Airmail 3.0.2 – Cross-Site Scripting

  • webapps
  • osx
  • redrain
    2016-09-09

    LamaHub 0.0.6.2 – Remote Buffer Overflow

  • remote
  • linux
  • Pi3rrot
    2016-09-09

    Vodafone Mobile Wifi – Reset Admin Password

  • webapps
  • hardware
  • Daniele Linguaglossa
    2016-09-08

    LogMeIn Client 1.3.2462 (x64) – Local Credentials Disclosure

  • local
  • windows_x86-64
  • Yakir Wizman
    2016-09-08

    Dropbox Desktop Client 9.4.49 (x64) – Local Credentials Disclosure

  • local
  • windows_x86-64
  • Yakir Wizman
    2016-09-08

    Adobe Flash – Method Calls Use-After-Free

  • dos
  • multiple
  • Google Security Research
    2016-09-08

    Adobe Flash – Transform.colorTranform Getter Infomation Leak

  • dos
  • multiple
  • Google Security Research
    2016-09-08

    Google Android – libutils UTF16 to UTF8 Conversion Heap Buffer Overflow

  • remote
  • android
  • Google Security Research
    2016-09-08

    Zabbix 2.0 < 3.0.3 - SQL Injection

  • webapps
  • php
  • Zzzians
    2016-09-08

    Jobberbase 2.0 – Multiple Vulnerabilities

  • webapps
  • php
  • Ross Marks
    2016-09-08

    Apple iCloud Desktop Client 5.2.1.0 – Local Credentials Disclosure

  • local
  • windows
  • Yakir Wizman
    2016-09-07

    Adobe ColdFusion < 11 Update 10 - XML External Entity Injection

  • webapps
  • multiple
  • Dawid Golunski
    2016-09-07

    FreePBX 13.0.x < 13.0.154 - Remote Command Execution

  • webapps
  • php
  • i-Hmx
    2016-09-07

    SugarCRM 6.5.23 – REST PHP Object Injection (Metasploit)

  • remote
  • php
  • Egidio Romano
    2016-09-07

    CumulusClips 2.4.1 – Multiple Vulnerabilities

  • webapps
  • php
  • kor3k
    2016-09-07

    TeamViewer 11.0.65452 (x64) – Local Credentials Disclosure

  • local
  • windows_x86-64
  • Alexander Korznikov
    2016-09-06

    Sony Playstation 4 (PS4) 3.15 < 3.55 - WebKit Code Execution (PoC)

  • local
  • hardware
  • TJ Corley
    2016-09-06

    WIN-911 7.17.00 – Multiple Vulnerabilities

  • local
  • windows
  • sh4d0wman
    2016-09-06

    glibc – ‘getaddrinfo’ Remote Stack Buffer Overflow

  • remote
  • linux
  • SpeeDr00t
    2016-09-06

    PHPIPAM 1.2.1 – Multiple Vulnerabilities

  • webapps
  • php
  • Saeed reza Zamanian
    2016-09-05

    MySQL 5.5.45 (x64) – Local Credentials Disclosure

  • local
  • windows_x86-64
  • Yakir Wizman
    2016-09-05

    Navicat Premium 11.2.11 (x64) – Local Database Password Disclosure

  • local
  • windows_x86-64
  • Yakir Wizman
    2016-09-05

    ArcServe UDP 6.0.3792 Update 2 Build 516 – Unquoted Service Path Privilege Escalation

  • local
  • windows
  • sh4d0wman
    2016-09-05

    WordPress Plugin RB Agency 2.4.7 – Local File Disclosure

  • webapps
  • php
  • Persian Hack Team
    2016-09-04

    Belkin F9K1122v1 1.00.30 – Buffer Overflow (via Cross-Site Request Forgery)

  • webapps
  • hardware
  • b1ack0wl
    2016-09-01

    FortiClient SSLVPN 5.4 – Credentials Disclosure

  • local
  • windows
  • Viktor Minin
    2016-08-31

    PHP 7.0 – JsonSerializable::jsonSerialize json_encode Local Denial of Service

  • dos
  • php
  • Yakir Wizman
    2016-08-31

    ZKTeco ZKAccess Security System 5.3.1 – Persistent Cross-Site Scripting

  • webapps
  • jsp
  • LiquidWorm
    2016-08-31

    ZKTeco ZKBioSecurity 3.0 – ‘visLogin.jsp’ Local Authentication Bypass

  • webapps
  • jsp
  • LiquidWorm
    2016-08-31

    ZKTeco ZKBioSecurity 3.0 – Directory Traversal

  • webapps
  • jsp
  • LiquidWorm
    2016-08-31

    ZKTeco ZKBioSecurity 3.0 – Cross-Site Request Forgery (Add Superadmin)

  • webapps
  • jsp
  • LiquidWorm
    2016-08-31

    ZKTeco ZKBioSecurity 3.0 – Hard-Coded Credentials SYSTEM Remote Code Execution

  • webapps
  • jsp
  • LiquidWorm
    2016-08-31

    ZKTeco ZKAccess Professional 3.5.3 – Insecure File Permissions Privilege Escalation

  • local
  • windows
  • LiquidWorm
    2016-08-31

    ZKTeco ZKTime.Net 3.0.1.6 – Insecure File Permissions Privilege Escalation

  • local
  • windows
  • LiquidWorm
    2016-08-31

    PHP 7.0 – ‘AppendIterator::append’ Local Denial of Service

  • dos
  • php
  • Yakir Wizman
    2016-08-31

    PHP 5.0.0 – ‘snmpset()’ Local Denial of Service

  • dos
  • php
  • Yakir Wizman
    2016-08-31

    PHP 5.0.0 – ‘snmprealwalk()’ Local Denial of Service

  • dos
  • php
  • Yakir Wizman
    2016-08-31

    PHP 5.0.0 – ‘snmpwalk()’ Local Denial of Service

  • dos
  • php
  • Yakir Wizman
    2016-08-31

    PHP 5.0.0 – ‘fbird_[p]connect()’ Local Denial of Service

  • dos
  • php
  • Yakir Wizman