Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2016-05-29

FreeBSD Kernel (FreeBSD 10.2 < 10.3 x64) - 'SETFKEY' (PoC)

  • dos
  • freebsd_x86-64
  • CTurt
    2016-05-27

    VideoLAN VLC Media Player 2.2.1 – ‘DecodeAdpcmImaQT’ Buffer Overflow

  • dos
  • windows
  • Patrick Coleman
    2016-05-27

    PHP Realestate Script Script 4.9.0 – SQL Injection

  • webapps
  • php
  • Meisam Monsef
    2016-05-26

    HP Data Protector A.09.00 – Arbitrary Command Execution

  • remote
  • windows
  • Ian Lovering
    2016-05-26

    Micro Focus Rumba+ 9.4 – Multiple Stack Buffer Overflow Vulnerabilities

  • dos
  • windows
  • LiquidWorm
    2016-05-26

    EduSec 4.2.5 – SQL Injection

  • webapps
  • php
  • Bikramaditya Guha
    2016-05-26

    Real Estate Portal 4.1 – Multiple Vulnerabilities

  • webapps
  • php
  • Bikramaditya Guha
    2016-05-26

    Graphite2 – NameTable::getName Multiple Heap Out-of-Bounds Reads

  • dos
  • multiple
  • Google Security Research
    2016-05-26

    Graphite2 – TtfUtil::CmapSubtable4NextCodepoint Heap Overread

  • dos
  • multiple
  • Google Security Research
    2016-05-26

    Graphite2 – TtfUtil::CheckCmapSubtable12 Heap Overread

  • dos
  • multiple
  • Google Security Research
    2016-05-26

    Graphite2 – GlyphCache::Loader Heap Overreads

  • dos
  • multiple
  • Google Security Research
    2016-05-26

    Graphite2 – GlyphCache::GlyphCache Heap Buffer Overflow

  • dos
  • multiple
  • Google Security Research
    2016-05-25

    PowerFolder Server 10.4.321 – Remote Code Execution

  • remote
  • java
  • Hans-Martin Muench
    2016-05-25

    Ubiquiti airOS – Arbitrary File Upload (Metasploit)

  • remote
  • unix
  • Metasploit
    2016-05-25

    Oracle Application Testing Suite (ATS) – Arbitrary File Upload (Metasploit)

  • remote
  • java
  • Metasploit
    2016-05-24

    AfterLogic WebMail Pro ASP.NET 6.2.6 – Administrator Account Disclosure via XML External Entity Injection

  • webapps
  • asp
  • Mehmet Ince
    2016-05-23

    XenAPI 1.4.1 for XenForo – Multiple SQL Injections

  • webapps
  • php
  • Julien Ahrens
    2016-05-23

    WordPress Plugin Job Script by Scubez – Remote Code Execution

  • webapps
  • php
  • Bikramaditya Guha
    2016-05-23

    Operation Technology ETAP 14.1.0 – Multiple Stack Buffer Overrun Vulnerabilities

  • dos
  • windows
  • LiquidWorm
    2016-05-23

    Operation Technology ETAP 14.1.0 – Local Privilege Escalation

  • local
  • windows
  • LiquidWorm
    2016-05-19

    Apple QuickTime – ‘.mov’ Parsing Memory Corruption

  • dos
  • osx
  • Francis Provencher
    2016-05-19

    VirIT Explorer Lite & Pro 8.1.68 – Local Privilege Escalation

  • local
  • windows
  • Paolo Stagno
    2016-05-19

    4digits 1.1.4 – Local Buffer Overflow (PoC)

  • dos
  • linux
  • N_A
    2016-05-19

    SAP NetWeaver AS JAVA 7.1 < 7.5 - Information Disclosure

  • webapps
  • xml
  • ERPScan
    2016-05-19

    SAP NetWeaver AS JAVA 7.1 < 7.5 - SQL Injection

  • webapps
  • xml
  • ERPScan
    2016-05-18

    Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File

  • webapps
  • php
  • agix
    2016-05-17

    Cisco ASA Software 8.x/9.x – IKEv1 / IKEv2 Buffer Overflow

  • remote
  • hardware
  • Exodus Intelligence
    2016-05-17

    Meteocontrol WEB’log – Admin Password Disclosure (Metasploit)

  • webapps
  • multiple
  • Karn Ganeshen
    2016-05-17

    SAP xMII 15.0 – Directory Traversal

  • webapps
  • java
  • ERPScan
    2016-05-17

    Dell SonicWALL Scrutinizer 11.01 – methodDetail SQL Injection (Metasploit)

  • remote
  • multiple
  • Metasploit
    2016-05-17

    Symantec/Norton AntiVirus – ASPack Remote Heap/Pool Memory Corruption

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Microsoft Windows – ‘gdi32.dll’ Heap Buffer Overflow in ExtEscape() Triggerable via EMR_EXTESCAPE EMF Record (MS16-055)

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Microsoft Windows – ‘gdi32.dll’ Multiple ‘EMF COMMENT_MULTIFORMATS’ Record Handling (MS16-055)

  • dos
  • windows
  • Google Security Research
    2016-05-17

    Microsoft Windows – ‘gdi32.dll’ Multiple ‘EMF CREATECOLORSPACEW’ Record Handling (MS16-055)

  • dos
  • windows
  • Google Security Research
    2016-05-17

    Adobe Flash – SetNative Use-After-Free

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Adobe Flash – addProperty Use-After-Free

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Adobe Flash – Type Confusion in FileReference Constructor

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Adobe Flash – ‘.MP4’ Stack Corruption

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Adobe Flash – Heap Overflow in ATF Processing Image Reading

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Adobe Flash – Overflow in Processing Raw 565 Textures

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Adobe Flash – Out-of-Bounds Read when Placing Object

  • dos
  • multiple
  • Google Security Research
    2016-05-17

    Adobe Flash – JXR Processing Out-of-Bounds Read

  • dos
  • multiple
  • Google Security Research
    2016-05-16

    Web2py 2.14.5 – Multiple Vulnerabilities

  • webapps
  • Python
  • Narendra Bhati
    2016-05-16

    Apple OS X 10.10.5 – ‘rootsh’ Local Privilege Escalation

  • local
  • osx
  • Brandon Azad
    2016-05-16

    Hex : Shard of Fate 1.0.1.026 – Unquoted Path Privilege Escalation

  • local
  • windows
  • Cyril Vallicari
    2016-05-16

    Microsoft Excel 2010 – Crash (PoC) (2)

  • dos
  • windows
  • HauntIT
    2016-05-16

    Web Interface for DNSmasq / Mikrotik – SQL Injection

  • webapps
  • php
  • hyp3rlinx
    2016-05-16

    eXtplorer 2.1.9 – ‘.ZIP’ Directory Traversal

  • webapps
  • php
  • hyp3rlinx
    2016-05-16

    Multiples Nexon Games – Unquoted Path Privilege Escalation

  • local
  • windows
  • Cyril Vallicari
    2016-05-16

    CakePHP Framework 3.2.4 – IP Spoofing

  • webapps
  • php
  • Dawid Golunski