Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2022-08-01

mPDF 7.0 – Local File Inclusion

  • webapps
  • php
  • Musyoka Ian
    2022-07-29

    WordPress Plugin WP-UserOnline 2.87.6 – Stored Cross-Site Scripting (XSS)

  • webapps
  • php
  • Steffin Stanly
    2022-07-29

    Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) – Remote Code Execution

  • remote
  • hardware
  • LiquidWorm
    2022-07-29

    Carel pCOWeb HVAC BACnet Gateway 2.1.0 – Directory Traversal

  • webapps
  • hardware
  • LiquidWorm
    2022-07-29

    Asus GameSDK v1.0.0.4 – ‘GameSDK.exe’ Unquoted Service Path

  • local
  • windows
  • Angelo Pio Amirante
    2022-07-29

    Dingtian-DT-R002 3.1.276A – Authentication Bypass

  • webapps
  • hardware
  • Victor Hanna
    2022-07-29

    rpc.py 0.6.0 – Remote Code Execution (RCE)

  • remote
  • Python
  • Elias Hohl
    2022-07-29

    Geonetwork 4.2.0 – XML External Entity (XXE)

  • webapps
  • multiple
  • Amel BOUZIANE-LEBLOND
    2022-07-26

    WordPress Plugin Visual Slide Box Builder 3.2.9 – SQLi

  • webapps
  • php
  • nu11secur1ty
    2022-07-21

    Dr. Fone 4.0.8 – ‘net_updater32.exe’ Unquoted Service Path

  • local
  • windows
  • Esant1490
    2022-07-21

    Magnolia CMS 6.2.19 – Stored Cross-Site Scripting (XSS)

  • webapps
  • php
  • Giulio Garzia Ozozuz
    2022-07-21

    Kite 1.2021.610.0 – Unquoted Service Path

  • local
  • windows
  • Ghaleb Al-otaibi
    2022-07-21

    IOTransfer 4.0 – Remote Code Execution (RCE)

  • remote
  • windows
  • Tomer Peled
    2022-07-21

    OctoBot WebInterface 0.4.3 – Remote Code Execution (RCE)

  • webapps
  • multiple
  • Samy Younsi
    2022-07-21

    CodoForum v5.1 – Remote Code Execution (RCE)

  • webapps
  • php
  • Krish Pandey
    2022-07-11

    Nginx 1.20.0 – Denial of Service (DOS)

  • remote
  • multiple
  • Mohammed Alshehri
    2022-07-01

    WiFi Mouse 1.7.8.5 – Remote Code Execution(v2)

  • remote
  • windows
  • RedHatAugust
    2022-06-27

    Mailhog 1.0.1 – Stored Cross-Site Scripting (XSS)

  • webapps
  • multiple
  • Vulnz
    2022-06-27

    WSO2 Management Console (Multiple Products) – Unauthenticated Reflected Cross-Site Scripting (XSS)

  • webapps
  • php
  • cxosmo
    2022-06-27

    WordPress Plugin Weblizar 8.9 – Backdoor

  • webapps
  • php
  • Sobhan Mahmoodi
    2022-06-14

    Pandora FMS v7.0NG.742 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • UNICORD
    2022-06-14

    Algo 8028 Control Panel – Remote Code Execution (RCE) (Authenticated)

  • remote
  • hardware
  • Filip Carlsson
    2022-06-14

    HP LaserJet Professional M1210 MFP Series Receive Fax Service – Unquoted Service Path

  • local
  • windows
  • Ali Alipour
    2022-06-14

    Virtua Software Cobranca 12S – SQLi

  • remote
  • windows
  • Luca Regne
    2022-06-14

    Marval MSM v14.19.0.12476 – Cross-Site Request Forgery (CSRF)

  • remote
  • windows
  • Momen Eldawakhly
    2022-06-14

    Marval MSM v14.19.0.12476 – Remote Code Execution (RCE) (Authenticated)

  • remote
  • windows
  • Momen Eldawakhly
    2022-06-14

    Avantune Genialcloud ProJ 10 – Cross-Site Scripting (XSS)

  • webapps
  • multiple
  • Andrea Intilangelo
    2022-06-14

    Real Player 16.0.3.51 – ‘external::Import()’ Directory Traversal to Remote Code Execution (RCE)

  • local
  • windows
  • Eduardo Braun Prado
    2022-06-14

    Real Player v.20.0.8.310 G2 Control – ‘DoGoToURL()’ Remote Code Execution (RCE)

  • local
  • windows
  • Eduardo Braun Prado
    2022-06-14

    SolarView Compact 6.00 – ‘pow’ Cross-Site Scripting (XSS)

  • webapps
  • hardware
  • Ahmed Alroky
    2022-06-14

    SolarView Compact 6.00 – ‘time_begin’ Cross-Site Scripting (XSS)

  • webapps
  • hardware
  • Ahmed Alroky
    2022-06-14

    Old Age Home Management System 1.0 – SQLi Authentication Bypass

  • webapps
  • php
  • twseptian
    2022-06-14

    ChurchCRM 4.4.5 – SQLi

  • webapps
  • php
  • nu11secur1ty
    2022-06-14

    Sourcegraph Gitserver 3.36.3 – Remote Code Execution (RCE)

  • remote
  • multiple
  • Altelus
    2022-06-14

    phpIPAM 1.4.5 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • Guilherme Alves
    2022-06-14

    TP-Link Router AX50 firmware 210730 – Remote Code Execution (RCE) (Authenticated)

  • remote
  • hardware
  • Tomas Melicher
    2022-06-10

    Confluence Data Center 7.18.0 – Remote Code Execution (RCE)

  • webapps
  • java
  • Fellipe Oliveira
    2022-06-10

    WordPress Plugin Motopress Hotel Booking Lite 4.2.4 – Stored Cross-Site Scripting (XSS)

  • webapps
  • php
  • Sanjay Singh
    2022-06-03

    Contao 4.13.2 – Cross-Site Scripting (XSS)

  • webapps
  • php
  • Chetanya Sharma
    2022-06-03

    SolarView Compact 6.00 – Directory Traversal

  • remote
  • hardware
  • Ahmed Alroky
    2022-06-03

    Schneider Electric C-Bus Automation Controller (5500SHAC) 1.10 – Remote Code Execution (RCE)

  • remote
  • hardware
  • LiquidWorm
    2022-06-03

    Telesquare SDT-CW3B1 1.1.0 – OS Command Injection

  • remote
  • hardware
  • Bryan Leong
    2022-06-03

    Microweber CMS 1.2.15 – Account Takeover

  • webapps
  • php
  • Manojkumar J
    2022-06-03

    Zyxel USG FLEX 5.21 – OS Command Injection

  • remote
  • hardware
  • Valentin Lobstein
    2022-05-25

    qdPM 9.1 – Remote Code Execution (RCE) (Authenticated) (v2)

  • webapps
  • php
  • RedHatAugust
    2022-05-23

    m1k1o’s Blog v.10 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • Malte V
    2022-05-23

    OpenCart v3.x Newsletter Module – Blind SQLi

  • webapps
  • php
  • Saud Alenazi
    2022-05-17

    Showdoc 2.10.3 – Stored Cross-Site Scripting (XSS)

  • webapps
  • php
  • Akshay Ravi
    2022-05-17

    SolarView Compact 6.0 – OS Command Injection

  • remote
  • hardware
  • Ahmed Alroky
    2022-05-17

    T-Soft E-Commerce 4 – SQLi (Authenticated)

  • webapps
  • multiple
  • Alperen Ergel