Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24745Exploits
日期 标题 类型 平台 作者
2023-04-06

LDAP Tool Box Self Service Password v1.5.2 – Account takeover

  • webapps
  • php
  • Tahar BENNACEF
    2023-04-06

    Osprey Pump Controller 1.0.1 – (eventFileSelected) Command Injection

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Music Gallery Site v1.0 – SQL Injection on page view_music_details.php

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    Intern Record System v1.0 – SQL Injection (Unauthenticated)

  • webapps
  • php
  • Hamdi Sevben
    2023-04-06

    Osprey Pump Controller 1.0.1 – Unauthenticated Remote Code Execution Exploit

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Music Gallery Site v1.0 – Broken Access Control

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    Simple Task Managing System v1.0 – SQL Injection (Unauthenticated)

  • webapps
  • php
  • Hamdi Sevben
    2023-04-06

    Osprey Pump Controller 1.0.1 – Cross-Site Request Forgery

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Music Gallery Site v1.0 – SQL Injection on music_list.php

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    Art Gallery Management System Project in PHP v 1.0 – SQL injection

  • webapps
  • php
  • Yogesh Verma
    2023-04-06

    Osprey Pump Controller 1.0.1 – Authentication Bypass Credentials Modification

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Employee Task Management System v1.0 – SQL Injection on edit-task.php

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    atrocore 1.5.25 User interaction – Unauthenticated File upload – RCE

  • webapps
  • php
  • nu11secur1ty
    2023-04-06

    Osprey Pump Controller v1.0.1 – Unauthenticated Reflected XSS

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Employee Task Management System v1.0 – SQL Injection on (task-details.php?task_id=?)

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    Dompdf 1.2.1 – Remote Code Execution (RCE)

  • webapps
  • php
  • Ravindu Wickramasinghe
    2023-04-06

    Osprey Pump Controller 1.0.1 – (userName) Blind Command Injection

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Employee Task Management System v1.0 – Broken Authentication

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    Arris Router Firmware 9.1.103 – Remote Code Execution (RCE) (Authenticated)

  • remote
  • hardware
  • Yerodin Richards
    2023-04-06

    Osprey Pump Controller 1.0.1 – (pseudonym) Semi-blind Command Injection

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Auto Dealer Management System v1.0 – SQL Injection on manage_user.php

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    TitanFTP 2.0.1.2102 – Path traversal to Remote Code Execution (RCE)

  • remote
  • windows
  • Andreas Finstad
    2023-04-06

    Osprey Pump Controller 1.0.1 – Administrator Backdoor Access

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Auto Dealer Management System v1.0 – SQL Injection in sell_vehicle.php

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    FileZilla Client 3.63.1 – ‘TextShaping.dl’ DLL Hijacking

  • local
  • windows
  • Bilal Qureshi
    2023-04-06

    Osprey Pump Controller 1.0.1 – Unauthenticated File Disclosure

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Auto Dealer Management System v1.0 – SQL Injection

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    EasyNas 1.1.0 – OS Command Injection

  • remote
  • hardware
  • Ivan Spiridonov
    2023-04-06

    craftercms 4.x.x – CORS

  • webapps
  • multiple
  • nu11secur1ty
    2023-04-06

    Osprey Pump Controller 1.0.1 – Predictable Session Token / Session Hijack

  • remote
  • hardware
  • LiquidWorm
    2023-04-06

    Auto Dealer Management System 1.0 – Broken Access Control Exploit

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-06

    Purchase Order Management-1.0 – Local File Inclusion

  • webapps
  • php
  • nu11secur1ty
    2023-04-06

    ChurchCRM v4.5.3-121fcc1 – SQL Injection

  • webapps
  • php
  • nu11secur1ty
    2023-04-06

    Best pos Management System v1.0 – Remote Code Execution (RCE) on File Upload

  • webapps
  • php
  • Ahmed Ismail
    2023-04-05

    Binwalk v2.3.2 – Remote Command Execution (RCE)

  • remote
  • Python
  • Etienne Lacoche
    2023-04-05

    XWorm Trojan 2.1 – Null Pointer Derefernce DoS

  • dos
  • windows
  • TOUHAMI Kasbaoui
    2023-04-05

    Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB – Information Disclosure

  • remote
  • hardware
  • Ken Pyle
    2023-04-05

    Provide Server v.14.4 XSS – CSRF & Remote Code Execution (RCE)

  • webapps
  • multiple
  • Andreas Finstad
    2023-04-05

    PostgreSQL 9.6.1 – Remote Code Execution (RCE) (Authenticated)

  • remote
  • multiple
  • Paulo Trindade
    2023-04-05

    Froxlor 2.0.3 Stable – Remote Code Execution (RCE)

  • webapps
  • php
  • Askar
    2023-04-05

    Online Eyewear Shop 1.0 – SQL Injection (Unauthenticated)

  • webapps
  • php
  • Muhammad Navaid Zafar Ansari
    2023-04-05

    Apache Tomcat 10.1 – Denial Of Service

  • dos
  • multiple
  • Cristian Giustini
    2023-04-05

    bgERP v22.31 (Orlovets) – Cookie Session vulnerability & Cross-Site Scripting (XSS)

  • webapps
  • php
  • nu11secur1ty
    2023-04-05

    ImageMagick 7.1.0-49 – Arbitrary File Read

  • local
  • multiple
  • Cristian Giustini
    2023-04-05

    Liferay Portal 6.2.5 – Insecure Permissions

  • webapps
  • java
  • Fu2x2000
    2023-04-05

    CKEditor 5 35.4.0 – Cross-Site Scripting (XSS)

  • webapps
  • php
  • Manish Pathak
    2023-04-05

    D-Link DIR-846 – Remote Command Execution (RCE) vulnerability

  • remote
  • hardware
  • Françoa Taffarel
    2023-04-05

    SOUND4 LinkAndShare Transmitter 1.1.2 – Format String Stack Buffer Overflow

  • remote
  • hardware
  • LiquidWorm
    2023-04-05

    Bus Pass Management System 1.0 – Stored Cross-Site Scripting (XSS)

  • webapps
  • php
  • Matteo Conti
    2023-04-05

    Answerdev 1.0.3 – Account Takeover

  • webapps
  • go
  • Eduardo Pérez-Malumbres Cervera