Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2015-12-14

Microsoft Internet Explorer 11 – MSHTML!CObjectElement Use-After-Free (MS15-124)

  • dos
  • windows
  • Moritz Jodeit
    2015-12-14

    Polycom VVX-Series Business Media Phones – Directory Traversal

  • webapps
  • hardware
  • Jake Reynolds
    2015-12-14

    Adobe Flash – Type Confusion in Serialization with ObjectEncoder.dynamicPropertyWriter

  • dos
  • multiple
  • Google Security Research
    2015-12-14

    Adobe Flash – Type Confusion in IExternalizable.readExternal When Performing Local Serialization

  • dos
  • multiple
  • Google Security Research
    2015-12-14

    Microsoft Office / COM Object – DLL Planting with ‘comsvcs.dll’ Delay Load of ‘mqrt.dll’ (MS15-132)

  • remote
  • windows
  • Google Security Research
    2015-12-14

    WordPress Plugin Admin Management Xtended 2.4.0 – Privilege escalation

  • webapps
  • php
  • Kacper Szurek
    2015-12-12

    GoAutoDial CE 3.3 – Multiple SQL Injections / Command Injection

  • webapps
  • php
  • R-73eN
    2015-12-10

    Gökhan Balbal Script 2.0 – Cross-Site Request Forgery

  • webapps
  • php
  • KnocKout
    2015-12-10

    iy10 Dizin Scripti – Multiple Vulnerabilities

  • webapps
  • php
  • KnocKout
    2015-12-10

    Avast! – Integer Overflow Verifying numFonts in TTC Header

  • dos
  • windows
  • Google Security Research
    2015-12-10

    Avast! – Heap Overflow Unpacking MoleBox Archives

  • dos
  • multiple
  • Google Security Research
    2015-12-10

    Avast! – JetDb::Ised4x Performs Unbounded Search on Input

  • dos
  • multiple
  • Google Security Research
    2015-12-10

    Avast! – Out-of-Bounds Write Decrypting PEncrypt Packed executables

  • dos
  • multiple
  • Google Security Research
    2015-12-10

    Rar – CmdExtract::UnstoreFile Integer Truncation Memory Corruption

  • dos
  • multiple
  • Google Security Research
    2015-12-10

    Skybox Platform < 7.0.611 - Multiple Vulnerabilities

  • webapps
  • hardware
  • SEC Consult
    2015-12-09

    Microsoft Office / COM Object – ‘els.dll’ DLL Planting (MS15-134)

  • remote
  • windows
  • Google Security Research
    2015-12-09

    Apple Mac OSX 10.11 – FTS Deep Structure of the FileSystem Buffer Overflow

  • dos
  • osx
  • Maksymilian Arciemowicz
    2015-12-09

    Microsoft Internet Explorer 11.0.9600.18097 – COmWindowProxy::SwitchMarkup NULL PTR

  • dos
  • windows
  • Marcin Ressel
    2015-12-09

    WordPress Plugin WP Easy Poll 1.1.3 – Cross-Site Scripting / Cross-Site Request Forgery

  • webapps
  • php
  • Mysticism
    2015-12-09

    WIMAX MT711x – Multiple Vulnerabilities

  • webapps
  • hardware
  • alimp5
    2015-12-09

    WIMAX LX350P(WIXFMR-108) – Multiple Vulnerabilities

  • webapps
  • hardware
  • alimp5
    2015-12-09

    Microsoft Windows Media Center – ‘.Link’ File Incorrectly Resolved Reference (MS15-134)

  • remote
  • windows
  • Core Security
    2015-12-09

    Microsoft Windows Media Center Library – Parsing Remote Code Execution aka ‘self-executing’ MCL File

  • remote
  • windows
  • Eduardo Braun Prado
    2015-12-08

    dotCMS 3.2.4 – Multiple Vulnerabilities

  • webapps
  • php
  • LiquidWorm
    2015-12-08

    Atlassian HipChat for Jira Plugin – Velocity Template Injection (Metasploit)

  • remote
  • multiple
  • Metasploit
    2015-12-08

    iniNet SpiderControl PLC Editor Simatic 6.30.04 – Insecure File Permissions

  • local
  • windows
  • LiquidWorm
    2015-12-08

    iniNet SpiderControl SCADA Web Server Service 2.02 – Insecure File Permissions

  • local
  • windows
  • LiquidWorm
    2015-12-08

    WordPress Plugin Polls Widget 1.0.7 – SQL Injection

  • webapps
  • php
  • WICS
    2015-12-08

    PHP Utility Belt – Remote Code Execution

  • webapps
  • php
  • WICS
    2015-12-08

    phpFileManager 0.9.8 – Remote Code Execution (Metasploit)

  • remote
  • php
  • Metasploit
    2015-12-08

    OpenMRS 2.3 (1.11.4) – Local File Disclosure

  • webapps
  • xml
  • LiquidWorm
    2015-12-08

    OpenMRS 2.3 (1.11.4) – Multiple Cross-Site Scripting Vulnerabilities

  • webapps
  • xml
  • LiquidWorm
    2015-12-08

    Microsoft Office – OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)

  • local
  • windows
  • Metasploit
    2015-12-08

    OpenMRS 2.3 (1.11.4) – Expression Language Injection

  • webapps
  • xml
  • LiquidWorm
    2015-12-08

    OpenMRS 2.3 (1.11.4) – XML External Entity Processing

  • webapps
  • xml
  • LiquidWorm
    2015-12-08

    SIMOGEO FileManager 2.3.0 – Multiple Vulnerabilities

  • webapps
  • php
  • HaHwul
    2015-12-06

    Cyclope Employee Surveillance 8.6.1 – Insecure File Permissions

  • local
  • windows
  • loneferret
    2015-12-06

    WinAsm Studio 5.1.8.8 – Buffer Overflow Crash (PoC)

  • dos
  • windows
  • Un_N0n
    2015-12-04

    WordPress Plugin TheCartPress 1.4.7 – Multiple Vulnerabilities

  • webapps
  • php
  • KedAns-Dz
    2015-12-04

    WordPress Plugin Sell Download 1.0.16 – Local File Disclosure

  • webapps
  • php
  • KedAns-Dz
    2015-12-04

    WordPress Plugin Advanced uploader 2.10 – Multiple Vulnerabilities

  • webapps
  • php
  • KedAns-Dz
    2015-12-03

    Oracle BeeHive 2 – ‘voice-servlet processEvaluation()’ Write File (Metasploit)

  • remote
  • windows
  • Metasploit
    2015-12-03

    Malwarebytes AntiVirus 2.2.0 – Denial of Service (PoC)

  • dos
  • windows
  • Francis Provencher
    2015-12-03

    Gnome Nautilus 3.16 – Denial of Service

  • dos
  • linux
  • Panagiotis Vagenas
    2015-12-03

    WordPress Plugin Users Ultra 1.5.50 – Persistent Cross-Site Scripting

  • webapps
  • php
  • Panagiotis Vagenas
    2015-12-03

    WordPress Plugin Users Ultra 1.5.50 – Blind SQL Injection

  • webapps
  • php
  • Panagiotis Vagenas
    2015-12-03

    WordPress Plugin Gwolle Guestbook 1.5.3 – Remote File Inclusion

  • webapps
  • php
  • High-Tech Bridge SA
    2015-12-03

    Oracle BeeHive 2 – ‘voice-servlet prepareAudioToPlay()’ Arbitrary File Upload (Metasploit)

  • remote
  • windows
  • Metasploit
    2015-12-02

    Man-db 2.6.7.1 – Local Privilege Escalation

  • local
  • linux
  • halfdog
    2015-12-02

    Advantech Switch – ‘Shellshock’ Bash Environment Variable Command Injection (Metasploit)

  • remote
  • cgi
  • Metasploit