Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2022-03-22

Ivanti Endpoint Manager 4.6 – Remote Code Execution (RCE)

  • remote
  • multiple
  • d7x
    2022-03-22

    iRZ Mobile Router – CSRF to RCE

  • remote
  • hardware
  • John Jackson
    2022-03-22

    ICEHRM 31.0.0.0S – Cross-site Request Forgery (CSRF) to Account Takeover

  • webapps
  • php
  • Devansh Bordia
    2022-03-21

    WordPress Plugin iQ Block Country 1.2.13 – Arbitrary File Deletion via Zip Slip (Authenticated)

  • webapps
  • php
  • Ceylan BOZOĞULLARINDAN
    2022-03-16

    Apache APISIX 2.12.1 – Remote Code Execution (RCE)

  • remote
  • multiple
  • Ven3xy
    2022-03-16

    Tiny File Manager 2.4.6 – Remote Code Execution (RCE)

  • webapps
  • php
  • FEBIN MON SAJI
    2022-03-16

    Pluck CMS 4.7.16 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • Ashish Koli
    2022-03-16

    Moodle 3.11.5 – SQLi (Authenticated)

  • webapps
  • php
  • Chris Anastasio
    2022-03-14

    VIVE Runtime Service – ‘ViveAgentService’ Unquoted Service Path

  • local
  • windows
  • Faisal Alasmari
    2022-03-14

    Baixar GLPI Project 9.4.6 – SQLi

  • webapps
  • multiple
  • Prof. Joas Antonio
    2022-03-11

    Tdarr 2.00.15 – Command Injection

  • remote
  • multiple
  • Sam Smith
    2022-03-11

    Seowon SLR-120 Router – Remote Code Execution (Unauthenticated)

  • remote
  • hardware
  • Aryan Chehreghani
    2022-03-10

    Sandboxie-Plus 5.50.2 – ‘Service SbieSvc’ Unquoted Service Path

  • local
  • windows
  • Antonio Cuomo
    2022-03-10

    WOW21 5.0.1.9 – ‘Service WOW21_Service’ Unquoted Service Path

  • local
  • windows
  • Antonio Cuomo
    2022-03-10

    Sony playmemories home – ‘PMBDeviceInfoProvider’ Unquoted Service Path

  • local
  • windows
  • Saud Alenazi
    2022-03-10

    Zabbix 5.0.17 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • Hussien Misbah
    2022-03-10

    BattlEye 0.9 – ‘BEService’ Unquoted Service Path

  • local
  • windows
  • Saud Alenazi
    2022-03-10

    McAfee(R) Safe Connect VPN – Unquoted Service Path Elevation Of Privilege

  • local
  • windows
  • Saud Alenazi
    2022-03-09

    Audio Conversion Wizard v2.01 – Buffer Overflow

  • local
  • windows
  • Hejap Zairy Al-Sharif
    2022-03-09

    Cobian Backup 0.9 – Unquoted Service Path

  • local
  • windows
  • Hejap Zairy Al-Sharif
    2022-03-09

    Webmin 1.984 – Remote Code Execution (Authenticated)

  • webapps
  • linux
  • faisalfs10x
    2022-03-09

    Wondershare Dr.Fone 12.0.18 – ‘Wondershare InstallAssist’ Unquoted Service Path

  • local
  • windows
  • Mohamed Alzhrani
    2022-03-09

    Printix Client 1.3.1106.0 – Privilege Escalation

  • local
  • windows
  • Logan Latvala
    2022-03-08

    Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)

  • local
  • linux
  • Lance Biggerstaff
    2022-03-07

    Foxit PDF Reader 11.0 – Unquoted Service Path

  • local
  • windows
  • Hejap Zairy Al-Sharif
    2022-03-07

    Malwarebytes 4.5 – Unquoted Service Path

  • local
  • windows
  • Hejap Zairy Al-Sharif
    2022-03-07

    Cloudflare WARP 1.4 – Unquoted Service Path

  • local
  • windows
  • Hejap Zairy Al-Sharif
    2022-03-07

    Private Internet Access 3.3 – ‘pia-service’ Unquoted Service Path

  • local
  • windows
  • Saud Alenazi
    2022-03-07

    Hasura GraphQL 2.2.0 – Information Disclosure

  • webapps
  • multiple
  • Dolev Farhi
    2022-03-07

    Attendance and Payroll System v1.0 – SQLi Authentication Bypass

  • webapps
  • php
  • pr0z
    2022-03-07

    Attendance and Payroll System v1.0 – Remote Code Execution (RCE)

  • webapps
  • php
  • pr0z
    2022-03-07

    part-db 0.5.11 – Remote Code Execution (RCE)

  • webapps
  • php
  • Chetanya Sharma
    2022-03-07

    Spring Cloud Gateway 3.1.0 – Remote Code Execution (RCE)

  • webapps
  • java
  • Carlos E. Vieira
    2022-03-02

    Xerte 3.9 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • Rik Lutz
    2022-03-02

    Xerte 3.10.3 – Directory Traversal (Authenticated)

  • webapps
  • php
  • Rik Lutz
    2022-03-02

    Printix Client 1.3.1106.0 – Remote Code Execution (RCE)

  • remote
  • windows
  • Logan Latvala
    2022-03-02

    Zyxel ZyWALL 2 Plus Internet Security Appliance – Cross-Site Scripting (XSS)

  • webapps
  • multiple
  • Momen Eldawakhly
    2022-03-02

    Prowise Reflect v1.0.9 – Remote Keystroke Injection

  • remote
  • windows
  • Rik Lutz
    2022-02-28

    WAGO 750-8212 PFC200 G2 2ETH RS – Privilege Escalation

  • remote
  • hardware
  • Momen Eldawakhly
    2022-02-28

    Casdoor 1.13.0 – SQL Injection (Unauthenticated)

  • webapps
  • multiple
  • Mayank Deshmukh
    2022-02-28

    Cobian Backup Gravity 11.2.0.582 – ‘CobianBackup11’ Unquoted Service Path

  • local
  • windows
  • Luis Martínez
    2022-02-28

    Cobian Backup 11 Gravity 11.2.0.582 – ‘Password’ Denial of Service (PoC)

  • local
  • windows
  • Luis Martínez
    2022-02-28

    Cobian Reflector 0.9.93 RC1 – ‘Password’ Denial of Service (PoC)

  • local
  • windows
  • Luis Martínez
    2022-02-28

    Cipi Control Panel 3.1.15 – Stored Cross-Site Scripting (XSS) (Authenticated)

  • webapps
  • linux
  • Ghuliev
    2022-02-24

    Wondershare MirrorGo 2.0.11.346 – Insecure File Permissions

  • local
  • windows
  • Luis Martínez
    2022-02-23

    Air Cargo Management System v1.0 – SQLi

  • webapps
  • php
  • nu11secur1ty
    2022-02-23

    Simple Real Estate Portal System 1.0 – ‘id’ SQLi

  • webapps
  • php
  • Mosaaed
    2022-02-23

    Microweber CMS 1.2.10 – Local File Inclusion (Authenticated) (Metasploit)

  • webapps
  • php
  • Talha Karakumru
    2022-02-23

    WebHMI 4.1 – Stored Cross Site Scripting (XSS) (Authenticated)

  • webapps
  • php
  • Antonio Cuomo
    2022-02-23

    WebHMI 4.1.1 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • Antonio Cuomo