Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24745Exploits
日期 标题 类型 平台 作者
2014-11-10

WordPress Plugin Another WordPress Classifieds Plugin – SQL Injection

  • webapps
  • php
  • dill
    2014-11-10

    ZTE ZXDSL 831CII – Insecure Direct Object Reference

  • webapps
  • hardware
  • Paulos Yibelo
    2014-11-10

    Microsoft Internet Explorer 11 – Denial of Service

  • dos
  • windows
  • Behrooz Abbassi
    2014-11-09

    ManageEngine OpManager / Social IT Plus / IT360 – Multiple Vulnerabilities

  • webapps
  • multiple
  • Pedro Ribeiro
    2014-11-06

    Symantec Endpoint Protection 12.1.4023.4080 – Multiple Vulnerabilities

  • webapps
  • jsp
  • SEC Consult
    2014-11-06

    Citrix Netscaler SOAP Handler – Remote Code Execution (Metasploit)

  • remote
  • bsd
  • Metasploit
    2014-11-06

    i.Mage 1.11 – Local Crash (PoC)

  • dos
  • windows
  • metacom
    2014-11-06

    i.Hex 0.98 – Local Crash (PoC)

  • dos
  • windows
  • metacom
    2014-11-06

    i-FTP 2.20 – Local Buffer Overflow (SEH)

  • local
  • windows
  • metacom
    2014-11-06

    Minix 3.3.0 – Local Denial of Service (PoC)

  • dos
  • linux
  • nitr0us
    2014-11-06

    Belkin N750 – ‘jump?login’ Remote Buffer Overflow

  • remote
  • hardware
  • Marco Vaz
    2014-11-06

    X7 Chat 2.0.5 – ‘message.php’ PHP Code Execution (Metasploit)

  • remote
  • php
  • Metasploit
    2014-11-06

    VMware Workstation 10.0.0.40273 – ‘vmx86.sys’ Arbitrary Kernel Read

  • dos
  • windows_x86
  • KoreLogic
    2014-11-05

    ManageEngine EventLog Analyzer – Multiple Vulnerabilities (2)

  • webapps
  • multiple
  • Pedro Ribeiro
    2014-11-05

    Mouse Media Script 1.6 – Persistent Cross-Site Scripting

  • webapps
  • php
  • Halil Dalabasmaz
    2014-11-05

    MODx CMS 2.2.14 – Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting

  • webapps
  • php
  • Narendra Bhati
    2014-11-03

    Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)

  • webapps
  • php
  • Stefan Horst
    2014-11-03

    Apple Mac OSX (Mavericks) – ‘IOBluetoothHCIUserClient’ Privilege Escalation

  • dos
  • osx
  • rpaleari & joystick
    2014-11-03

    Xerox Multifunction Printers (MFP) – ‘Patch’ DLM (Metasploit)

  • remote
  • hardware
  • Metasploit
    2014-11-03

    Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)

  • webapps
  • php
  • Stefan Horst
    2014-11-03

    PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection

  • webapps
  • php
  • Ryan King (Starfall)
    2014-11-02

    Esotalk CMS 1.0.0g4 – Cross-Site Scripting

  • webapps
  • php
  • evi1m0
    2014-10-31

    Who’s Who Script – Cross-Site Request Forgery (Add Admin)

  • webapps
  • php
  • ZoRLu Bugrahan
    2014-10-31

    ZTE Modem ZXDSL 531BIIV7.3.0f_D09_IN – Persistent Cross-Site Scripting

  • webapps
  • hardware
  • Ravi Rajput
    2014-10-31

    Progress OpenEdge 11.2 – Directory Traversal

  • webapps
  • jsp
  • XLabs Security
    2014-10-29

    Konke Smart Plug K – Authentication Bypass

  • remote
  • hardware
  • gamehacker
    2014-10-29

    CUPS Filter – Bash Environment Variable Code Injection (Metasploit)

  • remote
  • linux
  • Metasploit
    2014-10-29

    MAARCH 1.4 – SQL Injection

  • webapps
  • php
  • Adrien Thierry
    2014-10-29

    MAARCH 1.4 – Arbitrary File Upload

  • webapps
  • php
  • Adrien Thierry
    2014-10-29

    IBM Tivoli Monitoring 6.2.2 kbbacf1 – Local Privilege Escalation

  • local
  • linux
  • Robert Jaroszuk
    2014-10-29

    Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 – ‘.wax’ File Buffer Overflow (Denial of Service) (PoC) EIP Overwrite

  • dos
  • windows
  • ZoRLu Bugrahan
    2014-10-28

    Tapatalk for vBulletin 4.x – Blind SQL Injection

  • webapps
  • php
  • tintinweb
    2014-10-28

    Microsoft Windows – TrackPopupMenu Win32k Null Pointer Dereference (MS14-058) (Metasploit)

  • local
  • windows
  • Metasploit
    2014-10-28

    Enalean Tuleap 7.4.99.5 – Remote Command Execution

  • webapps
  • php
  • Portcullis
    2014-10-28

    Enalean Tuleap 7.2 – XML External Entity File Disclosure

  • webapps
  • php
  • Portcullis
    2014-10-28

    Enalean Tuleap 7.4.99.5 – Blind SQL Injection

  • webapps
  • php
  • Portcullis
    2014-10-27

    Centreon – SQL Injection / Command Injection (Metasploit)

  • remote
  • unix
  • Metasploit
    2014-10-27

    Filemaker Pro 13.03 / Advanced 12.04 – Authentication Bypass / Privilege Escalation

  • local
  • windows
  • Giuseppe D'Amore
    2014-10-27

    HP Operations Agent – Cross-Site Scripting iFrame Injection

  • webapps
  • multiple
  • Matt Schmidt
    2014-10-27

    CBN CH6640E/CG6640E Wireless Gateway Series – Multiple Vulnerabilities

  • webapps
  • hardware
  • LiquidWorm
    2014-10-27

    Free WMA MP3 Converter 1.8 – ‘.wav’ Local Buffer Overflow

  • local
  • windows
  • metacom
    2014-10-27

    WordPress Plugin CP Multi View Event Calendar 1.01 – SQL Injection

  • webapps
  • php
  • Claudio Viviani
    2014-10-27

    Folder Plus 2.5.1 iOS – Persistent Cross-Site Scripting

  • webapps
  • ios
  • Vulnerability-Lab
    2014-10-27

    WebDisk+ 2.1 iOS – Code Execution

  • webapps
  • ios
  • Vulnerability-Lab
    2014-10-27

    Binary File Descriptor Library (libbfd) – Out-of-Bounds Crash

  • dos
  • linux
  • Michal Zalewski
    2014-10-27

    Incredible PBX 2.0.6.5.0 – Remote Command Execution

  • webapps
  • php
  • Simo Ben Youssef
    2014-10-27

    Mulesoft ESB Runtime 3.5.1 – Privilege Escalation

  • webapps
  • jsp
  • Brandon Perry
    2014-10-25

    OpenBSD 5.5 – Local Kernel Panic (Denial of Service)

  • dos
  • bsd
  • nitr0us
    2014-10-25

    WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form – Arbitrary File Upload

  • webapps
  • php
  • Claudio Viviani
    2014-10-25

    Dell EqualLogic Storage – Directory Traversal

  • webapps
  • hardware
  • XLabs Security