Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24745Exploits
日期 标题 类型 平台 作者
2021-10-08

Loan Management System 1.0 – SQLi Authentication Bypass

  • webapps
  • php
  • Merve Oral
    2021-10-08

    Cmder Console Emulator 1.3.18 – ‘Cmder.exe’ Denial of Service (PoC)

  • local
  • windows
  • Aryan Chehreghani
    2021-10-08

    Online Employees Work From Home Attendance System 1.0 – SQLi Authentication Bypass

  • webapps
  • php
  • Merve Oral
    2021-10-08

    Online Enrollment Management System 1.0 – Authentication Bypass

  • webapps
  • php
  • Amine ismail
    2021-10-08

    Simple Online College Entrance Exam System 1.0 – ‘Multiple’ SQL injection

  • webapps
  • php
  • Amine ismail
    2021-10-08

    Simple Online College Entrance Exam System 1.0 – Account Takeover

  • webapps
  • php
  • Amine ismail
    2021-10-08

    Simple Online College Entrance Exam System 1.0 – Unauthenticated Admin Creation

  • webapps
  • php
  • Amine ismail
    2021-10-08

    WordPress Plugin Pie Register 3.7.1.4 – Admin Privilege Escalation (Unauthenticated)

  • webapps
  • php
  • Lotfi13-DZ
    2021-10-07

    Simple Online College Entrance Exam System 1.0 – SQLi Authentication Bypass

  • webapps
  • php
  • Mevlüt Yılmaz
    2021-10-07

    Online Traffic Offense Management System 1.0 – Multiple RCE (Unauthenticated)

  • webapps
  • php
  • snup
    2021-10-07

    Online Traffic Offense Management System 1.0 – Multiple XSS (Unauthenticated)

  • webapps
  • php
  • snup
    2021-10-07

    Online Traffic Offense Management System 1.0 – Multiple SQL Injection (Unauthenticated)

  • webapps
  • php
  • snup
    2021-10-07

    Online DJ Booking Management System 1.0 – ‘Multiple’ Blind Cross-Site Scripting

  • webapps
  • php
  • Yash Mahajan
    2021-10-07

    Google SLO-Generator 2.0.0 – Code Execution

  • local
  • linux
  • Kiran Ghimire
    2021-10-06

    Odine Solutions GateKeeper 1.0 – ‘trafficCycle’ SQL Injection

  • webapps
  • multiple
  • Emel Basayar
    2021-10-06

    Atlassian Jira Server Data Center 8.16.0 – Arbitrary File Read

  • webapps
  • multiple
  • Mayank Deshmukh
    2021-10-06

    Apache HTTP Server 2.4.49 – Path Traversal & Remote Code Execution (RCE)

  • webapps
  • multiple
  • Lucas Souza
    2021-10-06

    WordPress Plugin BulletProof Security 5.1 – Sensitive Information Disclosure

  • webapps
  • php
  • Ron Jost
    2021-10-05

    WordPress Plugin MStore API 2.0.6 – Arbitrary File Upload

  • webapps
  • php
  • spacehen
    2021-10-05

    WordPress Plugin TheCartPress 1.5.3.6 – Privilege Escalation (Unauthenticated)

  • webapps
  • php
  • spacehen
    2021-10-05

    Atlassian Confluence 7.12.2 – Pre-Authorization Arbitrary File Read

  • webapps
  • java
  • Mayank Deshmukh
    2021-10-05

    Student Quarterly Grading System 1.0 – SQLi Authentication Bypass

  • webapps
  • php
  • Blackhan
    2021-10-04

    Young Entrepreneur E-Negosyo System 1.0 – ‘PRODESC’ Stored Cross-Site Scripting (XSS)

  • webapps
  • php
  • Jordan Glover
    2021-10-04

    Young Entrepreneur E-Negosyo System 1.0 – SQL Injection Authentication Bypass

  • webapps
  • php
  • Jordan Glover
    2021-10-04

    Open Game Panel – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • multiple
  • prey
    2021-10-04

    Lodging Reservation Management System 1.0 – Authentication Bypass

  • webapps
  • php
  • Nitin Sharma
    2021-10-04

    Payara Micro Community 5.2021.6 – Directory Traversal

  • webapps
  • multiple
  • Yasser Khan
    2021-10-01

    Vehicle Service Management System 1.0 – Remote Code Execution (RCE) (Unauthenticated)

  • webapps
  • php
  • Ghuliev
    2021-10-01

    Phpwcms 1.9.30 – Arbitrary File Upload

  • webapps
  • php
  • Okan Kurtulus
    2021-10-01

    Blood Bank System 1.0 – Authentication Bypass

  • webapps
  • php
  • Nitin Sharma
    2021-10-01

    Drupal Module MiniorangeSAML 8.x-2.22 – Privilege escalation

  • webapps
  • php
  • Cristian \'void\' Giustini
    2021-10-01

    Exam Form Submission System 1.0 – SQL Injection Authentication Bypass

  • webapps
  • php
  • Nitin Sharma
    2021-10-01

    Directory Management System 1.0 – SQL Injection Authentication Bypass

  • webapps
  • php
  • Sanjay Singh
    2021-10-01

    CMSimple_XH 1.7.4 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • Halit AKAYDIN
    2021-10-01

    WhatsUpGold 21.0.3 – Stored Cross-Site Scripting (XSS)

  • webapps
  • multiple
  • Andreas Finstad
    2021-10-01

    Dairy Farm Shop Management System 1.0 – SQL Injection Authentication Bypass

  • webapps
  • php
  • Sanjay Singh
    2021-09-30

    Pharmacy Point of Sale System 1.0 – ‘Multiple’ SQL Injection (SQLi)

  • webapps
  • php
  • Murat
    2021-09-30

    Cmsimple 5.4 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • pussycat0x
    2021-09-30

    Cyber Cafe Management System Project (CCMS) 1.0 – SQL Injection Authentication Bypass

  • webapps
  • php
  • Sanjay Singh
    2021-09-29

    Pet Shop Management System 1.0 – Remote Code Execution (RCE) (Unauthenticated)

  • webapps
  • php
  • Mr.Gedik
    2021-09-29

    OpenSIS 8.0 – ‘cp_id_miss_attn’ Reflected Cross-Site Scripting (XSS)

  • webapps
  • php
  • Eric Salario
    2021-09-29

    Mitrastar GPT-2541GNAC-N1 – Privilege escalation

  • remote
  • hardware
  • Leonardo Nicolas Servalli
    2021-09-29

    WordPress Plugin Redirect 404 to Parent 1.3.0 – Reflected Cross-Site Scripting

  • webapps
  • php
  • 0xB9
    2021-09-29

    WordPress Plugin Select All Categories and Taxonomies 1.3.1 – Reflected Cross-Site Scripting (XSS)

  • webapps
  • php
  • 0xB9
    2021-09-29

    Storage Unit Rental Management System 1.0 – Remote Code Execution (RCE) (Unauthenticated)

  • webapps
  • php
  • Ghuliev
    2021-09-28

    FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 – Config Download (Unauthenticated)

  • webapps
  • hardware
  • LiquidWorm
    2021-09-28

    FatPipe Networks WARP 10.2.2 – Authorization Bypass

  • webapps
  • hardware
  • LiquidWorm
    2021-09-28

    FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 – ‘Add Admin’ Cross-Site Request Forgery (CSRF)

  • webapps
  • hardware
  • LiquidWorm
    2021-09-28

    Apache James Server 2.3.2 – Remote Command Execution (RCE) (Authenticated) (2)

  • remote
  • linux
  • shinris3n
    2021-09-28

    WordPress Plugin Popup 1.10.4 – Reflected Cross-Site Scripting (XSS)

  • webapps
  • php
  • 0xB9