Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2021-03-04

Web Based Quiz System 1.0 – ‘eid’ Union Based Sql Injection (Authenticated)

  • webapps
  • php
  • Deepak Kumar Bharti
    2021-03-04

    Online Ordering System 1.0 – Blind SQL Injection (Unauthenticated)

  • webapps
  • php
  • Suraj Bhosale
    2021-03-04

    Textpattern CMS 4.9.0-dev – ‘Excerpt’ Persistent Cross-Site Scripting (XSS)

  • webapps
  • php
  • Tushar Vaidya
    2021-03-04

    Textpattern CMS 4.8.4 – ‘Comments’ Persistent Cross-Site Scripting (XSS)

  • webapps
  • php
  • Tushar Vaidya
    2021-03-04

    Online Ordering System 1.0 – Arbitrary File Upload

  • webapps
  • php
  • Suraj Bhosale
    2021-03-03

    AnyDesk 5.5.2 – Remote Code Execution

  • remote
  • linux
  • scryh
    2021-03-03

    Local Services Search Engine Management System (LSSMES) 1.0 – Blind & Error based SQL injection (Authenticated)

  • webapps
  • php
  • Tushar Vaidya
    2021-03-03

    Local Services Search Engine Management System (LSSMES) 1.0 – ‘name’ Persistent Cross-Site Scripting (XSS)

  • webapps
  • php
  • Tushar Vaidya
    2021-03-02

    Zen Cart 1.5.7b – Remote Code Execution (Authenticated)

  • webapps
  • php
  • Mücahit Saratar
    2021-03-02

    Web Based Quiz System 1.0 – ‘name’ Persistent Cross-Site Scripting

  • webapps
  • php
  • P.Naveen Kumar
    2021-03-02

    Tiny Tiny RSS – Remote Code Execution

  • webapps
  • php
  • Daniel Neagaru
    2021-03-02

    Web Based Quiz System 1.0 – ‘MCQ options’ Persistent Cross-Site Scripting

  • webapps
  • php
  • Praharsh Kumar Singh
    2021-03-01

    Covid-19 Contact Tracing System 1.0 – Remote Code Execution (Unauthenticated)

  • webapps
  • php
  • Christian Vierschilling
    2021-03-01

    Online Catering Reservation System 1.0 – Remote Code Execution (Unauthenticated)

  • webapps
  • php
  • Christian Vierschilling
    2021-03-01

    VMware vCenter Server 7.0 – Unauthenticated File Upload

  • webapps
  • multiple
  • Photubias
    2021-03-01

    WiFi Mouse 1.7.8.5 – Remote Code Execution

  • remote
  • windows
  • H4rk3nz0
    2021-03-01

    FortiLogger 4.4.2.2 – Unauthenticated Arbitrary File Upload (Metasploit)

  • webapps
  • multiple
  • Berkan Er
    2021-02-26

    Simple Employee Records System 1.0 – File Upload RCE (Unauthenticated)

  • webapps
  • php
  • sml
    2021-02-26

    Remote Desktop Web Access – Authentication Timing Attack (Metasploit Module)

  • remote
  • windows
  • Matthew Dunn
    2021-02-26

    LightCMS 1.3.4 – ‘exclusive’ Stored XSS

  • webapps
  • multiple
  • Peithon
    2021-02-26

    Triconsole 3.75 – Reflected XSS

  • webapps
  • php
  • Akash Chathoth
    2021-02-25

    Vehicle Parking Management System 1.0 – ‘catename’ Persistent Cross-Site Scripting (XSS)

  • webapps
  • php
  • Tushar Vaidya
    2021-02-25

    ASUS Remote Link 1.1.2.13 – Remote Code Execution

  • remote
  • windows
  • H4rk3nz0
    2021-02-24

    LayerBB 1.1.4 – ‘search_query’ SQL Injection

  • webapps
  • php
  • Görkem Haşin
    2021-02-24

    Product Key Explorer 4.2.7 – ‘multiple’ Denial of Service (PoC)

  • dos
  • windows
  • Sinem Şahin
    2021-02-24

    SpotAuditor 5.3.5 – ‘multiple’ Denial Of Service (PoC)

  • dos
  • windows
  • Sinem Şahin
    2021-02-24

    Softros LAN Messenger 9.6.4 – ‘SoftrosSpellChecker’ Unquoted Service Path

  • local
  • windows
  • Victor Mondragón
    2021-02-24

    Unified Remote 3.9.0.2463 – Remote Code Execution

  • remote
  • windows
  • H4rk3nz0
    2021-02-24

    LogonExpert 8.1 – ‘LogonExpertSvc’ Unquoted Service Path

  • local
  • windows
  • Victor Mondragón
    2021-02-24

    python jsonpickle 2.0.0 – Remote Code Execution

  • remote
  • multiple
  • Adi Malyanker
    2021-02-23

    HFS (HTTP File Server) 2.3.x – Remote Command Execution (3)

  • remote
  • windows
  • Pergyz
    2021-02-23

    Batflat CMS 1.3.6 – ‘multiple’ Stored XSS

  • webapps
  • php
  • Tadjmen
    2021-02-23

    Monica 2.19.1 – ‘last_name’ Stored XSS

  • webapps
  • multiple
  • BouSalman
    2021-02-19

    Online Exam System With Timer 1.0 – ’email’ SQL injection Auth Bypass

  • webapps
  • php
  • Suresh Kumar
    2021-02-19

    Comment System 1.0 – ‘multiple’ Stored Cross-Site Scripting

  • webapps
  • php
  • Pintu Solanki
    2021-02-19

    PEEL Shopping 9.3.0 – ‘Comments’ Persistent Cross-Site Scripting

  • webapps
  • php
  • Anmol K Sachan
    2021-02-19

    Beauty Parlour Management System 1.0 – ‘sername’ SQL Injection

  • webapps
  • php
  • Thinkland Security Team
    2021-02-19

    OpenText Content Server 20.3 – ‘multiple’ Stored Cross-Site Scripting

  • webapps
  • multiple
  • Kamil Breński
    2021-02-19

    dataSIMS Avionics ARINC 664-1 – Local Buffer Overflow (PoC)

  • local
  • windows
  • Kağan Çapar
    2021-02-18

    Batflat CMS 1.3.6 – Remote Code Execution (Authenticated)

  • webapps
  • php
  • mari0x00
    2021-02-18

    Apport 2.20 – Local Privilege Escalation

  • local
  • linux
  • Gr33nh4t
    2021-02-18

    Gitea 1.12.5 – Remote Code Execution (Authenticated)

  • webapps
  • multiple
  • Podalirius
    2021-02-17

    Billing Management System 2.0 – ’email’ SQL injection Auth Bypass

  • webapps
  • php
  • Pintu Solanki
    2021-02-17

    Faulty Evaluation System 1.0 – ‘multiple’ Stored Cross-Site Scripting

  • webapps
  • php
  • Suresh Kumar
    2021-02-16

    Nsauditor 3.2.2.0 – ‘Event Description’ Denial of Service (PoC)

  • dos
  • windows
  • Ismael Nava
    2021-02-16

    AgataSoft PingMaster Pro 2.1 – Denial of Service (PoC)

  • dos
  • windows
  • Ismael Nava
    2021-02-16

    Managed Switch Port Mapping Tool 2.85.2 – Denial of Service (PoC)

  • dos
  • windows
  • Ismael Nava
    2021-02-16

    BlackCat CMS 1.3.6 – ‘Display name’ Cross Site Scripting (XSS)

  • webapps
  • php
  • Kamaljeet Kumar
    2021-02-16

    Online Internship Management System 1.0 – ’email’ SQL injection Auth Bypass

  • webapps
  • php
  • Christian Vierschilling
    2021-02-15

    Tasks 9.7.3 – Insecure Permissions

  • local
  • android
  • Lyhin\'s Lab