Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2021-02-15

Teachers Record Management System 1.0 – ‘searchteacher’ SQL Injection

  • webapps
  • php
  • Soham Bakore
    2021-02-15

    TestLink 1.9.20 – Unrestricted File Upload (Authenticated)

  • webapps
  • php
  • snovvcrash
    2021-02-12

    School File Management System 1.0 – ‘multiple’ Stored Cross-Site Scripting

  • webapps
  • php
  • Pintu Solanki
    2021-02-12

    PDFCOMPLETE Corporate Edition 4.1.45 – ‘pdfcDispatcher’ Unquoted Service Path

  • local
  • windows
  • Ismael Nava
    2021-02-12

    School Event Attendance Monitoring System 1.0 – ‘Item Name’ Stored Cross-Site Scripting

  • webapps
  • php
  • Suresh Kumar
    2021-02-11

    Online Marriage Registration System (OMRS) 1.0 – Remote code execution (3)

  • webapps
  • php
  • Ricardo Ruiz
    2021-02-11

    Openlitespeed WebServer 1.7.8 – Command Injection (Authenticated) (2)

  • webapps
  • multiple
  • Metin Yunus Kandemir
    2021-02-11

    b2evolution 6.11.6 – ‘tab3’ Reflected XSS

  • webapps
  • php
  • Nakul Ratti
    2021-02-11

    b2evolution 6.11.6 – ‘redirect_to’ Open Redirect

  • webapps
  • php
  • Nakul Ratti
    2021-02-11

    PEEL Shopping 9.3.0 – ‘address’ Stored Cross-Site Scripting

  • webapps
  • php
  • Anmol K Sachan
    2021-02-10

    Node.JS – ‘node-serialize’ Remote Code Execution (2)

  • webapps
  • nodejs
  • UndeadLarva
    2021-02-10

    b2evolution 6.11.6 – ‘plugin name’ Stored XSS

  • webapps
  • php
  • Soham Bakore
    2021-02-09

    Adobe Connect 10 – Username Disclosure

  • webapps
  • multiple
  • h4shur
    2021-02-09

    AnyTXT Searcher 1.2.394 – ‘ATService’ Unquoted Service Path

  • local
  • windows
  • Mohammed Alshehri
    2021-02-09

    Epson USB Display 1.6.0.0 – ‘EMP_UDSA’ Unquoted Service Path

  • local
  • windows
  • Hector Gerbacio
    2021-02-09

    Online Car Rental System 1.0 – Stored Cross Site Scripting

  • webapps
  • php
  • Naved Shaikh
    2021-02-08

    WordPress Plugin Supsystic Digital Publications 1.6.9 – Multiple Vulnerabilities

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    Microsoft Internet Explorer 11 32-bit – Use-After-Free

  • local
  • windows
  • Forrest Orr
    2021-02-08

    WordPress Plugin Supsystic Membership 1.4.7 – ‘sidx’ SQL injection

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    WordPress Plugin Supsystic Newsletter 1.5.5 – ‘sidx’ SQL injection

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    Alt-N MDaemon webmail 20.0.0 – ‘file name’ Stored Cross Site Scripting (XSS)

  • webapps
  • windows
  • Kailash Bohara
    2021-02-08

    Alt-N MDaemon webmail 20.0.0 – ‘Contact name’ Stored Cross Site Scripting (XSS)

  • webapps
  • windows
  • Kailash Bohara
    2021-02-08

    AMD Fuel Service – ‘Fuel.service’ Unquote Service Path

  • local
  • windows
  • Hector Gerbacio
    2021-02-08

    YetiShare File Hosting Script 5.1.0 – ‘url’ Server-Side Request Forgery

  • webapps
  • php
  • numan türle
    2021-02-08

    WordPress Plugin Supsystic Pricing Table 1.8.7 – Multiple Vulnerabilities

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    WordPress Plugin Supsystic Ultimate Maps 1.1.12 – ‘sidx’ SQL injection

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    WordPress Plugin Welcart e-Commerce 2.0.0 – ‘search[order_column][0]’ SQL injection

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    Millewin 13.39.146.1 – Local Privilege Escalation

  • local
  • windows
  • Andrea Intilangelo
    2021-02-08

    Jenzabar 9.2.2 – ‘query’ Reflected XSS.

  • webapps
  • multiple
  • y0ung_dst
    2021-02-08

    WordPress Plugin Supsystic Backup 2.3.9 – Local File Inclusion

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    SmartFoxServer 2X 2.17.0 – God Mode Console WebSocket XSS

  • webapps
  • multiple
  • LiquidWorm
    2021-02-08

    WordPress Plugin Supsystic Contact Form 1.7.5 – Multiple Vulnerabilities

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    SmartFoxServer 2X 2.17.0 – Credentials Disclosure

  • local
  • multiple
  • LiquidWorm
    2021-02-08

    WordPress Plugin Supsystic Data Tables Generator 1.9.96 – Multiple Vulnerabilities

  • webapps
  • php
  • Erik David Martin
    2021-02-08

    SmartFoxServer 2X 2.17.0 – God Mode Console Remote Code Execution

  • local
  • multiple
  • LiquidWorm
    2021-02-05

    SEO Panel 4.6.0 – Remote Code Execution (2)

  • webapps
  • php
  • Kr0ff
    2021-02-05

    PhreeBooks 5.2.3 ERP – Remote Code Execution (2)

  • webapps
  • php
  • Kr0ff
    2021-02-05

    LiteSpeed Web Server Enterprise 5.4.11 – Command Injection (Authenticated)

  • webapps
  • php
  • SunCSR
    2021-02-03

    Sudo 1.9.5p1 – ‘Baron Samedit ‘ Heap-Based Buffer Overflow Privilege Escalation (2)

  • local
  • multiple
  • nu11secur1ty
    2021-02-03

    Sudo 1.9.5p1 – ‘Baron Samedit ‘ Heap-Based Buffer Overflow Privilege Escalation (1)

  • local
  • multiple
  • West Shepherd
    2021-02-03

    Car Rental Project 2.0 – Arbitrary File Upload to Remote Code Execution

  • webapps
  • php
  • Jannick Tiger
    2021-02-03

    Pixelimity 1.0 – ‘password’ Cross-Site Request Forgery

  • webapps
  • multiple
  • Noth
    2021-02-02

    Solaris 10 (SPARC) – ‘dtprintinfo’ Local Privilege Escalation (3)

  • local
  • solaris
  • Marco Ivaldi
    2021-02-02

    Solaris 10 (SPARC) – ‘dtprintinfo’ Local Privilege Escalation (2)

  • local
  • solaris
  • Marco Ivaldi
    2021-02-02

    Solaris 10 (SPARC) – ‘dtprintinfo’ Local Privilege Escalation (1)

  • local
  • solaris
  • Marco Ivaldi
    2021-02-02

    Solaris 10 (Intel) – ‘dtprintinfo’ Local Privilege Escalation (3)

  • local
  • solaris
  • Marco Ivaldi
    2021-02-02

    Solaris 10 (Intel) – ‘dtprintinfo’ Local Privilege Escalation (2)

  • local
  • solaris
  • Marco Ivaldi
    2021-02-02

    Student Record System 4.0 – ‘cid’ SQL Injection

  • webapps
  • php
  • Jannick Tiger
    2021-02-01

    Vehicle Parking Tracker System 1.0 – ‘Owner Name’ Stored Cross-Site Scripting

  • webapps
  • php
  • Anmol K Sachan
    2021-02-01

    H8 SSRMS – ‘id’ IDOR

  • webapps
  • aspx
  • Mohammed Farhan