Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2020-07-07

Joomla! J2 JOBS 1.3.0 – ‘sortby’ Authenticated SQL Injection

  • webapps
  • php
  • Mehmet Kelepçe
    2020-07-07

    Online Shopping Portal 3.1 – ’email’ SQL Injection

  • webapps
  • php
  • gh1mau
    2020-07-06

    BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution

  • webapps
  • linux
  • Critical Start
    2020-07-06

    Nagios XI 5.6.12 – ‘export-rrd.php’ Remote Code Execution

  • webapps
  • php
  • Basim Alabdullah
    2020-07-06

    RSA IG&L Aveksa 7.1.1 – Remote Code Execution

  • webapps
  • multiple
  • Jakub Palaczynski
    2020-07-06

    Grafana 7.0.1 – Denial of Service (PoC)

  • dos
  • linux
  • mostwanted002
    2020-07-06

    Fire Web Server 0.1 – Remote Denial of Service (PoC)

  • dos
  • windows
  • Saeed reza Zamanian
    2020-07-06

    RiteCMS 2.2.1 – Authenticated Remote Code Execution

  • webapps
  • php
  • Enes Özeser
    2020-07-06

    File Management System 1.1 – Persistent Cross-Site Scripting

  • webapps
  • php
  • KeopssGroup0day,Inc
    2020-07-05

    BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution (PoC)

  • webapps
  • linux
  • Budi Khoirudin
    2020-07-02

    OCS Inventory NG 2.7 – Remote Code Execution

  • webapps
  • multiple
  • Askar
    2020-07-02

    ZenTao Pro 8.8.2 – Command Injection

  • webapps
  • php
  • Daniel Monzón
    2020-07-01

    Online Shopping Portal 3.1 – Authentication Bypass

  • webapps
  • php
  • Ümit Yalçın
    2020-07-01

    PHP-Fusion 9.03.60 – PHP Object Injection

  • webapps
  • php
  • coiffeur
    2020-07-01

    e-learning Php Script 0.1.0 – ‘search’ SQL Injection

  • webapps
  • php
  • KeopssGroup0day,Inc
    2020-07-01

    RM Downloader 2.50.60 2006.06.23 – ‘Load’ Local Buffer Overflow (EggHunter) (SEH) (PoC)

  • local
  • windows
  • Paras Bhatia
    2020-06-30

    Reside Property Management 3.0 – ‘profile’ SQL Injection

  • webapps
  • php
  • Behzad Khalifeh
    2020-06-30

    Victor CMS 1.0 – ‘user_firstname’ Persistent Cross-Site Scripting

  • webapps
  • php
  • Anushree Priyadarshini
    2020-06-26

    KiteService 1.2020.618.0 – Unquoted Service Path

  • local
  • windows
  • Marcos Antonio León
    2020-06-26

    Windscribe 1.83 – ‘WindscribeService’ Unquoted Service Path

  • local
  • windows
  • Ethan Seow
    2020-06-26

    OpenEMR 5.0.1 – ‘controller’ Remote Code Execution

  • webapps
  • php
  • Emre ÖVÜNÇ
    2020-06-25

    FHEM 6.0 – Local File Inclusion

  • webapps
  • php
  • Emre ÖVÜNÇ
    2020-06-25

    mySCADA myPRO 7 – Hardcoded Credentials

  • remote
  • hardware
  • Emre ÖVÜNÇ
    2020-06-24

    BSA Radar 1.6.7234.24750 – Persistent Cross-Site Scripting

  • webapps
  • multiple
  • William Summerhill
    2020-06-23

    Lansweeper 7.2 – Incorrect Access Control

  • local
  • windows
  • Amel BOUZIANE-LEBLOND
    2020-06-23

    Code Blocks 20.03 – Denial Of Service (PoC)

  • dos
  • windows
  • Paras Bhatia
    2020-06-23

    Online Student Enrollment System 1.0 – Cross-Site Request Forgery (Add Student)

  • webapps
  • php
  • BKpatron
    2020-06-23

    Responsive Online Blog 1.0 – ‘id’ SQL Injection

  • webapps
  • php
  • Eren Şimşek
    2020-06-22

    Online Student Enrollment System 1.0 – Unauthenticated Arbitrary File Upload

  • webapps
  • php
  • BKpatron
    2020-06-22

    Odoo 12.0 – Local File Inclusion

  • webapps
  • multiple
  • Emre ÖVÜNÇ
    2020-06-22

    Student Enrollment 1.0 – Unauthenticated Remote Code Execution

  • webapps
  • php
  • Enesdex
    2020-06-22

    FileRun 2019.05.21 – Reflected Cross-Site Scripting

  • webapps
  • multiple
  • Emre ÖVÜNÇ
    2020-06-22

    Eaton Intelligent Power Manager 1.6 – Directory Traversal

  • webapps
  • hardware
  • Emre ÖVÜNÇ
    2020-06-22

    Frigate 2.02 – Denial Of Service (PoC)

  • dos
  • windows
  • Paras Bhatia
    2020-06-22

    WebPort 1.19.1 – ‘setup’ Reflected Cross-Site Scripting

  • webapps
  • php
  • Emre ÖVÜNÇ
    2020-06-22

    WebPort 1.19.1 – Reflected Cross-Site Scripting

  • webapps
  • multiple
  • Emre ÖVÜNÇ
    2020-06-18

    Beauty Parlour Management System 1.0 – Authentication Bypass

  • webapps
  • php
  • Prof. Kailas PATIL
    2020-06-17

    OpenCTI 3.3.1 – Directory Traversal

  • webapps
  • multiple
  • Raif Berkay Dincel
    2020-06-17

    Code Blocks 17.12 – ‘File Name’ Local Buffer Overflow (Unicode) (SEH) (PoC)

  • local
  • windows
  • Paras Bhatia
    2020-06-17

    College-Management-System-Php 1.0 – Authentication Bypass

  • webapps
  • php
  • BLAY ABU SAFIAN
    2020-06-16

    Bandwidth Monitor 3.9 – ‘Svc10StrikeBandMontitor’ Unquoted Service Path

  • local
  • windows
  • boku
    2020-06-16

    Gila CMS 1.11.8 – ‘query’ SQL Injection

  • webapps
  • php
  • BillyV4
    2020-06-15

    Netgear R7000 Router – Remote Code Execution

  • webapps
  • hardware
  • grimm-co
    2020-06-15

    SOS JobScheduler 1.13.3 – Stored Password Decryption

  • remote
  • multiple
  • Sander Ubink
    2020-06-12

    Sysax MultiServer 6.90 – Reflected Cross Site Scripting

  • webapps
  • multiple
  • Luca Epifanio
    2020-06-12

    Avaya IP Office 11 – Password Disclosure

  • webapps
  • multiple
  • hyp3rlinx
    2020-06-12

    SmarterMail 16 – Arbitrary File Upload

  • webapps
  • multiple
  • vvhack.org
    2020-06-11

    Frigate Professional 3.36.0.9 – ‘Find Computer’ Local Buffer Overflow (SEH) (PoC)

  • local
  • windows
  • Paras Bhatia
    2020-06-10

    Virtual Airlines Manager 2.6.2 – ‘id’ SQL Injection

  • webapps
  • php
  • Mosaaed
    2020-06-10

    WinGate 9.4.1.5998 – Insecure Folder Permissions

  • local
  • windows
  • hyp3rlinx