Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2020-05-04

Outline Service 1.3.3 – ‘Outline Service ‘ Unquoted Service Path

  • local
  • windows
  • Minh Tuan
    2020-05-04

    osTicket 1.14.1 – Persistent Authenticated Cross-Site Scripting

  • webapps
  • php
  • Mehmet Kelepçe
    2020-05-04

    BoltWire 6.03 – Local File Inclusion

  • webapps
  • php
  • Andrey Stoykov
    2020-05-01

    Apache Shiro 1.2.4 – Cookie RememberME Deserial RCE (Metasploit)

  • remote
  • multiple
  • Metasploit
    2020-05-01

    Online Scheduling System 1.0 – Authentication Bypass

  • webapps
  • php
  • boku
    2020-05-01

    Apache OFBiz 17.12.03 – Cross-Site Request Forgery (Account Takeover)

  • webapps
  • java
  • Faiz Ahmed Zaidi
    2020-05-01

    HardDrive 2.1 for iOS – Arbitrary File Upload

  • webapps
  • ios
  • Vulnerability-Lab
    2020-05-01

    Super Backup 2.0.5 for iOS – Directory Traversal

  • webapps
  • ios
  • Vulnerability-Lab
    2020-05-01

    php-fusion 9.03.50 – Persistent Cross-Site Scripting

  • webapps
  • php
  • SunCSR
    2020-05-01

    Online Scheduling System 1.0 – Persistent Cross-Site Scripting

  • webapps
  • php
  • boku
    2020-05-01

    VirtualTablet Server 3.0.2 – Denial of Service (PoC)

  • dos
  • windows
  • Dolev Farhi
    2020-05-01

    ChemInv 1.0 – Authenticated Persistent Cross-Site Scripting

  • webapps
  • php
  • boku
    2020-04-29

    Druva inSync Windows Client 6.5.2 – Local Privilege Escalation

  • local
  • windows
  • Chris Lyne
    2020-04-29

    hits script 1.0 – ‘item_name’ SQL Injection

  • webapps
  • php
  • SajjadBnd
    2020-04-29

    EmEditor 19.8 – Insecure File Permissions

  • local
  • windows
  • SajjadBnd
    2020-04-29

    Internet Download Manager 6.37.11.1 – Stack Buffer Overflow (PoC)

  • local
  • windows
  • Vulnerability-Lab
    2020-04-29

    Andrea ST Filters Service 1.0.64.7 – ‘Andrea ST Filters Service ‘ Unquoted Service Path

  • local
  • windows
  • Roberto Piña
    2020-04-29

    Easy Transfer 1.7 for iOS – Directory Traversal

  • webapps
  • ios
  • Vulnerability-Lab
    2020-04-29

    School ERP Pro 1.0 – Arbitrary File Read

  • webapps
  • php
  • Besim
    2020-04-29

    Open-AudIT Professional 3.3.1 – Remote Code Execution

  • webapps
  • php
  • Askar
    2020-04-28

    School ERP Pro 1.0 – Remote Code Execution

  • webapps
  • php
  • Besim
    2020-04-28

    NVIDIA Update Service Daemon 1.0.21 – ‘nvUpdatusService’ Unquoted Service Path

  • local
  • windows
  • Roberto Piña
    2020-04-28

    School ERP Pro 1.0 – ‘es_messagesid’ SQL Injection

  • webapps
  • php
  • Besim
    2020-04-28

    CloudMe 1.11.2 – Buffer Overflow (PoC)

  • remote
  • windows
  • Andy Bowden
    2020-04-28

    Docker-Credential-Wincred.exe – Privilege Escalation (Metasploit)

  • local
  • windows
  • Metasploit
    2020-04-27

    Netis E1+ V1.2.32533 – Unauthenticated WiFi Password Leak

  • webapps
  • hardware
  • Besim
    2020-04-27

    Online shopping system advanced 1.0 – ‘p’ SQL Injection

  • webapps
  • php
  • Majid kalantari
    2020-04-27

    Netis E1+ 1.2.32533 – Backdoor Account (root)

  • webapps
  • hardware
  • Besim
    2020-04-27

    PHP-Fusion 9.03.50 – ‘Edit Profile’ Arbitrary File Upload

  • webapps
  • php
  • Besim
    2020-04-27

    Source Engine CS:GO BuildID: 4937372 – Arbitrary Code Execution

  • local
  • macos
  • 0xEmma
    2020-04-27

    Maian Support Helpdesk 4.3 – Cross-Site Request Forgery (Add Admin)

  • webapps
  • php
  • Besim
    2020-04-27

    Online Course Registration 2.0 – Authentication Bypass

  • webapps
  • php
  • Daniel Monzón
    2020-04-24

    Furukawa Electric ConsciusMAP 2.8.1 – Remote Code Execution

  • webapps
  • java
  • LiquidWorm
    2020-04-24

    Popcorn Time 6.2 – ‘Update service’ Unquoted Service Path

  • local
  • windows
  • Uriel Yochpaz
    2020-04-24

    Edimax EW-7438RPn 1.13 – Remote Code Execution

  • webapps
  • hardware
  • Besim
    2020-04-24

    EspoCRM 5.8.5 – Privilege Escalation

  • webapps
  • multiple
  • Besim
    2020-04-23

    Sky File 2.1.0 iOS – Directory Traversal

  • webapps
  • ios
  • Vulnerability-Lab
    2020-04-23

    Library CMS Powerful Book Management System 2.2.0 – Session Fixation

  • webapps
  • php
  • Ismail Tasdelen
    2020-04-23

    Zen Load Balancer 3.10.1 – Directory Traversal (Metasploit)

  • webapps
  • cgi
  • Dhiraj Mishra
    2020-04-23

    Complaint Management System 4.2 – Cross-Site Request Forgery (Delete User)

  • webapps
  • php
  • Besim
    2020-04-23

    Complaint Management System 4.2 – Authentication Bypass

  • webapps
  • php
  • Besim
    2020-04-23

    Complaint Management System 4.2 – Persistent Cross-Site Scripting

  • webapps
  • php
  • Besim
    2020-04-23

    User Management System 2.0 – Authentication Bypass

  • webapps
  • php
  • Besim
    2020-04-23

    User Management System 2.0 – Persistent Cross-Site Scripting

  • webapps
  • php
  • Besim
    2020-04-22

    Mahara 19.10.2 CMS – Persistent Cross-Site Scripting

  • webapps
  • linux
  • Vulnerability-Lab
    2020-04-22

    Edimax EW-7438RPn – Cross-Site Request Forgery (MAC Filtering)

  • webapps
  • hardware
  • Besim
    2020-04-22

    Edimax EW-7438RPn – Information Disclosure (WiFi Password)

  • webapps
  • hardware
  • Besim
    2020-04-22

    RM Downloader 3.1.3.2.2010.06.13 – ‘Load’ Buffer Overflow (SEH)

  • local
  • windows
  • Felipe Winsnes
    2020-04-21

    Neowise CarbonFTP 1.4 – Insecure Proprietary Password Encryption

  • remote
  • windows
  • hyp3rlinx
    2020-04-21

    P5 FNIP-8x16A FNIP-4xSH 1.0.20 – Cross-Site Request Forgery (Add Admin)

  • webapps
  • hardware
  • LiquidWorm