Exploits
Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
- 类型
- 漏洞条目
- 总量
- 24,950
- 页码
- 7
CrushFTP 11.3.1 – Authentication Bypass
# Exploit Title: CrushFTP 11.3.1 - Authentication Bypass
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 – Privilege Escalation
# Exploit Title: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
RDPGuard 9.9.9 – Privilege Escalation
# Exploit Title: RDPGuard 9.9.9 - Privilege Escalation
Kentico Xperience 13.0.178 – Cross Site Scripting (XSS)
# Exploit Title: Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
TP-Link VN020 F3v(T) TT_V6.2.1021) – DHCP Stack Buffer Overflow
#define _WINSOCK_DEPRECATED_NO_WARNINGS
Apache ActiveMQ 6.1.6 – Denial of Service (DOS)
# Exploit Title: Apache ActiveMQ 6.1.6 - Denial of Service (DOS)
Microsoft Windows 11 Pro 23H2 – Ancillary Function Driver for WinSock Privilege Escalation
# Exploit Title: Microsoft Windows 11 Pro 23H2 - Ancillary Function Driver for WinSock Privilege Escalation
WordPress Depicter Plugin 3.6.1 – SQL Injection
# Exploit Title: WordPress Depicter Plugin 3.6.1 - SQL Injection
SureTriggers OttoKit Plugin 1.0.82 – Privilege Escalation
# Exploit Title: SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation
VirtualBox 7.0.16 – Privilege Escalation
# Exploit Title: VirtualBox 7.0.16 - Privilege Escalation
Casdoor 1.901.0 – Cross-Site Request Forgery (CSRF)
# Exploit Title: Casdoor 1.901.0 - Cross-Site Request Forgery (CSRF)
Grokability Snipe-IT 8.0.4 – Insecure Direct Object Reference (IDOR)
# Exploit Title: Grokability Snipe-IT 8.0.4 - Insecure Direct Object Reference (IDOR)
ERPNext 14.82.1 – Account Takeover via Cross-Site Request Forgery (CSRF)
# Exploit Title: ERPNext 14.82.1 - Account Takeover via Cross-Site Request Forgery (CSRF)
Microsoft Windows – XRM-MS File NTLM Information Disclosure Spoofing
# Exploit Author: John Page (aka hyp3rlinx)
Daikin Security Gateway 14 – Remote Password Reset
# Daikin Security Gateway 214 - Remote Password Reset
ZTE ZXV10 H201L – RCE via authentication bypass
# Exploit Title: ZTE ZXV10 H201L - RCE via authentication bypass
Microsoft – NTLM Hash Disclosure Spoofing (library-ms)
# Exploit title: Microsoft - NTLM Hash Disclosure Spoofing (library-ms)
unzip-stream 0.3.1 – Arbitrary File Write
# Exploit Title: unzip-stream 0.3.1 - Arbitrary File Write
code-projects Online Exam Mastering System 1.0 – Reflected Cross-Site Scripting (XSS)
# Exploit Title: code-projects Online Exam Mastering System 1.0 - Reflected Cross-Site Scripting (XSS)
tar-fs 3.0.0 – Arbitrary File Write/Overwrite
# Exploit Title: tar-fs 3.0.0 - Arbitrary File Write/Overwrite
Microsoft Windows 11 23h2 – CLFS.sys Elevation of Privilege
# Exploit Title: Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege
WonderCMS 3.4.2 – Remote Code Execution (RCE)
# Exploit Title: WonderCMS 3.4.2 - Remote Code Execution (RCE)
Firefox ESR 115.11 – PDF.js Arbitrary JavaScript execution
# Exploit Title: Firefox ESR 115.11 - Arbitrary JavaScript execution in
WordPress Core 6.2 – Directory Traversal
# Exploit Title: WordPress Core 6.2 - Directory Traversal
Microsoft Windows 11 – Kernel Privilege Escalation
# Exploit Title: Microsoft Windows 11 - Kernel Privilege Escalation
Drupal 11.x-dev – Full Path Disclosure
#!/usr/bin/env python
FoxCMS 1.2.5 – Remote Code Execution (RCE)
# Date: 2025-04-17
Hunk Companion Plugin 1.9.0 – Unauthenticated Plugin Installation
# Exploit Title: Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation
Tatsu 3.3.11 – Unauthenticated RCE
# Exploit Title:Tatsu 3.3.11 - Unauthenticated RCE
Apache Commons Text 1.10.0 – Remote Code Execution
# Exploit Title: Apache Commons Text 1.10.0 - Remote Code Execution
Langflow 1.3.0 – Remote Code Execution (RCE)
# Exploit Title: Langflow 1.3.0 - Remote Code Execution (RCE)
Inventio Lite 4 – SQL Injection
# Exploit Title: Inventio Lite 4 - SQL Injection
UJCMS 9.6.3 – User Enumeration via IDOR
# Exploit Title: UJCMS 9.6.3 User Enumeration via IDOR
KiviCare Clinic & Patient Management System (EHR) 3.6.4 – Unauthenticated SQL Injection
# Exploit Title: KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated SQL Injection
TP-Link VN020 F3v(T) TT_V6.2.1021 – Buffer Overflow Memory Corruption
#define _CRT_SECURE_NO_WARNINGS
TP-Link VN020 F3v(T) TT_V6.2.1021 – Denial Of Service (DOS)
# Exploit Title: TP-Link VN020 F3v(T) TT_V6.2.1021 - Denial Of Service (DOS)
ABB Cylon Aspect 3.08.02 (deployStart.php) – Unauthenticated Command Execution
# Exploit Title: ABB Cylon Aspect 3.08.02 (deployStart.php) Unauthenticated Command Execution
ABB Cylon Aspect 3.08.02 (ethernetUpdate.php) – Authenticated Path Traversal
# Exploit Title: ABB Cylon Aspect 3.08.02 (ethernetUpdate.php) - Authenticated Path Traversal
Angular-Base64-Upload Library 0.1.21 – Unauthenticated Remote Code Execution (RCE)
# Exploit Title: Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE)
Usermin 2.100 – Username Enumeration
# Exploit Title: Usermin 2.100 - Username Enumeration
Blood Bank & Donor Management System 2.4 – CSRF Improper Input Validation
#Exploit Title: Blood Bank & Donor Management System 2.4 - CSRF Improper
compop.ca 3.5.3 – Arbitrary code Execution
# Exploit Title: compop.ca 3.5.3 - Arbitrary code Execution
AnyDesk 9.0.1 – Unquoted Service Path
# Exploit Title: AnyDesk 9.0.1 - Unquoted Service Path
Dell EMC iDRAC7/iDRAC8 2.52.52.52 – Remote Code Execution (RCE)
# Exploit Title: Dell EMC iDRAC7/iDRAC8 2.52.52.52 - Remote Code Execution (RCE)
WooCommerce Customers Manager 29.4 – Post-Authenticated SQL Injection
# Exploit Title: WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection
Teedy 1.11 – Account Takeover via Stored Cross-Site Scripting (XSS)
# Exploit Title: Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
ProConf 6.0 – Insecure Direct Object Reference (IDOR)
# Exploit Title: ProConf 6.0 - Insecure Direct Object Reference (IDOR)
WebMethods Integration Server 10.15.0.0000-0092 – Improper Access on Login Page
# Exploit Title: WebMethods Integration Server 10.15.0.0000-0092 - Improper Access on Login Page