Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2019-09-02

Wolters Kluwer TeamMate 3.1 – Cross-Site Request Forgery

  • webapps
  • multiple
  • Bhadresh Patel
    2019-09-02

    ChaosPro 2.1 – SEH Buffer Overflow

  • local
  • windows
  • Jonathan Crosby
    2019-09-02

    Kaseya VSA agent 9.5 – Privilege Escalation

  • local
  • windows
  • NF
    2019-08-30

    WordPress Plugin WooCommerce Product Feed 2.2.18 – Cross-Site Scripting

  • webapps
  • php
  • Damian Ebelties
    2019-08-30

    VX Search Enterprise 10.4.16 – ‘User-Agent’ Denial of Service

  • dos
  • windows
  • James Chamberlain
    2019-08-30

    SQL Server Password Changer 1.90 – Denial of Service

  • dos
  • windows
  • Velayutham Selvaraj, Praveen Thiyagarayam
    2019-08-30

    Canon PRINT 2.5.5 – Information Disclosure

  • local
  • android
  • 0x48piraj
    2019-08-30

    YouPHPTube 7.4 – Remote Code Execution

  • webapps
  • php
  • Damian Ebelties
    2019-08-30

    DomainMod 4.13 – Cross-Site Scripting

  • webapps
  • php
  • Damian Ebelties
    2019-08-30

    Easy MP3 Downloader 4.7.8.8 – ‘Unlock Code’ Denial of Service

  • dos
  • windows
  • Mohan Ravichandran, Snazzy Sanoj
    2019-08-30

    Asus Precision TouchPad 11.0.0.25 – Denial of Service

  • dos
  • windows
  • Athanasios Tserpelis
    2019-08-30

    Sentrifugo 3.2 – File Upload Restriction Bypass

  • webapps
  • php
  • creosote
    2019-08-30

    Sentrifugo 3.2 – Persistent Cross-Site Scripting

  • webapps
  • php
  • creosote
    2019-08-29

    PilusCart 1.4.1 – Local File Disclosure

  • webapps
  • php
  • Damian Ebelties
    2019-08-29

    Jobberbase 2.0 – ‘subscribe’ SQL Injection

  • webapps
  • php
  • Damian Ebelties
    2019-08-29

    Webkit JSC: JIT – Uninitialized Variable Access in ArgumentsEliminationPhase::transform

  • dos
  • multiple
  • Google Security Research
    2019-08-28

    SQLiteManager 1.2.0 / 1.2.4 – Blind SQL Injection

  • webapps
  • php
  • Rafael Pedrero
    2019-08-28

    Outlook Password Recovery 2.10 – Denial of Service

  • dos
  • windows
  • Velayutham Selvaraj, Praveen Thiyagarayam
    2019-08-28

    Jobberbase 2.0 CMS – ‘jobs-in’ SQL Injection

  • webapps
  • php
  • Suvadip Kar
    2019-08-27

    Tableau – XML External Entity

  • webapps
  • multiple
  • Jarad Kopf
    2019-08-26

    openITCOCKPIT 3.6.1-2 – Cross-Site Request Forgery

  • webapps
  • php
  • Julian Rittweger
    2019-08-26

    Microsoft Windows 10 – SET_REPARSE_POINT_EX Mount Point Security Feature Bypass

  • local
  • windows
  • Google Security Research
    2019-08-26

    Exim 4.87 / 4.91 – Local Privilege Escalation (Metasploit)

  • local
  • linux
  • Metasploit
    2019-08-26

    LSoft ListServ < 16.5-2018a - Cross-Site Scripting

  • webapps
  • windows
  • MTK
    2019-08-26

    WordPress Plugin Import Export WordPress Users 1.3.1 – CSV Injection

  • webapps
  • php
  • Javier Olmedo
    2019-08-26

    WordPress Plugin UserPro 4.9.32 – Cross-Site Scripting

  • webapps
  • php
  • Damian Ebelties
    2019-08-23

    Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal

  • webapps
  • multiple
  • MaYaSeVeN
    2019-08-21

    Nagios XI 5.6.5 – Remote Code Execution / Root Privilege Escalation

  • webapps
  • php
  • Jak Gibb
    2019-08-21

    LibreOffice < 6.2.6 Macro - Python Code Execution (Metasploit)

  • remote
  • multiple
  • LoadLow
    2019-08-21

    Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN – Arbitrary File Disclosure (Metasploit)

  • webapps
  • multiple
  • Alyssa Herrera
    2019-08-21

    Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data – Multiple Vulnerabilities

  • remote
  • multiple
  • Pedro Ribeiro
    2019-08-20

    QEMU – Denial of Service

  • dos
  • linux
  • vishnudevtj
    2019-08-20

    WordPress Plugin Add Mime Types 2.2.1 – Cross-Site Request Forgery

  • webapps
  • php
  • Princy Edward
    2019-08-19

    Neo Billing 3.5 – Persistent Cross-Site Scripting

  • webapps
  • php
  • n1x_
    2019-08-19

    Webmin 1.920 – Remote Code Execution

  • webapps
  • linux
  • Fernando A. Lagos B
    2019-08-19

    YouPHPTube 7.2 – ‘userCreate.json.php’ SQL Injection

  • webapps
  • php
  • Fabian Mosch
    2019-08-19

    Fortinet FortiOS 5.6.3 – 5.6.7 / FortiOS 6.0.0 – 6.0.4 – Credentials Disclosure (Metasploit)

  • webapps
  • hardware
  • Carlos E. Vieira
    2019-08-19

    RAR Password Recovery 1.80 – ‘User Name and Registration Code’ Denial of Service

  • dos
  • windows
  • Achilles
    2019-08-19

    Fortinet FortiOS 5.6.3 – 5.6.7 / FortiOS 6.0.0 – 6.0.4 – Credentials Disclosure

  • webapps
  • hardware
  • Carlos E. Vieira
    2019-08-19

    Kimai 2 – Persistent Cross-Site Scripting

  • webapps
  • php
  • osamaalaa
    2019-08-16

    EyesOfNetwork 5.1 – Authenticated Remote Command Execution

  • webapps
  • php
  • Nassim Asrir
    2019-08-16

    Web Wiz Forums 12.01 – ‘PF’ SQL Injection

  • webapps
  • asp
  • n1x_
    2019-08-16

    Integria IMS 5.0.86 – Arbitrary File Upload

  • webapps
  • php
  • Greg.Priest
    2019-08-16

    GetGo Download Manager 6.2.2.3300 – Denial of Service

  • dos
  • windows_x86-64
  • Malav Vyas
    2019-08-16

    Joomla! component com_jsjobs 1.2.6 – Arbitrary File Deletion

  • webapps
  • php
  • qw3rTyTy
    2019-08-15

    Adobe Acrobat CoolType (AFDKO) – Memory Corruption in the Handling of Type 1 Font load/store Operators

  • dos
  • windows
  • Google Security Research
    2019-08-15

    Microsoft Font Subsetting – DLL Heap Corruption in ReadTableIntoStructure

  • dos
  • windows
  • Google Security Research
    2019-08-15

    Adobe Acrobat Reader DC for Windows – Double Free due to Malformed JP2 Stream

  • dos
  • windows
  • Google Security Research
    2019-08-15

    Microsoft Windows Text Services Framework MSCTF – Multiple Vulnerabilities

  • local
  • windows
  • Google Security Research
    2019-08-15

    Microsoft Font Subsetting – DLL Heap Corruption in ReadAllocFormat12CharGlyphMapList

  • dos
  • windows
  • Google Security Research