multiple
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Pie Register WordPress Plugin 3.7.1.4 – Authentication Bypass to RCE
# Exploit Title: Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE
Simple File List WordPress Plugin 4.2.2 – File Upload to RCE
# Exploit Title: Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
WP Publications WordPress Plugin 1.2 – Stored XSS
# Exploit Title: WP Publications WordPress Plugin 1.2 - Stored XSS
White Star Software Protop 4.4.2-2024-11-27 – Local File Inclusion (LFI)
# Exploit Title: White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)
SugarCRM 14.0.0 – SSRF/Code Injection
# Exploit Title : SugarCRM 14.0.0 - SSRF/Code Injection
Langflow 1.2.x – Remote Code Execution (RCE)
#!/usr/bin/env python3
TOTOLINK N300RB 8.54 – Command Execution
# Title: TOTOLINK N300RB 8.54 - Command Execution
PivotX 3.0.0 RC3 – Remote Code Execution (RCE)
# Exploit Title: PivotX v3.0.0 RC3 - Stored XSS to Remote Code Execution (RCE)
MikroTik RouterOS 7.19.1 – Reflected XSS
# Exploit Title: MikroTik RouterOS 7.19.1 - Reflected XSS
Discourse 3.2.x – Anonymous Cache Poisoning
#!/usr/bin/env python3
Stacks Mobile App Builder 5.2.3 – Authentication Bypass via Account Takeover
# Exploit Title: Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover
ScriptCase 9.12.006 (23) – Remote Command Execution (RCE)
# Exploit Title: ScriptCase 9.12.006 (23) - Remote Command Execution (RCE)
Moodle 4.4.0 – Authenticated Remote Code Execution
# Exploit Title: Moodle 4.4.0 - Authenticated Remote Code Execution
gogs 0.13.0 – Remote Code Execution (RCE)
# Exploit Title: gogs 0.13.0 - Remote Code Execution (RCE)
Wing FTP Server 7.4.3 – Unauthenticated Remote Code Execution (RCE)
# Exploit Title: Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
Social Warfare WordPress Plugin 3.5.2 – Remote Code Execution (RCE)
#!/usr/bin/env python3
McAfee Agent 5.7.6 – Insecure Storage of Sensitive Information
Exploit Title: McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
Sitecore 10.4 – Remote Code Execution (RCE)
# Exploit Title: Sitecore 10.4 - Remote Code Execution (RCE)
Pterodactyl Panel 1.11.11 – Remote Code Execution (RCE)
# Exploit Title: Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
PX4 Military UAV Autopilot 1.12.3 – Denial of Service (DoS)
# Exploit Title: PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
Ingress-NGINX 4.11.0 – Remote Code Execution (RCE)
# Exploit Title: Ingress-NGINX 4.11.0 - Remote Code Execution (RCE)
FortiOS SSL-VPN 7.4.4 – Insufficient Session Expiration & Cookie Reuse
#!/usr/bin/env python3
Skyvern 0.1.85 – Remote Code Execution (RCE) via SSTI
# Exploit Title: Skyvern 0.1.85 - Remote Code Execution (RCE) via SSTI
Parrot and DJI variants Drone OSes – Kernel Panic Exploit
#!/usr/bin/env python3
Freefloat FTP Server 1.0 – Remote Buffer Overflow
# Exploit Title: Freefloat FTP Server 1.0 - Remote Buffer Overflow
TightVNC 2.8.83 – Control Pipe Manipulation
# Exploit Title: TightVNC 2.8.83 - Control Pipe Manipulation
Apache Tomcat 10.1.39 – Denial of Service (DoS)
# Exploit Title: Apache Tomcat 10.1.39 - Denial of Service (DOS)
ABB Cylon Aspect 3.08.04 DeploySource – Remote Code Execution (RCE)
ABB Cylon Aspect 3.08.04 DeploySource - Remote Code Execution (RCE)
Grandstream GSD3710 1.0.11.13 – Stack Overflow
#!/usr/bin/env python3
SolarWinds Serv-U 15.4.2 HF1 – Directory Traversal
# Exploit Title: SolarWinds Serv-U 15.4.2 HF1 - Directory Traversal
Automic Agent 24.3.0 HF4 – Privilege Escalation
# Exploit Title: Automic Agent 24.3.0 HF4 - Privilege Escalation
Fortra GoAnywhere MFT 7.4.1 – Authentication Bypass
#!/usr/bin/env python3
WordPress Digits Plugin 8.4.6.1 – Authentication Bypass via OTP Bruteforcing
# Exploit Title: WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcing
Campcodes Online Hospital Management System 1.0 – SQL Injection
# Exploit Title: Campcodes Online Hospital Management System 1.0 - SQL Injection
ABB Cylon Aspect Studio 3.08.03 – Binary Planting
# Exploit Title: ABB Cylon Aspect Studio 3.08.03 - Binary Planting
Grandstream GSD3710 1.0.11.13 – Stack Buffer Overflow
#!/usr/bin/env python3
WordPress User Registration & Membership Plugin 4.1.2 – Authentication Bypass
#!/usr/bin/env python3
ABB Cylon Aspect 3.08.03 – Guest2Root Privilege Escalation
#!/usr/bin/env python
CrushFTP 11.3.1 – Authentication Bypass
# Exploit Title: CrushFTP 11.3.1 - Authentication Bypass
Zyxel USG FLEX H series uOS 1.31 – Privilege Escalation
# Exploit Title: Zyxel USG FLEX H series uOS 1.31 - Privilege Escalation
TP-Link VN020 F3v(T) TT_V6.2.1021) – DHCP Stack Buffer Overflow
#define _WINSOCK_DEPRECATED_NO_WARNINGS
Kentico Xperience 13.0.178 – Cross Site Scripting (XSS)
# Exploit Title: Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
RDPGuard 9.9.9 – Privilege Escalation
# Exploit Title: RDPGuard 9.9.9 - Privilege Escalation
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 – Privilege Escalation
# Exploit Title: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
SureTriggers OttoKit Plugin 1.0.82 – Privilege Escalation
# Exploit Title: SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation
WordPress Depicter Plugin 3.6.1 – SQL Injection
# Exploit Title: WordPress Depicter Plugin 3.6.1 - SQL Injection