reNgine 2.2.0 – Command Injection (Authenticated)
# Exploit Title: reNgine 2.2.0 - Command Injection (Authenticated)
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: reNgine 2.2.0 - Command Injection (Authenticated)
# Exploit Title: Stored XSS in NoteMark
# Exploit Title: Stored XSS in Gitea
# Exploit Title: Stored XSS in Calibre-web
# Exploit Title: Ivanti vADC 9.9 - Authentication Bypass
# Exploit Title: SolarWinds Platform 2024.1 SR1 - Race Condition
# Exploit Title: Sitefinity 15.0 - Cross-Site Scripting (XSS)
# Exploit Title: changedetection
## Exploit Title: CrushFTP Directory Traversal
# Exploit Title: iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS)
# Exploit Title: PrusaSlicer 2.6.1 - Arbitrary code execution on g-code export
Exploit Title: Broken Access Control - on NodeBB v3.6.7
# Exploit Title: Asterisk AMI - Partial File Content & Path Disclosure (Authenticated)
# Exploit Title: NAGIOS XI SQLI
# Exploit Title: CVE-2023-22527: Atlassian Confluence RCE Vulnerability
# Exploit Title: vm2 Sandbox Escape vulnerability
Exploit Title: SnipeIT 6.2.1 - Stored Cross Site Scripting
# Exploit Title: [VMware Cloud Director | Bypass identity verification]
#!/usr/bin/python
#!/usr/bin/python
# Exploit Title: File Read Arbitrary Exploit for CVE-2023-26360
# Exploit Title: Easywall 0.3.1 - Authenticated Remote Command Execution
#!/usr/bin/python
# Exploit Title: Magento ver. 2.4.6 - XSLT Server Side Injection
# Exploit Title: Executables Created with perl2exe malicious.pl
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
# Author: prodigiousMind
# Exploit Title: SureMDM On-premise < 6.31 - CAPTCHA Bypass User Enumeration
# Exploit Title: SISQUALWFM 7.1.319.103 Host Header Injection
# Exploit Title: Splunk 9.0.4 - Information Disclosure
# Exploit Author: TOUHAMI KASBAOUI
# Exploit Title: WhatsUpGold 22.1.0 - Stored Cross-Site Scripting (XSS)
# Exploit Title: GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
#!/usr/bin/env python3
# Exploit Title: OpenPLC WebServer 3 - Denial of Service
# Exploit Title: Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS
# Exploit Title: FileMage Gateway 1.10.9 - Local File Inclusion
# Exploit Title: Lucee 5.4.2.17 - Authenticated Reflected XSS
# Exploit Title: Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read (Unauthenticated)
# Exploit Title: Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 - Password Dumping
Exploit Title: RWS WorldServer 11.7.3 - Session Token Enumeration
## Title: Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.
## Title: Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
## Title:Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
## Title:Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
## Title: Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
# Exploit Title: FuguHub 8.1 - Remote Code Execution