Microsoft Windows 11 – Kernel Privilege Escalation
# Exploit Title: Microsoft Windows 11 - Kernel Privilege Escalation
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Microsoft Windows 11 - Kernel Privilege Escalation
# Exploit Title: Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege
# Exploit Title: AnyDesk 9.0.1 - Unquoted Service Path
# Exploit Title: Fortinet FortiOS, FortiProxy, and FortiSwitchManager 7.2.0 - Authentication bypass
# Exploit Title: WebMethods Integration Server 10.15.0.0000-0092 - Improper Access on Login Page
# Exploit Title: Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
# Exploit Title: Solstice Pod API Session Key Extraction via API Endpoint
# Exploit Title: CVE-2024-21320 - NTLM Hash Leak via Malicious Windows Theme
# Exploit Title: VeeVPN 1.6.1 - 'VeePNService' Unquoted Service Path
#!/usr/bin/env python3
#Exploit Title: Genexus Protection Server 9.7.2.10 - 'protsrvservice' Unquoted Service Path Service Path
# Exploit Title: SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
# Exploit Title: Oracle Database 12c Release 1 - Unquoted Service Path
# Exploit Title: Bonjour Service - 'mDNSResponder.exe' Unquoted Service
# Exploit Title: Plantronics Hub 3.25.1 – Arbitrary File Read
# Exploit Title: AnyDesk 7.0.15 - Unquoted Service Path
# Exploit Title: ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path
[+] Credits: John Page (aka hyp3rlinx)
#############################################
# Exploit Title: Rapid7 nexpose - 'nexposeconsole' Unquoted Service Path
# Exploit Title: ASUS Control Center Express 01.06.15 - Unquoted Service Path
################################################################################################
#!/usr/bin/perl
# Exploit Title: LaborOfficeFree 19.10 MySQL Root Password Calculator - CVE-2024-1346
# Exploit Title: KiTTY 0.76.1.13 - Command Injection
# Exploit Title: KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
# Exploit Title: KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: XAMPP v3.3.0 — '.ini' Buffer Overflow (Unicode + SEH)
# Exploit Title: ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
# Exploit Title: PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow
# Exploit Title: WebCatalog 48.4 - Arbitrary Protocol Execution
# Exploit Title: Typora v1.7.4 - OS Command Injection
# Exploit Title: 7 Sticky Notes v1.9 - OS Command Injection
#---------------------------------------------------------
# Exploit Title: SyncBreeze 15.2.24 -'login' Denial of Service
# Exploit Title: GOM Player 2.3.90.5360 - Buffer Overflow (PoC)
# Exploit Title: GOM Player 2.3.90.5360 - Remote Code Execution (RCE)
#Exploit Title: Kingo ROOT 1.5.8 - Unquoted Service Path
#Exploit title: Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow
# Exploit Title: NVClient v5.0 - Stack Buffer Overflow (DoS)
# Exploit Title: Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
# Exploit Title: TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
# Exploit Title: TSplus 16.0.0.0 - Remote Work Insecure Files and Folders Permissions
# Exploit Title: TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions
# Exploit Title: OutSystems Service Studio 11.53.30 - DLL Hijacking
# Exploit Title: Xlight FTP Server 3.9.3.6 - 'Stack Buffer Overflow' (DOS)
# Exploit Title: General Device Manager 2.5.2.2 - Buffer Overflow (SEH)
# Exploit Title: mRemoteNG v1.77.3.1784-NB - Cleartext Storage of Sensitive Information in Memory