Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2023-07-20

pfSense v2.7.0 – OS Command Injection

  • webapps
  • php
  • Emir Polat
    2023-07-19

    ABB FlowX v4.00 – Exposure of Sensitive Information

  • webapps
  • hardware
  • Paul Smith
    2023-07-19

    Statamic 4.7.0 – File-Inclusion

  • webapps
  • php
  • nu11secur1ty
    2023-07-19

    CmsMadeSimple v2.2.17 – Stored Cross-Site Scripting (XSS)

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-19

    CmsMadeSimple v2.2.17 – Remote Code Execution (RCE)

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-19

    CmsMadeSimple v2.2.17 – session hijacking via Server-Side Template Injection (SSTI)

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-19

    Online Piggery Management System v1.0 – unauthenticated file upload vulnerability

  • webapps
  • php
  • 1337kid
    2023-07-19

    Backdrop Cms v1.25.1 – Stored Cross-Site Scripting (XSS)

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-19

    Vaidya-Mitra 1.0 – Multiple SQLi

  • webapps
  • php
  • nu11secur1ty
    2023-07-19

    Joomla! com_booking component 2.4.9 – Information Leak (Account enumeration)

  • webapps
  • php
  • qw3rTyTy
    2023-07-19

    phpfm v1.7.9 – Authentication type juggling

  • webapps
  • php
  • thoughtfault
    2023-07-19

    PimpMyLog v1.7.14 – Improper access control

  • webapps
  • php
  • thoughtfault
    2023-07-19

    Hikvision Hybrid SAN Ds-a71024 Firmware – Multiple Remote Code Execution

  • remote
  • hardware
  • Thurein Soe
    2023-07-19

    TP-Link TL-WR740N – Authenticated Directory Transversal

  • webapps
  • hardware
  • Anish Feroz
    2023-07-19

    Blackcat Cms v1.4 – Remote Code Execution (RCE)

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-19

    Blackcat Cms v1.4 – Stored XSS

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-15

    News Portal v4.0 – SQL Injection (Unauthorized)

  • webapps
  • php
  • Hubert Wojciechowski
    2023-07-15

    Icinga Web 2.10 – Authenticated Remote Code Execution

  • webapps
  • php
  • Dante Corona
    2023-07-15

    XAMPP 8.2.4 – Unquoted Path

  • local
  • windows
  • Andrey Stoykov
    2023-07-15

    Pluck v4.7.18 – Remote Code Execution (RCE)

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-15

    WinterCMS < 1.2.3 - Persistent Cross-Site Scripting

  • webapps
  • php
  • abhishek morla
    2023-07-15

    Admidio v4.2.10 – Remote Code Execution (RCE)

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-15

    Cisco UCS-IMC Supervisor 2.2.0.0 – Authentication Bypass

  • webapps
  • hardware
  • Fatih Sencer
    2023-07-15

    ProjeQtOr Project Management System v10.4.1 – Multiple XSS

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-11

    Game Jackal Server v5 – Unquoted Service Path “GJServiceV5”

  • local
  • windows
  • Idan Malihi
    2023-07-11

    AVG Anti Spyware 7.5 – Unquoted Service Path “AVG Anti-Spyware Guard”

  • local
  • windows
  • Idan Malihi
    2023-07-11

    Ateme TITAN File 3.9 – SSRF File Enumeration

  • webapps
  • hardware
  • LiquidWorm
    2023-07-11

    BuildaGate5library v5 – Reflected Cross-Site Scripting (XSS)

  • webapps
  • php
  • Idan Malihi
    2023-07-11

    Frappe Framework (ERPNext) 13.4.0 – Remote Code Execution (Authenticated)

  • webapps
  • Python
  • Sander Ferdinand
    2023-07-11

    MiniTool Partition Wizard ShadowMaker v.12.7 – Unquoted Service Path “MTSchedulerService”

  • local
  • windows
  • Idan Malihi
    2023-07-11

    MiniTool Partition Wizard ShadowMaker v.12.7 – Unquoted Service Path “MTAgentService”

  • local
  • windows
  • Idan Malihi
    2023-07-11

    Spring Cloud 3.2.2 – Remote Command Execution (RCE)

  • webapps
  • java
  • GatoGamer1155
    2023-07-11

    Netlify CMS 2.10.192 – Stored Cross-Site Scripting (XSS)

  • webapps
  • java
  • tmrswrr
    2023-07-07

    Windows 10 v21H1 – HTTP Protocol Stack Remote Code Execution

  • remote
  • windows
  • nu11secur1ty
    2023-07-07

    Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit – Remote Code Execution

  • remote
  • multiple
  • nu11secur1ty
    2023-07-07

    Faculty Evaluation System v1.0 – SQL Injection

  • webapps
  • php
  • Andrey Stoykov
    2023-07-06

    Microsoft Edge 114.0.1823.67 (64-bit) – Information Disclosure

  • local
  • multiple
  • nu11secur1ty
    2023-07-06

    Lost and Found Information System v1.0 – SQL Injection

  • webapps
  • php
  • Amirhossein Bahramizadeh
    2023-07-06

    Gila CMS 1.10.9 – Remote Code Execution (RCE) (Authenticated)

  • webapps
  • php
  • Omer Shaik
    2023-07-06

    Piwigo v13.7.0 – Stored Cross-Site Scripting (XSS) (Authenticated)

  • webapps
  • php
  • Okan Kurtulus
    2023-07-04

    Beauty Salon Management System v1.0 – SQLi

  • webapps
  • php
  • Fatih Nacar
    2023-07-04

    Car Rental Script 1.8 – Stored Cross-site scripting (XSS)

  • webapps
  • php
  • CraCkEr
    2023-07-03

    Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit – Remote Code Execution (RCE)

  • remote
  • multiple
  • nu11secur1ty
    2023-07-03

    WebsiteBaker v2.13.3 – Directory Traversal

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-03

    WebsiteBaker v2.13.3 – Stored XSS

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-03

    Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit – Remote Code Execution (RCE)

  • remote
  • multiple
  • nu11secur1ty
    2023-07-03

    POS Codekop v2.0 – Authenticated Remote Code Execution (RCE)

  • webapps
  • php
  • yuyudhn
    2023-07-03

    WBCE CMS 1.6.1 – Open Redirect & CSRF

  • webapps
  • php
  • Mirabbas Ağalarov
    2023-07-03

    FuguHub 8.1 – Remote Code Execution

  • webapps
  • multiple
  • redfire359
    2023-07-03

    PodcastGenerator 3.2.9 – Blind SSRF via XML Injection

  • webapps
  • php
  • Mirabbas Ağalarov