2021-06-16 |
disk sorter server 13.6.12 - 'disk sorter server' unquoted service path
|
local exploit |
windows vulnerability |
2021-06-16 |
diskpulse 13.6.14 - 'multiple' unquoted service path
|
local exploit |
windows vulnerability |
2021-06-15 |
polkit 0.105-26 0.117-2 - local privilege escalation
|
local exploit |
linux vulnerability |
2021-06-15 |
brother bragent 1.38 - 'wba_agent_client' unquoted service path
|
local exploit |
windows vulnerability |
2021-06-15 |
sysgauge 7.9.18 - ' sysgauge server' unquoted service path
|
local exploit |
windows vulnerability |
2021-06-15 |
client management system 1.1 - 'search' sql injection
|
webapps exploit |
tru64 vulnerability |
2021-06-15 |
client management system 1.1 - 'username' stored cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-06-15 |
brother brprint auditor - 'multiple' unquoted service path
|
local exploit |
windows vulnerability |
2021-06-14 |
tftpd64 4.64 - 'tftpd32_svc' unquoted service path
|
local exploit |
windows vulnerability |
2021-06-14 |
notex the best notes 6.4 - denial of service (poc)
|
dos exploit |
ios vulnerability |
2021-06-14 |
post-it 5.0.1 - denial of service (poc)
|
dos exploit |
ios vulnerability |
2021-06-14 |
secure notepad private notes 3.0.3 - denial of service (poc)
|
dos exploit |
ios vulnerability |
2021-06-14 |
wibukey runtime 6.51 - 'wksvw32.exe' unquoted service path
|
local exploit |
windows vulnerability |
2021-06-14 |
openemr 5.0.1.3 - 'manage_site_files' remote code execution (authenticated)
|
webapps exploit |
php vulnerability |
2021-06-14 |
spy emergency 25.0.650 - 'multiple' unquoted service path
|
local exploit |
windows vulnerability |
2021-06-14 |
textpattern cms 4.8.7 - remote command execution (authenticated)
|
webapps exploit |
php vulnerability |
2021-06-14 |
small crm 3.0 - 'authentication bypass' sql injection
|
webapps exploit |
php vulnerability |
2021-06-14 |
stock management system 1.0 - 'user_id' blind sql injection (authenticated)
|
webapps exploit |
php vulnerability |
2021-06-14 |
covid19 testing management system 1.0 - 'state' stored cross-site-scripting (xss)
|
webapps exploit |
php vulnerability |
2021-06-14 |
glpi 9.4.5 - remote code execution (rce)
|
webapps exploit |
php vulnerability |
2021-06-14 |
accela civic platform 21.1 - 'contactseqnumber' insecure direct object references (idor)
|
webapps exploit |
multiple vulnerability |
2021-06-14 |
accela civic platform 21.1 - 'successurl' cross-site-scripting (xss)
|
webapps exploit |
multiple vulnerability |
2021-06-11 |
wowonder social network platform 3.1 - authentication bypass
|
webapps exploit |
php vulnerability |
2021-06-11 |
zenario cms 8.8.52729 - 'cid' sql injection (authenticated)
|
webapps exploit |
php vulnerability |
2021-06-11 |
solar-log 500 2.8.2 - unprotected storage of credentials
|
webapps exploit |
multiple vulnerability |
2021-06-11 |
solar-log 500 2.8.2 - incorrect access control
|
webapps exploit |
multiple vulnerability |
2021-06-11 |
grocery crud 1.6.4 - 'order_by' sql injection
|
webapps exploit |
multiple vulnerability |
2021-06-11 |
wordpress plugin database backups 1.2.2.6 - 'database backup download' csrf
|
webapps exploit |
php vulnerability |
2021-06-11 |
openemr 5.0.0 - remote code execution (authenticated)
|
webapps exploit |
php vulnerability |
2021-06-11 |
microsoft sharepoint server 16.0.10372.20060 - 'getxmldatafromdatasource' server-side request forgery (ssrf)
|
webapps exploit |
windows vulnerability |
2021-06-11 |
cerberus ftp web service 11 - 'svg' stored cross-site scripting (xss)
|
webapps exploit |
multiple vulnerability |
2021-06-11 |
accela civic platform 21.1 - 'servprovcode' cross-site-scripting (xss)
|
webapps exploit |
multiple vulnerability |
2021-06-10 |
n+otes 1.6.2 - denial of service (poc)
|
dos exploit |
ios vulnerability |
2021-06-10 |
sticky notes widget version 3.0.6 - denial of service (poc)
|
dos exploit |
ios vulnerability |
2021-06-10 |
memono notepad version 4.2 - denial of service (poc)
|
local exploit |
ios vulnerability |
2021-06-10 |
linux/x86 - execve /bin/sh shellcode (fstenv eip getpc technique) (70 bytes, xor encoded)
|
shellcode exploit |
linux_x86 vulnerability |
2021-06-10 |
textpattern cms 4.8.7 - stored cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-06-10 |
student result management system 1.0 - 'class' sql injection
|
webapps exploit |
php vulnerability |
2021-06-09 |
gravcms 1.10.7 - arbitrary yaml write/update (unauthenticated) (2)
|
webapps exploit |
php vulnerability |
2021-06-09 |
wordpress plugin visitors-app 0.3 - 'user-agent' stored cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-06-09 |
opencart 3.0.3.6 - 'subject' stored cross-site scripting
|
webapps exploit |
php vulnerability |
2021-06-09 |
opencart 3.0.3.7 - 'change password' cross-site request forgery (csrf)
|
webapps exploit |
php vulnerability |
2021-06-09 |
intelbras router rf 301k - 'dns hijacking' cross-site request forgery (csrf)
|
webapps exploit |
hardware vulnerability |
2021-06-08 |
wordpress plugin wpdiscuz 7.0.4 - remote code execution (unauthenticated)
|
webapps exploit |
php vulnerability |
2021-06-08 |
backup key recovery 2.2.7 - denial of service (poc)
|
local exploit |
windows vulnerability |
2021-06-08 |
nsauditor 3.2.3 - denial of service (poc)
|
dos exploit |
windows vulnerability |
2021-06-08 |
nbmonitor 1.6.8 - denial of service (poc)
|
dos exploit |
windows vulnerability |
2021-06-07 |
cracking pi-hole passwords - paper
|
papers exploit |
linux vulnerability |
2021-06-07 |
wordpress plugin wpdiscuz 7.0.4 - arbitrary file upload (unauthenticated)
|
webapps exploit |
php vulnerability |
2021-06-07 |
grav cms 1.7.10 - server-side template injection (ssti) (authenticated)
|
webapps exploit |
php vulnerability |