Exploit-DB
2.41K subscribers
9.31K links
Offensive Security Exploit Database
Download Telegram
[dos] VLC Media Player/Kodi/PopcornTime 'Red Chimera' < 2.2.5 - Memory Corruption (PoC)
VLC Media Player/Kodi/PopcornTime 'Red Chimera' < 2.2.5 - Memory Corruption (PoC)
https://www.exploit-db.com/exploits/44514/?rss
[webapps] Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass
Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass
https://www.exploit-db.com/exploits/44513/?rss
[webapps] Monstra CMS 3.0.4 - Arbitrary Folder Deletion
Monstra CMS 3.0.4 - Arbitrary Folder Deletion
https://www.exploit-db.com/exploits/44512/?rss
[webapps] Open-AudIT 2.1 - CSV Macro Injection
Open-AudIT 2.1 - CSV Macro Injection
https://www.exploit-db.com/exploits/44511/?rss
[shellcode] Linux/x86 - execve(cp /bin/sh /tmp/sh; chmod +s /tmp/sh) + Null-Free Shellcode (74 bytes)
Linux/x86 - execve(cp /bin/sh /tmp/sh; chmod +s /tmp/sh) + Null-Free Shellcode (74 bytes)
https://www.exploit-db.com/exploits/44510/?rss
[shellcode] Linux/x86 - chmod 4755 /bin/dash Shellcode (33 bytes)
Linux/x86 - chmod 4755 /bin/dash Shellcode (33 bytes)
https://www.exploit-db.com/exploits/44509/?rss
[shellcode] Linux/x86 - Reverse TCP (127.1.1.1:5555/TCP) Shell Shellcode (73 Bytes)
Linux/x86 - Reverse TCP (127.1.1.1:5555/TCP) Shell Shellcode (73 Bytes)
https://www.exploit-db.com/exploits/44508/?rss
[shellcode] Linux/x86 - Edit /etc/sudoers (ALL ALL=(ALL) NOPASSWD: ALL) For Full Access + Null-Free Shellcode (79 bytes)
Linux/x86 - Edit /etc/sudoers (ALL ALL=(ALL) NOPASSWD: ALL) For Full Access + Null-Free Shellcode (79 bytes)
https://www.exploit-db.com/exploits/44507/?rss
[dos] Chrome V8 JIT - Arrow Function Scope Fixing Bug
Chrome V8 JIT - Arrow Function Scope Fixing Bug
https://www.exploit-db.com/exploits/44541/?rss
[dos] Chrome V8 JIT - 'AwaitedPromise' Update Bug
Chrome V8 JIT - 'AwaitedPromise' Update Bug
https://www.exploit-db.com/exploits/44540/?rss
[webapps] HRSALE The Ultimate HRM v1.0.2 - Local File Inclusion
HRSALE The Ultimate HRM v1.0.2 - Local File Inclusion
https://www.exploit-db.com/exploits/44539/?rss
[webapps] HRSALE The Ultimate HRM 1.0.2 - Authenticated Cross-Site Scripting
HRSALE The Ultimate HRM 1.0.2 - Authenticated Cross-Site Scripting
https://www.exploit-db.com/exploits/44538/?rss
[webapps] HRSALE The Ultimate HRM v1.0.2 - 'award_id' SQL Injection
HRSALE The Ultimate HRM v1.0.2 - 'award_id' SQL Injection
https://www.exploit-db.com/exploits/44537/?rss
[webapps] HRSALE The Ultimate HRM v1.0.2 - CSV Injection
HRSALE The Ultimate HRM v1.0.2 - CSV Injection
https://www.exploit-db.com/exploits/44536/?rss
[webapps] Blog Master Pro v1.0 - CSV Injection
Blog Master Pro v1.0 - CSV Injection
https://www.exploit-db.com/exploits/44535/?rss
[webapps] Shopy Point of Sale v1.0 - CSV Injection
Shopy Point of Sale v1.0 - CSV Injection
https://www.exploit-db.com/exploits/44534/?rss
[dos] VMware Workstation 12.5.2 - Drag n Drop Use-After-Free (Pwn2Own 2017) (PoC)
VMware Workstation 12.5.2 - Drag n Drop Use-After-Free (Pwn2Own 2017) (PoC)
https://www.exploit-db.com/exploits/44533/?rss
[papers] Nintendo Switch/Nvidia: Vulnerability Disclosure: Fusée Gelée
Nintendo Switch/Nvidia: Vulnerability Disclosure: Fusée Gelée
http://www.exploit-db.com/docs/english/44532-nintendo-switchnvidia-vulnerability-disclosure-fusée-gelée.pdf?rss
[papers] Nintendo Switch/Nvidia: Vulnerability Disclosure: Fusée Gelée
Nintendo Switch/Nvidia: Vulnerability Disclosure: Fusée Gelée
https://www.exploit-db.com/docs/english/44532-nintendo-switchnvidia-vulnerability-disclosure-fusée-gelée.pdf?rss
[webapps] Drupal < 7.58 - 'drupalgeddon3' Authenticated Remote Code Execution (PoC)
Drupal < 7.58 - 'drupalgeddon3' Authenticated Remote Code Execution (PoC)
https://www.exploit-db.com/exploits/44542/?rss
[webapps] Jfrog Artifactory < 4.16 - Unauthenticated Arbitrary File Upload / Remote Command Execution
Jfrog Artifactory < 4.16 - Unauthenticated Arbitrary File Upload / Remote Command Execution
https://www.exploit-db.com/exploits/44543/?rss