Exploit-DB
2.38K subscribers
9.31K links
Offensive Security Exploit Database
Download Telegram
[local] Mini-XML 3.2 - Heap Overflow
Mini-XML 3.2 - Heap Overflow
hxxps://www.exploit-db.com/exploits/50465
[webapps] Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
hxxps://www.exploit-db.com/exploits/50464
[webapps] WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50463
[webapps] Umbraco v8.14.1 - 'baseUrl' SSRF
Umbraco v8.14.1 - 'baseUrl' SSRF
hxxps://www.exploit-db.com/exploits/50462
[webapps] PHPGurukul Hostel Management System 2.1 - Cross-site request forgery (CSRF) to Cross-site Scripting (XSS)
PHPGurukul Hostel Management System 2.1 - Cross-site request forgery (CSRF) to Cross-site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50461
[webapps] WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS)
WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50460
[webapps] WordPress Plugin Filterable Portfolio Gallery 1.0 - 'title' Stored Cross-Site Scripting (XSS)
WordPress Plugin Filterable Portfolio Gallery 1.0 - 'title' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50458
[webapps] phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
hxxps://www.exploit-db.com/exploits/50457
[webapps] Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2)
Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2)
hxxps://www.exploit-db.com/exploits/50456
[webapps] WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS)
WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50455
[webapps] WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS)
WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50454
[webapps] Engineers Online Portal 1.0 - 'id' SQL Injection
Engineers Online Portal 1.0 - 'id' SQL Injection
hxxps://www.exploit-db.com/exploits/50453
[webapps] Engineers Online Portal 1.0 - 'multiple' Authentication Bypass
Engineers Online Portal 1.0 - 'multiple' Authentication Bypass
hxxps://www.exploit-db.com/exploits/50452
[webapps] Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50451
[webapps] Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS)
Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50450
[local] Gestionale Open 11.00.00 - Local Privilege Escalation
Gestionale Open 11.00.00 - Local Privilege Escalation
hxxps://www.exploit-db.com/exploits/50449
[local] OpenClinic GA 5.194.18 - Local Privilege Escalation
OpenClinic GA 5.194.18 - Local Privilege Escalation
hxxps://www.exploit-db.com/exploits/50448
[webapps] Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated)
Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated)
hxxps://www.exploit-db.com/exploits/50447
[webapps] Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
hxxps://www.exploit-db.com/exploits/50446