Exploit-DB
2.38K subscribers
9.31K links
Offensive Security Exploit Database
Download Telegram
[webapps] Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read
Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read
hxxps://www.exploit-db.com/exploits/50437
[webapps] Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50435
[dos] NIMax 5.3.1f0 - 'VISA Alias' Denial of Service (PoC)
NIMax 5.3.1f0 - 'VISA Alias' Denial of Service (PoC)
hxxps://www.exploit-db.com/exploits/50434
[dos] NIMax 5.3.1 - 'Remote VISA System' Denial of Service (PoC)
NIMax 5.3.1 - 'Remote VISA System' Denial of Service (PoC)
hxxps://www.exploit-db.com/exploits/50433
[webapps] Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
hxxps://www.exploit-db.com/exploits/50432
[local] Macro Expert 4.7 - Unquoted Service Path
Macro Expert 4.7 - Unquoted Service Path
hxxps://www.exploit-db.com/exploits/50431
[webapps] SonicWall SMA 10.2.1.0-17sv - Password Reset
SonicWall SMA 10.2.1.0-17sv - Password Reset
hxxps://www.exploit-db.com/exploits/50430
[webapps] Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
hxxps://www.exploit-db.com/exploits/50429
[webapps] myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50428
[webapps] WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50427
[webapps] Plastic SCM 10.0.16.5622 - WebAdmin Server Access
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
hxxps://www.exploit-db.com/exploits/50426
[webapps] Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF)
Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF)
hxxps://www.exploit-db.com/exploits/50425
[webapps] Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS)
Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50424
[webapps] Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50423
[webapps] Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
hxxps://www.exploit-db.com/exploits/50422
[webapps] Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS)
Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50421
[webapps] Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
hxxps://www.exploit-db.com/exploits/50420
[webapps] Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS)
Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50419
[webapps] i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50418
[local] SolarWinds Kiwi CatTools 3.11.8 - Unquoted Service Path
SolarWinds Kiwi CatTools 3.11.8 - Unquoted Service Path
hxxps://www.exploit-db.com/exploits/50416