Exploit-DB
2.41K subscribers
9.31K links
Offensive Security Exploit Database
Download Telegram
[webapps] Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE)
Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE)
hxxps://www.exploit-db.com/exploits/50444
[local] Netgear Genie 2.4.64 - Unquoted Service Path
Netgear Genie 2.4.64 - Unquoted Service Path
hxxps://www.exploit-db.com/exploits/50443
[webapps] WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
hxxps://www.exploit-db.com/exploits/50442
[webapps] Hikvision Web Server Build 210702 - Command Injection
Hikvision Web Server Build 210702 - Command Injection
hxxps://www.exploit-db.com/exploits/50441
[webapps] Online Course Registration 1.0 - Blind Boolean-Based SQL Injection (Authenticated)
Online Course Registration 1.0 - Blind Boolean-Based SQL Injection (Authenticated)
hxxps://www.exploit-db.com/exploits/50440
[webapps] Clinic Management System 1.0 - SQL injection to Remote Code Execution
Clinic Management System 1.0 - SQL injection to Remote Code Execution
hxxps://www.exploit-db.com/exploits/50439
[webapps] Jetty 9.4.37.v20210219 - Information Disclosure
Jetty 9.4.37.v20210219 - Information Disclosure
hxxps://www.exploit-db.com/exploits/50438
[webapps] Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read
Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read
hxxps://www.exploit-db.com/exploits/50437
[webapps] Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50435
[dos] NIMax 5.3.1f0 - 'VISA Alias' Denial of Service (PoC)
NIMax 5.3.1f0 - 'VISA Alias' Denial of Service (PoC)
hxxps://www.exploit-db.com/exploits/50434
[dos] NIMax 5.3.1 - 'Remote VISA System' Denial of Service (PoC)
NIMax 5.3.1 - 'Remote VISA System' Denial of Service (PoC)
hxxps://www.exploit-db.com/exploits/50433
[webapps] Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
hxxps://www.exploit-db.com/exploits/50432
[local] Macro Expert 4.7 - Unquoted Service Path
Macro Expert 4.7 - Unquoted Service Path
hxxps://www.exploit-db.com/exploits/50431
[webapps] SonicWall SMA 10.2.1.0-17sv - Password Reset
SonicWall SMA 10.2.1.0-17sv - Password Reset
hxxps://www.exploit-db.com/exploits/50430
[webapps] Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
hxxps://www.exploit-db.com/exploits/50429
[webapps] myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50428
[webapps] WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50427
[webapps] Plastic SCM 10.0.16.5622 - WebAdmin Server Access
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
hxxps://www.exploit-db.com/exploits/50426
[webapps] Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF)
Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF)
hxxps://www.exploit-db.com/exploits/50425
[webapps] Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS)
Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS)
hxxps://www.exploit-db.com/exploits/50424