ALL NEWS

Exploits

Exploit database updates and PoC releases

[remote] Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure

Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure

Aug 18Exploit Database

[webapps] Soosyze CMS 2.0 - Brute Force Login

Soosyze CMS 2.0 - Brute Force Login

Aug 18Exploit Database

[webapps] Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)

Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)

Aug 18Exploit Database

[local] GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure

GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure

Aug 26Exploit Database

[remote] GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)

GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)

Aug 26Exploit Database

[remote] HTMLDOC 1.9.13 - Stack Buffer Overflow

HTMLDOC 1.9.13 - Stack Buffer Overflow

Low
Sep 16Exploit Database

[remote] HTTP/2 2.0 - Denial Of Service (DOS)

HTTP/2 2.0 - Denial Of Service (DOS)

Sep 16Exploit Database

[local] Mbed TLS 3.6.4 - Use-After-Free

Mbed TLS 3.6.4 - Use-After-Free

Sep 16Exploit Database

[webapps] Concrete CMS 9.4.3 - Stored XSS

Concrete CMS 9.4.3 - Stored XSS

Sep 16Exploit Database

[webapps] XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)

XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)

Sep 16Exploit Database

[webapps] ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection

ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection

Sep 16Exploit Database

[webapps] dotCMS 25.07.02-1 - Authenticated Blind SQL Injection

dotCMS 25.07.02-1 - Authenticated Blind SQL Injection

Sep 16Exploit Database

[webapps] Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)

Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)

Sep 16Exploit Database

[webapps] Tourism Management System 2.0 - Arbitrary Shell Upload

Tourism Management System 2.0 - Arbitrary Shell Upload

Sep 16Exploit Database

[remote] ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)

ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)

Sep 16Exploit Database

[remote] ClipBucket 5.5.0 - Arbitrary File Upload

ClipBucket 5.5.0 - Arbitrary File Upload

Sep 16Exploit Database

[local] Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP - Elevation of Privilege

Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP - Elevation of Privilege

Sep 16Exploit Database

[remote] Ilevia EVE X1/X5 Server 4.7.18.0.eden - Reverse Rootshell

Ilevia EVE X1/X5 Server 4.7.18.0.eden - Reverse Rootshell

Sep 16Exploit Database

[webapps] Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)

Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)

Oct 29Exploit Database

[webapps] Flowise 3.0.4 - Remote Code Execution (RCE)

Flowise 3.0.4 - Remote Code Execution (RCE)

Low
Oct 31Exploit Database

[webapps] phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)

phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)

Dec 2Exploit Database

[webapps] phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)

phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)

Dec 2Exploit Database

[webapps] Piwigo 13.6.0 - SQL Injection

Piwigo 13.6.0 - SQL Injection

Dec 2Exploit Database

[webapps] phpIPAM 1.5.1 - SQL Injection

phpIPAM 1.5.1 - SQL Injection

Dec 2Exploit Database

[webapps] phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)

phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)

Dec 2Exploit Database

[webapps] YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)

YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)

Dec 2Exploit Database

[webapps] openSIS Community Edition 8.0 - SQL Injection

openSIS Community Edition 8.0 - SQL Injection

Dec 3Exploit Database

[webapps] PluckCMS 4.7.10 - Unrestricted File Upload

PluckCMS 4.7.10 - Unrestricted File Upload

Dec 3Exploit Database

[webapps] RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)

RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)

Dec 3Exploit Database

[webapps] RosarioSIS 6.7.2 - Cross Site Scripting (XSS)

RosarioSIS 6.7.2 - Cross Site Scripting (XSS)

Dec 3Exploit Database

[webapps] phpMyAdmin 5.0.0 - SQL Injection

phpMyAdmin 5.0.0 - SQL Injection

Dec 3Exploit Database

[webapps] OpenRepeater 2.1 - OS Command Injection

OpenRepeater 2.1 - OS Command Injection

Dec 3Exploit Database

[webapps] phpIPAM 1.4 - SQL-Injection

phpIPAM 1.4 - SQL-Injection

Dec 3Exploit Database

[webapps] MobileDetect 2.8.31 - Cross-Site Scripting (XSS)

MobileDetect 2.8.31 - Cross-Site Scripting (XSS)

Dec 3Exploit Database

[webapps] phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)

phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)

Dec 3Exploit Database

[webapps] Django 5.1.13 - SQL Injection

Django 5.1.13 - SQL Injection

Dec 3Exploit Database

[webapps] MaNGOSWebV4 4.0.6 - Reflected XSS

MaNGOSWebV4 4.0.6 - Reflected XSS

Dec 3Exploit Database

[webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF)

phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF)

Dec 3Exploit Database

[webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)

phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)

Dec 3Exploit Database

[webapps] Pluck 4.7.7-dev2 - PHP Code Execution

Pluck 4.7.7-dev2 - PHP Code Execution

Dec 8Exploit Database

[webapps] esm-dev 136 - Path Traversal

esm-dev 136 - Path Traversal

Dec 16Exploit Database

[webapps] Summar Employee Portal 3.98.0 - Authenticated SQL Injection

Summar Employee Portal 3.98.0 - Authenticated SQL Injection

Dec 16Exploit Database

[webapps] FreeBSD rtsold 15.x - Remote Code Execution via DNSSL

FreeBSD rtsold 15.x - Remote Code Execution via DNSSL

Dec 25Exploit Database

[webapps] Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie

Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie

Dec 25Exploit Database

[webapps] WordPress Quiz Maker 6.7.0.56 - SQL Injection

WordPress Quiz Maker 6.7.0.56 - SQL Injection

Dec 25Exploit Database