Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Microsoft Error Reporting Local Privilege Elevation

0
Authored by bwatters-r7, Filip Dragovic, Octoberfest7 | Site metasploit.com This Metasploit module takes advantage of a bug in the way Windows error reporting opens the report parser. If you open...

Microsoft Windows Kernel Refcount Overflow / Use-After-Free

0
Authored by Google Security Research, mjurczyk The Microsoft Windows kernel does not reset security cache during self-healing, leading to refcount overflow and use-after-free conditions. advisories | CVE-2023-38139

Lamano CMS 2.0 Cross Site Request Forgery

0
Authored by indoushka Lamano CMS version 2.0 suffers from a cross site request forgery vulnerability. Change Mirror Download ====================================================================================================================================| # Title : Lamano CMS v2.0 CSRF Vulnerability ...

Luxcal Event Calendar 3.2.3 Cross Site Request Forgery

0
Authored by indoushka Luxcal Event Calendar version 3.2.3 suffers from a cross site request forgery vulnerability. Change Mirror Download ====================================================================================================================================| # Title : Luxcal Event Calendar v3.2.3 CSRF...

WordPress Theme My Login 2FA Brute Force

0
Authored by Joost Grunwald | Site iecetee.com WordPress Theme My Login 2FA plugin versions prior to 1.2 suffer from a brute forcing vulnerability. Change Mirror Download The theme my login plugin before...

Taskhub 2.8.7 SQL Injection

0
Authored by CraCkEr Taskhub version 2.8.7 suffers from a remote SQL injection vulnerability. advisories | CVE-2023-4987 Change Mirror Download # Exploit Title: taskhub 2.8.7 - SQL Injection# Exploit Author: CraCkEr# Date: 05/09/2023# Vendor:...

WordPress Essential Blocks 4.2.0 / Essential Blocks Pro 1.1.0 PHP Object Injection

0
Authored by Marco Wotschka | Site wordfence.com WordPress Essential Blocks plugin versions 4.2.0 and below and Essential Blocks Pro versions 1.1.0 and below suffer from multiple PHP object injection vulnerabilities. advisories...

Lexmark Device Embedded Web Server Remote Code Execution

0
Authored by jheysel-r7, James Horseman, Zach Hanley | Site metasploit.com An unauthenticated remote code execution vulnerability exists in the embedded webserver in certain Lexmark devices through 2023-02-19. The vulnerability is...

Apache Airflow 1.10.10 Remote Code Execution

0
Authored by Pepe Berba, Ismail E. Dawoodjee, xuxiang | Site metasploit.com This Metasploit module exploits an unauthenticated command injection vulnerability by combining two critical vulnerabilities in Apache Airflow version 1.10.10....

Super Store Finder 3.7 Remote Command Execution

0
Authored by Etharus Super Store Finder versions 3.7 and below suffer from a remote command execution vulnerability. Change Mirror Download # Vulnerability : Authenticated Arbitrary PHP Code Injection lead to RemoteCode Execution#...