Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

AtTestimonials CMS 1.2 Missing Authentication

Authored by indoushka AtTestimonials CMS version 1.2 suffers from a missing authentication vulnerability. Change Mirror Download ====================================================================================================================================| # Title : AtTestimonials CMS v1.2 Missing Authentication Vulnerability ...

Avidi Media 2.0 Insecure Settings

Authored by indoushka Avidi Media version 2.0 appears to leave default credentials installed after installation. Change Mirror Download ====================================================================================================================================| # Title : Avidi Media v2.0 - Ultimate Video,...

Banner RotatorCMS 1.0 Database Disclosure

Authored by indoushka Banner RotatorCMS version 1.0 suffers from a database disclosure vulnerability. Change Mirror Download ====================================================================================================================================| # Title : Banner RotatorCMS v1.0 Database Disclosure Exploit ...

Spring Cloud 3.2.2 Remote Command Execution

Authored by GatoGamer1155, 0bfxgh0st Spring Cloud version 3.2.2 suffers from a remote command execution vulnerability. advisories | CVE-2022-22963 Change Mirror Download # Exploit Title: Spring Cloud 3.2.2 - Remote Command Execution (RCE)# Date:...

Frappe Framework 13.4.0 Remote Code Execution

Authored by Sander Ferdinand Frappe Framework (ERPNext) version 13.4.0 suffers from a remote code execution vulnerability. Change Mirror Download # Exploit Title: Frappe Framework (ERPNext) 13.4.0 - Remote Code Execution (Authenticated)# Exploit...

WordPress User Registration 3.0.2 Arbitrary File Upload

Authored by Lana Codes | Site wordfence.com The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hard-coded encryption key and missing file type validation...

Super Store Finder 3.6 SQL Injection

Authored by CraCkEr Super Store Finder version 3.6 suffers from a remote SQL injection vulnerability. Change Mirror Download ┌┌───────────────────────────────────────────────────────────────────────────────────────┐││ ...

Ekushey Project Manager CRM 5.0 Cross Site Scripting

Authored by CraCkEr Ekushey Project Manager CRM version 5.0 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Ekushey Project Manager CRM 5.0 - Stored XSS# Exploit...

Atlas Business Directory Listing 2.13 Cross Site Scripting

Authored by CraCkEr Atlas Business Directory Listing version 2.13 suffers from cross site scripting vulnerabilities. Change Mirror Download # Exploit Title: Atlas Business Directory Listing 2.13 - Reflected XSS# Exploit Author: CraCkEr#...

Kyocera TASKalfa 4053ci 2VG_S000.002.561 Path Traversal / Denial Of Service

Authored by Stefan Michlits, Gorazd Jank | Site sec-consult.com Kyocera TASKalfa 4053ci versions 2VG_S000.002.561 and below suffers from path traversal, user enumeration, and denial of service vulnerabilities. advisories | CVE-2023-34259, CVE-2023-34260,...