Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Piwigo 13.7.0 Cross Site Scripting

Authored by Okan Kurtulus Piwigo version 13.7.0 suffers from a persistent cross site scripting vulnerability. Change Mirror Download #Exploit Title: Piwigo v13.7.0 - Stored Cross-Site Scripting (XSS) (Authenticated)#Date: 25 June 2023#Exploit Author:...

Apache RocketMQ 5.1.0 Arbitrary Code Injection

Authored by h00die, jheysel-r7, Malayke | Site metasploit.com RocketMQ versions 5.1.0 and below are vulnerable to arbitrary code injection. Broker component of RocketMQ is leaked on the extranet and lack...

ApnaTrademark CMS 2.5 SQL Injection

Authored by indoushka ApnaTrademark CMS version 2.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Change Mirror Download ====================================================================================================================================| # Title : ApnaTrademark CMS...

AppleZeed CMS 2.0 SQL Injection

Authored by indoushka AppleZeed CMS version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Change Mirror Download ====================================================================================================================================| # Title : AppleZeed CMS...

POS Codekop 2.0 Shell Upload

Authored by yuyudhn POS Codekop version 2.0 suffers from a remote shell upload vulnerability. advisories | CVE-2023-36348 Change Mirror Download # Exploit Title: POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)# Date:...

D-Link DAP-1325 Insecure Direct Object Reference

Authored by ieduardogoncalves D-Link DAP-1325 suffers from an insecure direct object reference vulnerability. Change Mirror Download # Exploit Title: D-Link DAP-1325 - Broken Access Control# Date: 27-06-2023# Exploit Author: ieduardogoncalves# Contact :...

WordPress WP AutoComplete Search 1.0.4 SQL Injection

Authored by Matin Nouriyan WordPress WP AutoComplete Search plugin versions 1.0.4 and below suffer from a remote SQL injection vulnerability. advisories | CVE-2022-4297 Change Mirror Download # Exploit Title: WP AutoComplete 1.0.4 -...

Qualcomm Adreno/KGSL Insecure Execution

Authored by Jann Horn, Google Security Research Qualcomm Adreno/KGSL suffers from an issue where code in user-writable mapping is executed in non-protected mode. advisories | CVE-2023-21670

Citrix Gateway And Cloud MFA Insufficient Session Validation

Authored by Vulnerability Laboratory, Benjamin Mejri, Lars Guenther | Site vulnerability-lab.com Citrix Gateway and Cloud MFA suffers from an insufficient session validation vulnerability. Change Mirror Download Document Title:===============Citrix Gateway & Cloud MFA...

Super Store Finder PHP Script 3.6 SQL Injection

Authored by Etharus Super Store Finder PHP Script versions 3.6 and below suffer from a remote SQL injection vulnerability that allows for authentication bypass. Change Mirror Download #Title : Super Store Finder...