Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

SPIP 4.2.11 Code Execution

0
Authored by indoushka SPIP version 4.2.11 suffers from a code execution vulnerability. Change Mirror Download =============================================================================================================================================| # Title : SPIP 4.2.11 PHP Code execution Vulnerability ...

Helpdeskz 2.0.2 Cross Site Scripting

0
Authored by Md. Sadikul Islam Helpdeskz version 2.0.2 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Stored XSS Vulnerability via File Name# Google Dork: N/A# Date:...

Calibre Web 0.6.21 Cross Site Scripting

0
Authored by Catalin Iovita, Alexandru Postolache Calibre Web version 0.6.21 suffers from a persistent cross site scripting vulnerability. advisories | CVE-2024-39123 Change Mirror Download # Exploit Title: Stored XSS in Calibre-web# Date: 07/05/2024#...

Invesalius 3.1 Remote Code Execution

0
Authored by Riccardo Degli Esposti, Alessio Romano Invesalius versions 3.1.99991 through 3.1.99998 suffer from a remote code execution vulnerability. The exploitation steps of this vulnerability involve the use of a...

PlantUML 1.2024.6 Cross Site Scripting

0
Authored by Hosein Vita PlantUML version 1.2024.6 suffers from a cross site scripting vulnerability. Change Mirror Download #Exploit Title: PlantUML version 1.2024.6 Cross Site Scripting (XSS)#Date: 23/08/2024#Exploit Author: Hosein Vita#Vendor Homepage: https://plantuml.com/#Version:...

DiCal-RED 4009 Missing Authentication

0
Authored by Sebastian Hamann | Site syss.de DiCal-RED version 4009 provides a Telnet service on TCP port 23. This service grants access to an interactive shell as the system's root...

DiCal-RED 4009 Weak Hashing

0
Authored by Sebastian Hamann | Site syss.de DiCal-RED version 4009 has a password that is stored in the file /etc/deviceconfig as a plain MD5 hash, i.e. without any salt or...

DiCal-RED 4009 Cryptography Failure

0
Authored by Sebastian Hamann | Site syss.de DiCal-RED version 4009 provides an administrative web interface that requests the administrative system password before it can be used. Instead of submitting the...

DiCal-RED 4009 Path Traversal

0
Authored by Sebastian Hamann | Site syss.de DiCal-RED version 4009 has an administrative web interface that is vulnerable to path traversal attacks in several places. The functions to download or...

DiCal-RED 4009 Log Disclosure

0
Authored by Sebastian Hamann | Site syss.de DiCal-RED version 4009 is vulnerable to unauthorized log access and other files on the device's file system due to improper authentication checks. advisories |...