Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Facebook For Android Friend Acceptance

0
Authored by Sivanesh Ashok Facebook for Android is vulnerable to a permission issue which allows anyone with physical access to the Android device, to accept friend requests without unlocking the...

WordPress Picture Gallery 1.4.2 Cross Site Scripting

0
Authored by Aryan Chehreghani WordPress Picture Gallery plugin version 1.4.2 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: WordPress Plugin Picture Gallery 1.4.2 - 'Edit Content...

Simple Library Management System 1.0 SQL Injection

0
Authored by Halit Akaydin Simple Library Management System version 1.0 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: Simple Library Management System 1.0 - 'rollno' SQL Injection#...

Backdoor.Win32.Zaratustra Remote File Write / Code Execution

0
Authored by malvuln | Site malvuln.com Backdoor.Win32.Zaratustra malware suffers from an unauthenticated remote file write that can be leveraged to execute arbitrary code. Change Mirror Download Discovery / credits: Malvuln - malvuln.com...

OneNav Beta 0.9.12 Cross Site Scripting

0
Authored by nu11secur1ty OneNav Beta version 0.9.12 suffers from a persistent cross site scripting vulnerability. advisories | CVE-2021-38138 Change Mirror Download # Exploit Title: XSS-Stored - Brutal PWNED on OneNav beta 0.9.12 add_link...

Microsoft Windows Malicious Software Removal Tool Privilege Escalation

0
Authored by James Forshaw, Google Security Research Microsoft Windows suffers from unsafe temporary directory use with the Malicious Software Removal Tool that can lead to elevation of privilege. advisories | CVE-2007-0843,...

Cockpit CMS 0.11.1 NoSQL Injection

0
Authored by Brian Ombongi Cockpit CMS version 0.11.1 username enumeration and password reset NoSQL injection exploit. advisories | CVE-2020-35847, CVE-2020-35848 Change Mirror Download # Exploit Title: Cockpit CMS 0.11.1 - 'Username Enumeration &...

Moodle 3.9 Remote Code Execution

0
Authored by lanz Moodle version 3.9 authenticated remote code execution exploit. Change Mirror Download # Exploit Title: Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)# Date: 12-05-2021# Exploit Author: lanz# Vendor Homepage:...

GFI Mail Archiver 15.1 Arbitrary File Upload

0
Authored by Paul Taylor, Amin Bohio GFI Mail Archiver versions 15.1 and below Telerik UI component unauthenticated arbitrary file upload exploit. Change Mirror Download # Exploit Title: GFI Mail Archiver <= 15.1...

Amica Prodigy 1.7 Privilege Escalation

0
Authored by Andrea Intilangelo Amica Prodigy version 1.7 suffers from a local privilege escalation vulnerability. advisories | CVE-2021-35312 Change Mirror Download # Exploit Title: Amica Prodigy 1.7 - Privilege Escalation# Date: 2021-08-06# Exploit...