Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

WordPress Backup Guard Authenticated Remote Code Execution

Authored by Ron Jost, Nguyen Van Khanh | Site metasploit.com This Metasploit module allows an attacker with a privileged WordPress account to launch a reverse shell due to an arbitrary...

Sage X3 Administration Service Authentication Bypass / Command Execution

Authored by Aaron Herndon, Jonathan Peterson | Site metasploit.com This Metasploit module leverages an authentication bypass exploit within Sage X3 AdxSrv's administration protocol to execute arbitrary commands as SYSTEM against...

WordPress Simple Post 1.1 Cross Site Scripting

Authored by Vikas Srivastava WordPress Simple Post plugin version 1.1 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: WordPress Plugin Simple Post 1.1 - 'Text field'...

Microsoft SharePoint Server 2019 Remote Code Execution

Authored by Soroush Dalili, West Shepherd, Steven Seele Microsoft SharePoint Server 2019 remote code execution exploit. advisories | CVE-2020-1147 Change Mirror Download # Exploit Title: Microsoft SharePoint Server 2019 - Remote Code Execution...

ElasticSearch 7.13.3 Memory Disclosure

Authored by r0ny ElasticSearch version 7.13.3 memory disclosure exploit. advisories | CVE-2021-22145 Change Mirror Download # Exploit Title: ElasticSearch 7.13.3 - Memory disclosure # Date: 21/07/2021# Exploit Author: r0ny# Vendor Homepage: https://www.elastic.co/# Software...

KevinLAB BEMS 1.0 Authenticated File Path Traversal / Information Disclosure

Authored by LiquidWorm | Site zeroscience.mk KevinLAB BEMS version 1.0 suffers from an authenticated arbitrary file disclosure vulnerability. Input passed through the page GET parameter in index.php is not properly...

Vehicle Parking Management System 1.0 Cross Site Scripting

Authored by faisalfs10x Vehicle Parking Management System version 1.0 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting in this version is attributed to...

Vehicle Parking Management System 1.0 SQL Injection

Authored by faisalfs10x Vehicle Parking Management System version 1.0 suffers from a remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to gh1mau in July...

Trojan-Spy.Win32.SpyEyes.hqd Insecure Permissions

Authored by malvuln | Site malvuln.com Trojan-Spy.Win32.SpyEyes.hqd malware suffers from an insecure permissions vulnerability. Change Mirror Download Discovery / credits: Malvuln - malvuln.com (c) 2021Original source: https://malvuln.com/advisory/6f484fea8f6bb3974185fc856f37541b.txtContact: [email protected]: twitter.com/malvulnThreat: Trojan-Spy.Win32.SpyEyes.hqdVulnerability: Insecure Permissions...

WordPress Mimetic Books 0.2.13 Cross Site Scripting

Authored by Vikas Srivastava WordPress Mimetic Books plugin version 0.2.13 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher...