Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

WordPress Modern Events Calendar 5.16.2 Information Disclosure

Authored by Ron Jost WordPress Modern Events Calendar plugin version 5.16.2 suffers from an issue where unauthenticated parties can export all event data. advisories | CVE-2021-24146 Change Mirror Download # Exploit Title: Wordpress...

WordPress Modern Events Calendar 5.16.2 Shell Upload

Authored by Ron Jost WordPress Modern Events Calendar plugin version 5.16.2 suffers from a remote shell upload vulnerability. advisories | CVE-2021-24145 Change Mirror Download # Exploit Title: Wordpress Plugin Modern Events Calendar 5.16.2...

Scratch Desktop 3.17 Code Execution / Cross Site Scripting

Authored by apple502j, Stig Magnus Baugsto Scratch Desktop version 3.17 suffers from code execution and cross site scripting vulnerabilities. Change Mirror Download # Exploit Title: Scratch Desktop 3.17 - Cross-Site Scripting/Remote Code...

Microsoft PrintNightmare Proof Of Concept

Authored by cube0x0 | Site github.com This is the Impacket implementation of the PrintNightmare proof of concept originally created by Zhiniang Peng and Xuefeng Li that leverages a privilege escalation...

Garbage Collection Management System 1.0 SQL Injection

Authored by ircashem Garbage Collection Management System version 1.0 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: Garbage Collection Management System 1.0 - SQL Injection (Unauthenticated)# Exploit...

PrintNightmare Windows Spooler Service Remote Code Execution

Authored by Zhiniang Peng, Xuefeng Li | Site github.com PrintNightmare remote code execution proof of concept exploit for the Windows Spooler Service. advisories | CVE-2021-1675

Securepoint SSL VPN Client 2.0.30 Local Privilege Escalation

Authored by Florian Bogner | Site bogner.sh Securepoint SSL VPN Client version 2.0.30 suffers from a local privilege escalation vulnerability. advisories | CVE-2021-35523 Change Mirror Download Local Privilege Escalation in Securepoint SSL VPN...

Apache Superset 1.1.0 Account Enumeration

Authored by Dolev Farhi Apache Superset version 1.1.0 suffers from a time-based account enumeration vulnerability. Change Mirror Download # Exploit Title: Apache Superset 1.1.0 - Time-Based Account Enumeration# Author: Dolev Farhi# Date:...

KVM nested_svm_vmrun Double Fetch

Authored by Google Security Research, Felix Wilhelm A KVM guest on AMD can launch a L2 guest without the Intercept VMRUN control bit by exploiting a TOCTOU vulnerability in nested_svm_vmrun....

Vianeos OctoPUS 5 SQL Injection

Authored by Audencia Business School Vianeos OctoPUS version 5 suffers from a remote time-based SQL injection vulnerability. Change Mirror Download # Exploit Title: Vianeos OctoPUS 5 - 'login_user' SQLi# Date: 01/07/2021# Exploit...