Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

4Images 1.8 Cross Site Scripting

Authored by Piyush Patil 4Images version 1.8 suffers from a cross site scripting vulnerability. advisories | CVE-2021-27308 Change Mirror Download # Exploit Title: 4Images 1.8 - 'redirect' Reflected XSS# Exploit Author: Piyush Patil#...

Gitlab 13.9.3 Remote Code Execution

Authored by enox Gitlab version 13.9.3 authenticated remote code execution exploit. Change Mirror Download # Exploit Title: Gitlab 13.9.3 - Remote Code Execution (Authenticated)# Date: 02/06/2021# Exploit Author: enox# Vendor Homepage: https://about.gitlab.com/#...

Gstreamer Matroska Demuxing Use-After-Free

Authored by Google Security Research, natashenka Gstreamer suffers from a use-after-free vulnerability in Matroska demuxing. advisories | CVE-2021-3498

VMware ESXi OpenSLP Heap Overflow

Authored by Johnny Yu | Site github.com Proof of concept exploit for the OpenSLP heap overflow in VMware ESXi versions 7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, and 6.5 before ESXi650-202102101-SG. advisories...

Cisco SD-WAN vManage 19.2.2 Remote Root

Authored by Johnny Yu | Site github.com Cisco SD-WAN vManage version 19.2.2 remote root shell proof of concept exploit that leverages multiple vulnerabilities. advisories | CVE-2020-3387, CVE-2020-3437 Change Mirror Download <html><head><title>Cisco SD-WAN vManage...

Exim base64d Buffer Overflow

Authored by Johnny Yu | Site github.com Exim versions prior to 4.90.1 remote buffer overflow proof of concept exploit. advisories | CVE-2018-6789 Change Mirror Download #!/usr/bin/pythonimport sysimport timeimport socketimport structs = Nonef =...

Microsoft RDP Remote Code Execution

Authored by Johnny Yu | Site github.com Proof of concept exploit for a remote code execution vulnerability in Microsoft's RDP service. advisories | CVE-2019-0708 Change Mirror Download #!/usr/bin/pythonimport socketfrom OpenSSL import *from struct...

ProjeQtOr Project Management 9.1.4 Shell Upload

Authored by Temel Demir ProjeQtOr Project Management version 9.1.4 suffers from a remote shell upload vulnerability. Change Mirror Download # Exploit Title: ProjeQtOr Project Management 9.1.4 - Remote Code Execution# Date: 29.05.2021#...

Korenix CSRF / Backdoor Accounts / Command Injection / Missing Authentication

Authored by T. Weber | Site sec-consult.com Multiple Korenix products are affected by unauthenticated device administration, backdoor accounts, cross site request forgery, unauthenticated tftp actions, and command injection vulnerabilities. Products...

GetSimple CMS 3.3.4 Information Disclosure

Authored by Ron Jost GetSimple CMS version 3.3.4 suffers from an information disclosure vulnerability. advisories | CVE-2014-8722 Change Mirror Download # Exploit Title: GetSimple CMS 3.3.4 - Information Disclosure# Date 01.06.2021# Exploit Author:...