Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Podcast Generator 3.1 Cross Site Scripting

Authored by Aysenur Karaaslan Podcast Generator version 3.1 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Podcast Generator 3.1 - 'Long Description' Persistent Cross-Site Scripting (XSS)#...

Student Management System 1.0 Cross Site Scripting

Authored by Mohsen Khashei Student Management System version 1.0 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Student Management System 1.0 - 'message' Persistent Cross-Site Scripting...

Chrome Array Transfer Bypass

Authored by Google Security Research, Glazvunov The fix for CVE-2021-21148 has added a check in |ValueSerializer::WriteJSArrayBuffer| to make sure non-detachable array buffers cannot be transferred. The check can be bypassed...

ExifTool DjVu ANT Perl Injection

Authored by Justin Steven, William Bowling | Site metasploit.com This Metasploit module exploits a Perl injection vulnerability in the DjVu ANT parsing code of ExifTool versions 7.44 through 12.23 inclusive....

Windows Container Manager Service CmsRpcSrv_MapNamedPipeToContainer Privilege Escalation

Authored by James Forshaw, Google Security Research The Container Manager Service does not configure STORVSP correctly when opening mapped named pipes leading to privilege escalation. advisories | CVE-2021-31167

ZeroShell 3.9.0 Remote Command Execution

Authored by Fellipe Oliveira ZeroShell version 3.9.0 remote command execution exploit. advisories | CVE-2019-12725 Change Mirror Download # Exploit Title: ZeroShell 3.9.0 - Remote Command Execution # Google Dork: N/A# Date: 10/05/2021# Exploit...

Dental Clinic Appointment Reservation System 1.0 SQL Injection

Authored by Mesut Cetin Dental Clinic Appointment Reservation System version 1.0 suffers from multiple remote SQL injection vulnerabilities with one of them allowing for authentication bypass. Change Mirror Download # Exploit Title:...

Odoo 12.0.20190101 Unquoted Service Path

Authored by 1F98D Odoo version 12.0.20190101 suffers from an unquoted service path vulnerability. Change Mirror Download # Exploit Title: Odoo 12.0.20190101 - 'nssm.exe' Unquoted Service Path# Exploit Author: 1F98D# Vendor Homepage: https://www.odoo.com/#...

Splinterware System Scheduler Professional 5.30 Unquoted Service Path

Authored by Andrea Intilangelo Splinterware System Scheduler Professional version 5.30 suffers an unquoted service path vulnerability. Change Mirror Download # Exploit Title: Splinterware System Scheduler Professional 5.30 - Unquoted Service Path# Date:...

Android NFC nfa_rw_sys_disable Type Confusion

Authored by Google Security Research, nedwill Android NFC suffers from a type confusion vulnerability in nfa_rw_sys_disable.