Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Kruxton 1.0 Shell Upload

0
Authored by nu11secur1ty Kruxton version 1.0 suffers from a remote shell upload vulnerability. Change Mirror Download ## Title: kruxton-1.0-FileUpload-RCE## Author: nu11secur1ty## Date: 04/15/2024## Vendor: https://www.mayurik.com/## Software: https://www.sourcecodester.com/php/16127/best-pos-management-system-php.html## Reference: https://portswigger.net/web-security/file-upload## Description:The system setting...

Terratec dmx_6fire USB 1.23.0.02 Unquoted Service Path

0
Authored by Joseph Kwabena Fiagbor Terratec dmx_6fire USB version 1.23.0.02 suffers from an unquoted service path vulnerability. advisories | CVE-2024-31804 Change Mirror Download # Exploit Title: Terratec dmx_6fire USB - Unquoted Service...

GitLens Git Local Configuration Execution

0
Authored by h00die, Paul Gerste | Site metasploit.com GitKraken GitLens versions prior to 14.0.0 allow an untrusted workspace to execute git commands. A repo may include its own .git folder...

Visual Studio Code Execution

0
Authored by h00die | Site metasploit.com This Metasploit module creates a vsix file which can be installed in Visual Studio Code as an extension. At activation/install, the extension will execute...

Amazon AWS Glue Database Password Disclosure

0
Authored by Michael Werner | Site sec-consult.com The password of database connections in AWS Glue is loaded into the website when a connection's edit page is requested. Principals with appropriate...

Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 Insecure Direct Object Reference

0
Authored by LiquidWorm | Site zeroscience.mk Elber Signum DVB-S/S2 IRD for Radio Networks version 1.999 suffers from an unauthenticated device configuration and client-side hidden functionality disclosure vulnerability. Change Mirror Download Elber Signum...

Ray OS 2.6.3 Command Injection

0
Authored by Fire_Wolf The Ray Project dashboard contains a CPU profiling page, and the format parameter is not validated before being inserted into a system command executed in a shell,...

Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 Authentication Bypass

0
Authored by LiquidWorm | Site zeroscience.mk Elber Cleber/3 Broadcast Multi-Purpose Platform version 1.0.0 suffers from an authentication bypass vulnerability through a direct and unauthorized access to the password management functionality....

Apache Solr Backup/Restore API Remote Code Execution

Authored by jheysel-r7, l3yx | Site metasploit.com Apache Solr versions 6.0.0 through 8.11.2 and versions 9.0.0 up to 9.4.1 are affected by an unrestricted file upload vulnerability which can result...

Elber Wayber Analog/Digital Audio STL 4.00 Insecure Direct Object Reference

0
Authored by LiquidWorm | Site zeroscience.mk Elber Wayber Analog/Digital Audio STL version 4.00 suffers from an unauthenticated device configuration and client-side hidden functionality disclosure vulnerability. Change Mirror Download Elber Wayber Analog/Digital Audio...
Error decoding the Instagram API json