Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Sentrifugo 3.2 Shell Upload / Restriction Bypass

0
Authored by Gurkirat Singh Sentrifugo version 3.2 suffers from a restriction bypass vulnerability that allows for a remote shell upload. advisories | CVE-2019-15813 Change Mirror Download # Exploit Title: Sentrifugo 3.2 - File...

TDM Digital Signage PC Player 4.1 Insecure File Permissions

0
Authored by LiquidWorm | Site zeroscience.mk TDM Digital Signage Windows Player version 4.1 suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that...

WordPress Colorbox Lightbox 1.1.1 Cross Site Scripting

0
Authored by n1x_ WordPress Colorbox Lightbox plugin version 1.1.1 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting...

Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization

0
Authored by Spencer McIntyre, Oleksandr Mirosh, Markus Wulftange, Alvaro Munoz, Paul Taylor, Caleb Gross, straightblast | Site metasploit.com This Metasploit module exploits the .NET deserialization vulnerability within the RadAsyncUpload (RAU)...

Hrsale 2.0.0 Local File Inclusion

0
Authored by Sosecure Hrsale version 2.0.0 suffers from a local file inclusion vulnerability. Change Mirror Download # Exploit Title: Hrsale 2.0.0 - Local File Inclusion# Date: 10/21/2020# Exploit Author: Sosecure# Vendor Homepage:...

School Faculty Scheduling System 1.0 Cross Site Scripting

0
Authored by Jyotsna Adhana School Faculty Scheduling System version 1.0 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: School Faculty Scheduling System 1.0 - Stored Cross...

School Faculty Scheduling System 1.0 SQL Injection

0
Authored by Jyotsna Adhana School Faculty Scheduling System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Change Mirror Download # Exploit Title: School Faculty Scheduling System...

GOautodial 4.0 Shell Upload

0
Authored by Balzabu GOautodial version 4.0 suffers from a remote shell upload vulnerability. Change Mirror Download # Exploit Title: GOautodial 4.0 - Authenticated Shell Upload# Author: Balzabu# Discovery Date: 07-23-2020# Vendor Homepage:...

Libtaxii 1.1.117 / OpenTaxi 0.2.0 Server-Side Request Forgery

0
Authored by Owais Mehtab, Vijay Kota Libtaxii versions 1.1.117 and below and OpenTaxi versions 0.2.0 and below suffer from a server-side request forgery vulnerability. advisories | CVE-2020-27197 Change Mirror Download Libtaxii version <=...

Tiki Wiki CMS Groupware 21.1 Authentication Bypass

0
Authored by Maximilian Barz Tiki Wiki CMS Groupware version 21.1 suffers from an authentication bypass vulnerability. advisories | CVE-2020-15906 Change Mirror Download # Exploit Title: Tiki Wiki CMS Groupware 21.1 - Authentication Bypass#...
Error decoding the Instagram API json