Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Ruckus IoT Controller 1.5.1.0.21 Remote Code Execution

0
Authored by Emre Suren Ruckus IoT Controller (Ruckus vRIoT) versions 1.5.1.0.21 and below suffer from a remote code execution vulnerability. Change Mirror Download # Product: Ruckus IoT Controller (Ruckus vRIoT)# Version: <=...

Heroic Knowledge Base 3.0.1 Cross Site Scripting

0
Authored by begininvoke Heroic Knowledge Base plugin versions 3.0.1 and below suffer from persistent cross site scripting vulnerabilities. Change Mirror Download #Exploit Title : Heroic Knowledge Base Plugin <= 3.0.1 -...

Apache NiFi API Remote Code Execution

0
Authored by Graeme Robinson | Site metasploit.com This Metasploit module uses the NiFi API to create an ExecuteProcess processor that will execute OS commands. The API must be unsecured (or...

YATinyWinFTP Denial Of Service

0
Authored by strider YATinyWinFTP denial of service proof of concept exploit. Change Mirror Download # Exploit Title: YATinyWinFTP - Denial of Service (PoC)# Google Dork: None# Date: 20.08.2020# Exploit Author: strider# Vendor...

Laravel Administrator 4 File Upload

0
Authored by Xavi Beltran, Victor Campos Laravel Administrator version 4 suffers from an unrestricted file upload vulnerability. advisories | CVE-2020-10963 Change Mirror Download # Exploit title: Laravel Administrator 4 - Unrestricted File Upload...

WordPress Age Gate 2.13.4 Open Redirect

0
Authored by Ilca Lucian Florin WordPress Age Gate plugin versions 2.13.4 and below suffer fro an open redirection vulnerability. Change Mirror Download # Exploit Title: URL Redirection to Untrusted Site ('Open Redirect')...

WordPress Wibar Theme 1.1.8 Cross Site Scripting

0
Authored by Ilca Lucian Florin WordPress Wibar theme version 1.1.8 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Wordpress Theme Wibar 1.1.8 - 'Brand Component' Stored...

WordPress Accesspress Social Icons Theme 1.7.9 SQL Injection

0
Authored by SunCSR WordPress Accesspress Social Icons theme version 1.7.9 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: Wordpress Theme Accesspress Social Icons 1.7.9 - SQL injection...

WonderCMS 3.1.3 Cross Site Scripting

0
Authored by SunCSR WonderCMS version 3.1.3 suffers from a persistent cross site scripting vulnerability. Original finding for persistent cross site scripting in this version of WonderCMS is attributed to Hemant...

ZTE Blade Vantage Z839 Emode.APK android.uid.system Privilege Escalation

0
Authored by Hacker Fantastic ZTE Blade Vantage Z839 Emode.APK android.uid.system local privilege escalation exploit. Change Mirror Download ZTE Blade Vantage Z839 Emode.APK android.uid.system LPE exploit===============================================================ZTE Blade Vantage (Z839) Android handsets running 7.1.1...