Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Boxoft Audio Converter 2.3.0 Buffer Overflow

0
Authored by Luis Martinez Boxoft Audio Converter version 2.3.0 suffers from a buffer overflow vulnerability. Change Mirror Download # Exploit Title: Boxoft Audio Converter 2.3.0 - '.wav' Buffer Overflow (SEH)# Discovery by:...

TP-Link TL-WA855RE V5_200415 Device Reset Authentication Bypass

0
Authored by malwrforensics The TP-Link TL-WA855RE V5_200415 suffers from a flow where an unauthenticated attacker can reset the device and then set a new administrator password. Change Mirror Download # Exploit Title:...

LifeRay 7.2.1 GA2 Cross Site Scripting

0
Authored by 3ndG4me LifeRay version 7.2.1 GA2 suffers from a persistent cross site scripting vulnerability. advisories | CVE-2020-7934 Change Mirror Download # Exploit Title: LifeRay 7.2.1 GA2 - Stored XSS# Date: 10/05/2020 #...

Apache OpenMeetings 5.0.0 Denial Of Service

0
Authored by SunCSR Apache OpenMeetings version 5.0.0 suffers from a denial of service vulnerability. advisories | CVE-2020-13951 Change Mirror Download Exploit Title: Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service# Google Dork:...

nopCommerce Store 4.30 Cross Site Scripting

0
Authored by Hemant Patidar nopCommerce Store version 4.30 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting# Date: 24-11-2020#...

Vtiger CRM 7.0 Cross Site Scripting

0
Authored by Benjamin Kunz Mejri | Site vulnerability-lab.com Vtiger CRM version 7.0 suffers from a persistent cross site scripting vulnerability. Change Mirror Download Document Title:===============VTiger v7.0 CRM - (To) Persistent Email VulnerabilityReferences...

Barco wePresent Hardcoded API Credentials

0
Authored by Jim Becher | Site korelogic.com Barco wePresent device firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could...

Barco wePresent Admin Credential Exposure

0
Authored by Jim Becher | Site korelogic.com An attacker armed with hardcoded API credentials from KL-001-2020-004 (CVE-2020-28329) can issue an authenticated query to display the admin password for the main...

Barco wePresent Authentication Bypass

0
Authored by Jim Becher | Site korelogic.com The Barco wePresent WiPG-1600W version 2.5.1.8 web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a...

Barco wePresent Undocumented SSH Interface

0
Authored by Jim Becher | Site korelogic.com Barco wePresent WiPG-1600W version 2.5.1.8 has an SSH daemon included in the firmware image. By default, the SSH daemon is disabled and does...