Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

WordPress Video Gallery – YouTube Gallery And Vimeo Gallery 2.3.6 SQL Injection

Authored by tmrswrr | Site github.com WordPress Video Gallery - YouTube Gallery And Vimeo Gallery version 2.3.6 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: Wordpress Video...

Deep Sea Electronics DSE855 Remote Authentication Bypass

Authored by LiquidWorm | Site zeroscience.mk Deep Sea Electronics DSE855 is vulnerable to configuration disclosure when direct object reference is made to the Backup.bin file using an HTTP GET request....

Siemens CP-8000 / CP-8021 / CP8-022 / CP-8031 / CP-8050 / SICORE Buffer Overread...

Authored by Gerhard Hechenberger, Steffen Robertz, Constantin Schieber-Knoebl, Stefan Viehbock | Site sec-consult.com Siemens CP-8000, CP-8021, CP8-022, CP-8031, CP-8050, and SICORE products suffer from buffer overread, privilege escalation, and unsafe...

WordPress Photo Gallery 1.8.26 Cross Site Scripting

Authored by tmrswrr WordPress Photo Gallery plugin version 1.8.26 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Wordpress Photo Gallery Version 1.8.26 Stored XSS# Date: 2024-07-03#...

SoftMaker Office / FreeOffice Local Privilege Escalation

Authored by Michael Baer | Site sec-consult.com SoftMaker Office and FreeOffice suffer from a local privilege escalation vulnerability via the MSI installer. Vulnerable versions include SoftMaker Office 2024 / NX...

Xhibiter NFT Marketplace 1.10.2 SQL Injection

Authored by Sohel Yousef Xhibiter NFT Marketplace version 1.10.2 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: xhibiter nft marketplace SQLI# Google Dork: intitle:"View - Browse, create,...

WordPress WPCode Lite 2.1.14 Cross Site Scripting

Authored by tmrswrr WordPress WPCode Lite plugin version 2.1.14 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Wordpress WPCode Lite Version 2.1.14 Stored XSS# Date: 2024-06-30#...

Azon Dominator Affiliate Marketing Script SQL Injection

Authored by Buğra Enis Dönmez Azon Dominator Affiliate Marketing Script suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: Azon Dominator - Affiliate Marketing Script - SQL Injection#...

Simple Laboratory Management System 1.0 SQL Injection

Authored by Smitha Bhabal Simple Laboratory Management System version 1.0 suffers from a remote time-based SQL injection vulnerability. Change Mirror Download # Exploit Title: Simple Laboratory Management System - Manual Blind Time...

OpenSSH Server regreSSHion Remote Code Execution

Authored by Qualys Security Advisory | Site blog.qualys.com Qualys has discovered a a signal handler race condition vulnerability in OpenSSH's server, sshd. If a client does not authenticate within LoginGraceTime...