Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Sitefinity 15.0 Cross Site Scripting

Authored by Aldi Saputra Wahyudi Sitefinity version 15.0 suffers from a persistent cross site scripting vulnerability. advisories | CVE-2023-27636 Change Mirror Download # Exploit Title: Sitefinity 15.0 - Cross-Site Scripting (XSS)# Date: 2023-12-05#...

FreePBX 16 Remote Code Execution

Authored by Cold z3ro FreePBX suffers from a remote code execution vulnerability. Versions 14, 15, and 16 are all affected. Change Mirror Download # Exploit Title: FreePBX 16 - Remote Code...

Employee And Visitor Gate Pass Logging System 1.0 SQL Injection

Authored by Furkan Eren Tetik Employee and Visitor Gate Pass Logging System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Change Mirror Download # Exploit Title:...

WBCE CMS 1.6.2 Remote Code Execution

Authored by Ahmet Umit Bayram WBCE CME version 1.6.2 suffers from a remote code execution vulnerability. Change Mirror Download # Exploit Title: WBCE CMS v1.6.2 - Remote Code Execution (RCE)# Date: 3/5/2024#...

Akaunting 3.1.8 Server-Side Template Injection

Authored by tmrswrr Akaunting version 3.1.8 suffers from a server-side template injection vulnerability. Change Mirror Download # Exploit Title: Akaunting 3.1.8 - Server-Side Template Injection (SSTI)# Exploit Author: tmrswrr# Date: 30/05/2024# Vendor:...

Akaunting 3.1.8 Client-Side Template Injection

Authored by tmrswrr Akaunting version 3.1.8 suffers from a client-side template injection vulnerability. Change Mirror Download # Exploit Title: Akaunting 3.1.8 - Client Side Template Injection CSTI# Exploit Author: tmrswrr# Date: 30/05/2024#...

Progress Flowmon 12.3.5 Local sudo Privilege Escalation

Authored by Dave Yesland | Site metasploit.com This Metasploit module abuses a feature of the sudo command on Progress Flowmon. Certain binary files are allowed to automatically elevate with the...

Aquatronica Control System 5.1.6 Password Disclosure

Authored by LiquidWorm | Site zeroscience.mk Aquatronica Control System version 5.1.6 has a tcp.php endpoint on the controller that is exposed to unauthenticated attackers over the network. This vulnerability allows...

Check Point Security Gateway Information Disclosure

Authored by Yesith Alvarez Check Point Security Gateway suffers from an information disclosure vulnerability. Versions affected include R77.20 (EOL), R77.30 (EOL), R80.10 (EOL), R80.20 (EOL), R80.20.x, R80.20SP (EOL), R80.30 (EOL),...

iMLog Cross Site Scripting

Authored by Gabriel Felipe iMLog versions prior to 1.307 suffer from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: iMLog < 1.307 - Persistent Cross Site Scripting (XSS)#...