Exploits & CVE's

Exploits Database – Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, CVEs and more.

Linux nf_tables Local Privilege Escalation

Authored by Notselwyn | Site github.com A use-after-free vulnerability exists in the Linux kernel netfilter: nf_tables component. This is a universal local privilege escalation proof of concept exploit working on...

ARIS: Business Process Management 10.0.21.0 Cross Site Scripting

Authored by Seid Yassin ARIS: Business Process Management version 10.0.21.0 suffers from a persistent cross site scripting vulnerability. Change Mirror Download # Exploit Title: Stored Cross-Site Scripting (XSS) in ARIS: BusinessProcess Management#...

WordPress Gutenberg 18.0.0 Cross Site Scripting

Authored by tmrswrr WordPress Gutenberg plugin version 18.0.0 suffers from a persistent cross site scripting vulnerability. Change Mirror Download ## Exploit Title: Wordpress Gutenberg Plugin Version 18.0.0 Stored XSS### Date: 2024-3-29### Exploit...

Packet Storm New Exploits For March, 2024

Authored by Todd J. | Site packetstormsecurity.com This archive contains all of the 137 exploits added to Packet Storm in March, 2024.

Dell Security Management Server Privilege Escalation

Authored by Amirhossein Bahramizadeh Dell Security Management Server versions prior to 11.9.0 suffer from a local privilege escalation vulnerability. advisories | CVE-2023-32479 Change Mirror Download # Exploit Title: Dell Security Management Server...

FusionPBX Session Fixation

Authored by Yogesh Bhandage FusionPBX suffers from a session fixation vulnerability. Change Mirror Download *Vulnerability Name - *Application is Vulnerable to Session Fixation*Vulnerable URL: *www.fusionpbx.com*Overview of the Vulnerability*Session fixation is a security...

Circontrol Raption Buffer Overflow / Command Injection

Authored by Dariusz Gonda, Abert Spruyt, Alex Salvetti The server in Circontrol Raption versions through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control...

util-linux wall Escape Sequence Injection

Authored by Skyler Ferrante The util-linux wall command does not filter escape sequences from command line arguments. The vulnerable code was introduced in commit cdd3cc7fa4 (2013). Every version since has...

Event Management 1.0 SQL Injection

Authored by SoSPiro Event Management version 1.0 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: Event Management - SQL Injection# Application: Event Management# Date: 19.02.2024# Bugs: SQL...

FoF Pretty Mail 1.1.2 Command Injection

Authored by Chokri Hammedi The FoF Pretty Mail extension version 1.1.2 for Flarum suffers from a command injection vulnerability. Change Mirror Download Exploit Title: FoF Pretty Mail 1.1.2 Extension for Flarum Command...