Library System 1.0 SQL Injection
Authored by Vinay Bhuria
Library System version 1.0 suffers from a remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to Aitor Herrero in January...
CMS Made Simple 2.1.3 Remote Code Execution
Authored by Raed Ahsan
CMS Made Simple version 2.1.3 details on how to achieve remote code execution.
Backdoor.Win32.Hupigon.afjk Directory Traversal
Authored by malvuln | Site malvuln.com
Backdoor.Win32.Hupigon.afjk malware suffers from a directory traversal vulnerability.
Change Mirror Download
Discovery / credits: Malvuln - malvuln.com (c) 2021Original source: https://malvuln.com/advisory/8dc8abc99c1e7908fe9d048a4e360960_B.txtContact: [email protected]: twitter.com/malvulnThreat: Backdoor.Win32.Hupigon.afjkVulnerability: Directory TraversalDescription:...
WordPress Wappointment 2.2.4 Cross Site Scripting
Authored by Renos Nikolaou
WordPress Wappointment plugin version 2.2.4 suffers from a persistent cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS)#...
Simple Attendance System 1.0 Authentication Bypass
Authored by Richard Jones
Simple Attendance System version 1.0 authentication bypass exploit that adds an administrator.
Change Mirror Download
# Exploit Title: Simple Attendance System v1.0 - Unauthenticated Add Admin Account# Exploit...
iOS 15.0 Gamed Information Disclosure
Authored by IllusionOfChaos | Site github.com
Zero day exploit for Gamed on iOS 15.0 that demonstrates information disclosure vulnerabilities.
iOS 15.0 nehelper Enumeration
Authored by IllusionOfChaos | Site github.com
Zero day exploit for nehelper on iOS 15.0 that allows any user-installed application to determine whether any application is installed on the device given...
iOS 15.0 Nehelper Wifi Info Entitlement Check Bypass
Authored by IllusionOfChaos | Site github.com
Zero day exploit for Nehelper Wifi Info on iOS 15.0. XPC endpoint com.apple.nehelper accepts user-supplied parameter sdk-version, and if its value is less than...
WordPress Fitness Calculators 1.9.5 Cross Site Request Forgery
Authored by 0xB9
WordPress Fitness Calculators plugin version 1.9.5 suffers from a cross site request forgery vulnerability.
advisories | CVE-2021-24272
Change Mirror Download
# Exploit Title: WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site...
WordPress Advanced Order Export For WooCommerce 3.1.7 Cross Site Scripting
Authored by 0xB9
WordPress Advanced Order Export For WooCommerce plugin version 3.1.7 suffers from a cross site scripting vulnerability.
advisories | CVE-2021-24169
Change Mirror Download
# Exploit Title: WordPress Plugin Advanced Order Export...