Simple CRM 3.0 SQL Injection
Authored by Rinku Kumar
Simple CRM version 3.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Change Mirror Download
# Exploit Title: Simple CRM 3.0 - 'email' SQL...
Microsoft Windows Filtering Platform Token Access Check Privilege Escalation
Authored by James Forshaw, Google Security Research
The Windows Filtering Platform does not verify the token impersonation level when checking filters allowing the bypass of firewall rules leading to elevation...
WordPress Poll, Survey, Questionnaire And Voting System 1.5.2 SQL Injection
Authored by Toby Jackson
WordPress Poll, Survey, Questionnaire and Voting System plugin version 1.5.2 suffers from a blind remote SQL injection vulnerability.
Change Mirror Download
# Exploit Title: WordPress Plugin Poll, Survey,...
WordPress WP Google Maps 8.1.11 Cross Site Scripting
Authored by Mohammed Adam
WordPress WP Google Maps plugin version 8.1.11 suffers from a persistent cross site scripting vulnerability.
advisories | CVE-2021-24383
Change Mirror Download
# Exploit Title: WordPress Plugin WP Google Maps...
Monitorr 1.7.6m Bypass / Information Disclosure / Shell Upload
Authored by Alexandre Zanni
This ruby script is a 4-in-1 exploit that leverages shell upload, bypass, and information disclosure vulnerabilities in Monitorr version 1.7.6m.
advisories | CVE-2020-28871, CVE-2020-28872
Change Mirror Download
#!/usr/bin/env ruby#...
F5 BIG-IQ VE 8.0.0-2923215 Remote Root
Authored by Jeremy Brown
F5 BIG-IQ VE version 8.0.0-2923215 post-authentication remote root code execution exploit.
advisories | CVE-2021-23024
Change Mirror Download
F5 BIG-IQ VE v8.0.0-2923215 Post-auth Remote Root RCECVE-2021-23024=======Details=======It was possible to execute...
Cisco Modeling Labs 2.1.1-b19 Remote Command Execution
Authored by Jeremy Brown
Cisco Modeling Labs version 2.1.1-b19 remote command execution exploit.
advisories | CVE-2021-1531
Change Mirror Download
Cisco Modeling Labs 2.1.1-b19 Post-Auth RCE VulnerabilityCVE-2021-1531=======Details=======Authenticated command injection in the web portal via...
HPE RDA-CAS 1.23.826 Denial Of Service
Authored by Jeremy Brown
HPE RDA-CAS version 1.23.826 remote denial of service exploit.
Change Mirror Download
#!/usr/bin/python# -*- coding: UTF-8 -*-## hpfreeze.py## HPE Remote Device Access Unauthenticated Denial of Service## Jeremy Brown...
Websvn 2.6.0 Remote Code Execution
Authored by g0ldm45k
Websvn version 2.6.0 suffers from a remote code execution vulnerability.
advisories | CVE-2021-32305
Change Mirror Download
# Exploit Title: Websvn 2.6.0 - Remote Code Execution (Unauthenticated)# Date: 20/06/2021# Exploit Author:...
Dlink DSL2750U Command Injection
Authored by Mohammed Hadi
Dlink DSL2750U suffers from a reboot command injection vulnerability.
Change Mirror Download
# Exploit Title: Dlink DSL2750U - 'Reboot' Command Injection# Date: 17-06-2021# Exploit Author: Mohammed Hadi (HadiMed)#...





