SEO Panel 4.8.0 SQL Injection
Authored by nu11secur1ty
SEO Panel version 4.8.0 remote blind SQL injection exploit. Original discovery in this version is attributed to Piyush Patil in February of 2021.
advisories | CVE-2021-28419
Change Mirror Download
#...
OpenPLC 3 Remote Code Execution
Authored by Fellipe Oliveira
OpenPLC version 3 authenticated remote code execution exploit.
Change Mirror Download
# Exploit Title: OpenPLC 3 - Remote Code Execution (Authenticated)# Date: 25/04/2021# Exploit Author: Fellipe Oliveira# Vendor...
Hasura GraphQL 1.3.3 Remote Code Execution
Authored by Dolev Farhi
Hasura GraphQL version 1.3.3 remote code execution exploit.
Change Mirror Download
# Exploit Title: Hasura GraphQL 1.3.3 - Remote Code Execution# Software: Hasura GraphQL# Software Link: https://github.com/hasura/graphql-engine# Version:...
Montiorr 1.7.6m Cross Site Scripting
Authored by Ahmad Shakla
Montiorr version 1.7.6m suffers from a cross site scripting vulnerability via a file upload.
Change Mirror Download
# Exploit Title: Montiorr 1.7.6m - File Upload to XSS# Date:...
Apache Druid 0.20.0 Remote Command Execution
Authored by Litch1, je5442804, Alibaba Cloud Security Team | Site metasploit.com
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests; however, that feature...
WordPress WPGraphQL 1.3.5 Denial Of Service
Authored by Dolev Farhi
WordPress WPGraphQL plugin version 1.3.5 suffers from a denial of service vulnerability.
Change Mirror Download
# Exploit Title: WordPress Plugin WPGraphQL 1.3.5 - Denial of Service # Author:...
VMware vRealize Operations Manager Server-Side Request Forgery / Code Execution
Authored by wvu, Egor Dimitrenko | Site metasploit.com
This Metasploit module exploits a pre-auth server-side request forgery (CVE-2021-21975) and post-auth file write (CVE-2021-21983) in VMware vRealize Operations Manager to leak...
GetSimple CMS My SMTP Contact 1.1.1 CSRF/ XSS / Code Execution
Authored by Bobby Cooke
GetSimple CMS My SMTP Contact plugin versions 1.1.1 and below cross site request forgery to persistent cross site scripting to remote code execution exploit.
Change Mirror Download
#...
Document Management System 1.0 SQL Injection / Remote Code Execution
Authored by Richard Jones
Document Management System version 1.0 remote SQL injection exploit that deploys a web shell.
Change Mirror Download
# Exploit Title: Document Management System - SQL Injection to RCE...
DzzOffice 2.02.1 Cross Site Scripting
Authored by nu11secur1ty
DzzOffice version 2.02.1 suffers from a cross site scripting vulnerability.
advisories | CVE-2021-3318
Change Mirror Download
# Exploit Title: XSS attack (app/setting) in DzzOffice-2.02.1# Author: @nu11secur1ty# Testing and Debugging: @nu11secur1ty,...





