System Explorer 7.0.0 Unquoted Service Path
Authored by Mohammed Alshehri
System Explorer version 7.0.0 suffers from an unquoted service path vulnerability.
Change Mirror Download
# Exploit Title: System Explorer 7.0.0 - 'SystemExplorerHelpService' Unquoted Service Path# Date: 2020-10-14# Exploit...
Rumble Mail Server 0.51.3135 Cross Site Scripting
Authored by Mohammed Alshehri
Rumble Mail Server version 0.51.3135 suffers from multiple persistent cross site scripting vulnerabilities.
Change Mirror Download
# Exploit Title: Rumble Mail Server 0.51.3135 - 'servername' Stored XSS# Date:...
Macally WIFISD2-2A82 2.000.010 Privilege Escalation
Authored by Maximilian Barz, Daniel Schwendner
Macally WIFISD2-2A82 version 2.000.010 guest to root privilege escalation exploit.
advisories | CVE-2020-29669
Change Mirror Download
# Exploit Title: Macally WIFISD2-2A82 2.000.010 - Guest to Root Privilege...
LibreNMS 1.46 SQL Injection
Authored by Hodorsec
LibreNMS version 1.46 suffers from an authenticated remote SQL injection vulnerability in the MAC Account Graph. Original discovery of SQL injection in this version is attributed to...
usrsctp pending_reply_queue Out-Of-Bounds Access
Authored by Google Security Research, Felix Wilhelm
usrsctp suffers from a usrsctp pending_reply_queue out-of-bounds access vulnerability.
usrsctp HMAC Generation Out-Of-Bounds Access
Authored by Google Security Research, Felix Wilhelm
usrsctp suffers from insecure HMAC generation that can lead to out-of-bounds access.
Rukovoditel 2.6.1 Shell Upload / Local File Inclusion
Authored by coiffeur
Rukovoditel version 2.6.1 remote code execution exploit that leverages shell upload and local file inclusion vulnerabilities.
Change Mirror Download
# Exploit Title: Rukovoditel v2.6.1, RCE# Date: 2020-06-11# Exploit Author:...
Aerospike Database UDF Lua Code Execution
Authored by Brendan Coles, b4ny4n | Site metasploit.com
Aerospike Database versions before 5.1.0.3 permitted user-defined functions (UDF) to call the os.execute Lua function. This Metasploit module creates a UDF utilizing...
WordPress DirectoriesPro 1.3.45 Cross Site Scripting
Authored by Jack Misiura
WordPress DirectoriesPro plugin version 1.3.45 suffers from multiple cross site scripting vulnerabilities.
advisories | CVE-2020-29303, CVE-2020-29304
Change Mirror Download
Title: Reflected XSSProduct: WordPress DirectoriesPro Plugin by SabaiAppsVendor Homepage: https://directoriespro.com/Vulnerable...
OpenAsset Digital Asset Management IP Access Control Bypass
Authored by Jack Misiura
The OpenAsset Digital Asset Management web application allowed for spoofing of IP addresses by using X-Forwarded-For header. By default, the web application would allow all traffic...





