- [local] - BlazeDVD Pro 7.0 - (.plf) Stack Based Buffer Overflow (Direct RET)
- [webapps] - HybridAuth 2.2.2 - Remote Code Execution
- [local] - VirtualBox Guest Additions VBoxGuest.sys Privilege Escalation
- [local exploits] - BlazeDVD Pro 7.0 - (.plf) Stack Based Buffer Overflow (Direct RET)
- [local exploits] - VirtualBox Guest Additions VBoxGuest.sys Privilege Escalation Expl
- [web applications] - Ribose Cross Site Request Forgery Vulnerability
- [web applications] - Disqus 2.7.5 Cross Site Request Forgery / Cross Site Scripting
- [web applications] - Jamroom 5.2.6 Cross Site Scripting Vulnerability
- [remote] - VMTurbo Operations Manager 4.6 vmtadmin.cgi Remote Command Execution
- [webapps] - Disqus for Wordpress 2.7.5 Admin Stored CSRF and XSS
- [web applications] - BlackBerry Z10 Authentication Bypass Vulnerability
- [web applications] - TomatoCart 1.x - SQL Injection Vulnerability
- [web applications] - HybridAuth 2.2.2 - Remote Code Execution Vulnerability
- [remote exploits] - VirtualBox 3D Acceleration Virtual Machine Escape Exploit
- [remote exploits] - VMTurbo Operations Manager 4.6 vmtadmin.cgi Remote Command Execut
- [remote] - VirtualBox 3D Acceleration Virtual Machine Escape
- [web applications] - MyConnection Server (MCS) 9.7i Cross Site Scripting Vulnerabilit
- [web applications] - Lyris ListManagerWeb 8.95a Cross Site Scripting Vulnerability
- [web applications] - Wordpress Gallery Objects 0.4 SQL Injection Vulnerability
- [web applications] - Facebook - Account***039;s Phone Number Brute-Force
- [webapps] - Tenda A5s Router 3.02.05_CN - Authentication Bypass Vulnerability
- [webapps] - Feng Office - Stored XSS
- [remote exploits] - Gitlab-shell Code Execution Exploit
- [web applications] - Tenda A5s Router Authentication Bypass
- [remote exploits] - Firefox toString console.time Privileged Javascript Injection
- [remote exploits] - Senkas Kolibri WebServer 2.0 Buffer Overflow Exploit
- [web applications] - Udemy Paid Courses Bypasser - Downloader
- [local exploits] - BlazeDVD Pro v7.0 - (.plf) Buffer Overflow SEH Exploit
- [local exploits] - BulletProof FTP Client 2010 - Buffer Overflow (SEH) Exploit
- [remote] - Gitlab-shell Code Execution
- [remote] - Firefox toString console.time Privileged Javascript Injection
- [remote exploits] - Firefox toString console.time Privileged Javascript Injection Exp
- [local exploits] - BlazeDVD Pro v7.0 - (.plf) Buffer Overflow (SEH) Exploit
- [remote exploits] - HybridAuth install.php PHP Code Execution Exploit
- [web applications] - ArticleFR 3.0.4 SQL Injection Vulnerability
- [remote exploits] - ManageEngine Desktop Central / Password Manager Pro / IT360 SQL I
- [webapps] - MyBB 1.8 Beta 3 - Multiple Vulnerabilities
- [remote] - HybridAuth install.php PHP Code Execution
- [web applications] - MyBB 1.8 Beta 3 - Cross Site Scripting & SQL Injection Vulnerabi
- [remote exploits] - ManageEngine Password Manager MetadataServlet.dat SQL Injection E
- [web applications] - Dashing Times SQL Injection Vulnerability
- [web applications] - CMS Agencija O2 Cross Site Scripting / SQL Injection Vulnerabili
- [web applications] - Innovaphone PBX Cross Site Request Forgery Vulnerability
- [remote] - Air Transfer Iphone 1.3.9 - Multiple Vulnerabilities
- [local] - BlazeDVD Pro 7.0 (.plf) - Buffer Overflow (SEH)
- [remote exploits] - Air Transfer Iphone 1.3.9 Multiple Vulnerabilities
- [dos / poc] - Baidu Spark Browser v26.5.9999.3511 Remote Stack Overflow DoS
- [remote exploits] - IBM 1754 GCM KVM Multiple Vulnerabilities
- [webapps] - ManageEngine Password Manager MetadataServlet.dat SQL Injection
- [webapps] - Innovaphone PBX Admin-GUI - CSRF Vulnerability
- [webapps] - VTLS Virtua InfoStation.cgi - SQL Injection
- [webapps] - ntopng 1.2.0 - XSS Injection
- [web applications] - ntopng 1.2.0 - XSS Vulnerability
- [web applications] - VTLS Virtua InfoStation.cgi - SQL Injection Vulnerability
- [web applications] - Innovaphone PBX Admin-GUI - CSRF Vulnerability
- [web applications] - ManageEngine Password Manager MetadataServlet.dat SQL Injection
- [remote exploits] - vampir.mobi SQL injection Vulnerability (100k people)
- [web applications] - WordPress Plugin KenBurner Slider Arbitrary File Download Vulner
- [remote exploits] - Dragonfly 1.0.5 Remote Code Execution Exploit
- [local] - glibc Off-by-One NUL Byte gconv_translit_find Exploit
- [webapps] - WooCommerce Store Exporter 1.7.5 - SXSS and RXSS
- [web applications] - WooCommerce Store Exporter 1.7.5 - Multiple XSS Vulnerabilities
- [local exploits] - glibc Off-by-One NUL Byte gconv_translit_find Exploit
- [local exploits] - HTML Help Workshop 1.4 - (SEH) Buffer Overflow
- [remote exploits] - Wing FTP Server Authenticated Command Execution Exploit
- [remote exploits] - NRPE 2.15 - Remote Code Execution Vulnerability
- [dos / poc] - Internet Explorer MS14-029 Memory Corruption PoC
- [web applications] - WordPress ShortCode Plugin 1.1 - Local File Inclusion Vulnerabil
- [web applications] - Plogger 1.0-RC1 - Authenticated Arbitrary File Upload Exploit
- [web applications] - ManageEngine DeviceExpert 5.9 - User Credential Disclosure
- [web applications] - ActualAnalyzer Lite 2.81 - Unauthenticated Command Execution Exp
- [web applications] - PhpWiki - Remote Command Execution Exploit
- [web applications] - XRMS - Blind SQL Injection and Command Execution Exploit
- [remote exploits] - Firefox WebIDL Privileged Javascript Injection Exploit
- [dos] - HTML Help Workshop 1.4 - (SEH) Buffer Overflow
- [remote] - NRPE 2.15 - Remote Code Execution Vulnerability
- [remote] - F5 Big-IP - Unauthenticated rsync Access
- [dos] - Internet Explorer MS14-029 Memory Corruption PoC
- [webapps] - XRMS - Blind SQL Injection and Command Execution
- [webapps] - PhpWiki - Remote Command Execution
- [webapps] - ActualAnalyzer Lite 2.81 - Unauthenticated Command Execution
- [webapps] - ManageEngine DeviceExpert 5.9 - User Credential Disclosure
- [remote] - Firefox WebIDL Privileged Javascript Injection
- [webapps] - Plogger 1.0-RC1 - Authenticated Arbitrary File Upload
- [webapps] - ManageEngine EventLog Analyzer Multiple Vulnerabilities
- [webapps] - ManageEngine Desktop Central - Arbitrary File Upload / RCE
- [remote] - Wing FTP Server Authenticated Command Execution
- [papers] - Outsmarted - Why Malware Works in face of Antivirus Software
- [papers] - [Spanish] Design and Implementation of a Voice Encryption System for Telep
- [webapps] - WordPress Slideshow Gallery Plugin 1.4.6 - Shell Upload Vulnerability
- [webapps] - Arachni Web Application Scanner Web UI - Stored XSS Vulnerability
- [webapps] - Mulitple WordPress Themes (admin-ajax.php, img param) - Arbitrary File Do
- [web applications] - WordPress FR0_theme theme Arbitrary File Download Vulnerability
- [web applications] - WordPress lote27 theme Arbitrary File Download Vulnerability
- [web applications] - WordPress NativeChurch theme Arbitrary File Download Vulnerabili
- [web applications] - WordPress acento theme Arbitrary File Download Vulnerability
- [web applications] - WordPress CuckooTap Theme & eShop Arbitrary File Download
- [web applications] - WordPress Slideshow Gallery Plugin 1.4.6 - Shell Upload Vulnerab
- [web applications] - Arachni Web Application Scanner Web UI - Stored XSS Vulnerabilit
- [web applications] - ManageEngine Desktop Central - Arbitrary File Upload / RCE Vulne
- [web applications] - ManageEngine EventLog Analyzer Multiple Vulnerabilities
- [web applications] - Facebook - Logout your friends Vulnerability
- [web applications] - Wordpress Huge-IT Image Gallery 1.0.1 Authenticated SQL Injectio
- [webapps] - Wordpress Huge-IT Image Gallery 1.0.1 Authenticated SQL Injection
- [webapps] - vBulletin 4.0.x - 4.1.2 (search.php, cat param) - SQL Injection Exploit
- [web applications] - Easy Forms for vBulletin 4.X - Upload Shell Code / Remote Code E
- [remote exploits] - Exploit firefox cache & Anonymous mode cache bypass (all OS)
- [remote exploits] - vBulletin 4.0.x => 4.1.2 Automatic SQL Injection exploit
- [remote exploits] - LeapFTP 3.1.0 URL Handling Buffer Overflow Exploit
- [web applications] - Subex ROC Fraud Management System 7.4 SQL Injection Vulnerabilit
- [web applications] - JQuery 1.4.2 Cross Site Scripting Vulnerability
- [web applications] - LogAnalyzer 3.6.5 Cross Site Scripting Vulnerability
- [dos / poc] - WWW File Share Pro 7.0 Denial Of Service Exploit
- [local exploits] - Apple iOS 7.1.2 Merge Apps Service Local Bypass Vulnerability
- [remote exploits] - Android Browser Same Origin Policy Bypass Vulnerability
- [remote exploits] - Google Chrome 31.0 XSS Auditor Bypass Vulnerability
- [remote exploits] - Firefox
- [web applications] - phpMyFAQ 2.8.X - Multiple Vulnerabilities
- [web applications] - BlackCat CMS 1.0.3 Cross Site Scripting Vulnerability
- [web applications] - MyWebSQL 3.4 Cross Site Scripting Vulnerability
- [web applications] - Jenkins 1.578 Cross Site Request Forgery / Command Execution
- [web applications] - Mpay24 Payment Module 1.5 Information Disclosure / SQL Injection
- [web applications] - WordPress Advanced Access Manager 2.8.2 File Write / Code Execut
- [remote exploits] - Oracle NUMTODSINTERVAL() Buffer Overflow Exploit
- [web applications] - IP Board 3.x CSRF - Token hjiacking Vulnerability
- [webapps] - Wordpress Plugins Premium Gallery Manager Unauthenticated Configuration A
- [web applications] - Wordpress Like Dislike Counter Plugin SQL Injection Vulnerabilit
- [web applications] - Wordpress Spider Facebook 1.0.8 Authenticated SQL Injection Vuln
- [web applications] - vBulletin 5.1.X - Cross Site Scripting Vulnerability
- [web applications] - Wordpress Plugins Premium Gallery Manager Unauthenticated Config
- [web applications] - WordPress The Retailer theme Arbitrary File Download Vulnerabili
- [web applications] - MyBB User Social Networks Plugin 1.2 - Stored XSS Vulnerability
- [local exploits] - BulletProof FTP Client 2010 - Buffer Overflow (SEH) Exploit
- [local] - BulletProof FTP Client 2010 - Buffer Overflow (SEH) Exploit
- [webapps] - MyBB User Social Networks Plugin 1.2 - Stored XSS
- [remote exploits] - ManageEngine Desktop Central StatusUpdate Arbitrary File Upload E
- [web applications] - Joomla Spider Calendar
- [local] - HTML Help Workshop 1.4 - Local Buffer Overflow Exploit (SEH)
- [webapps] - IP Board 3.x - CSRF Token hjiacking
- [webapps] - Syslog LogAnalyzer 3.6.5 - Stored XSS (Python Exploit)
- [webapps] - PHP Stock Management System 1.02 - Multiple Persistent Cross Site Scripti
- [webapps] - Wordpress Bulk Delete Users by Email Plugin 1.0 - CSRF
- [webapps] - Joomla Spider Calendar
- [webapps] - PhpOnlineChat 3.0 - XSS
- [webapps] - Wordpress Like Dislike Counter 1.2.3 Plugin - SQL Injection Vulnerability
- [webapps] - LoadedCommerce7 - Systemic Query Factory Vulnerability
- [web applications] - PHP Stock Management System 1.02 - Multiple Persistent Cross Sit
- [web applications] - Syslog LogAnalyzer 3.6.5 - Stored XSS Exploit
- [web applications] - LoadedCommerce7 - Systemic Query Factory Vulnerability
- [web applications] - PhpOnlineChat 3.0 - XSS Vulnerability
- [web applications] - Wordpress Bulk Delete Users by Email Plugin 1.0 - CSRF Vulnerabi
- [webapps] - Mpay24 PrestaShop Payment Module 1.5 - Multiple Vulnerabilities
- [webapps] - WordPress Acento Theme (view-pdf.php, file param) - Arbitrary File Downlo
- [webapps] - Jenkins 1.578 - Multiple Vulnerabilities
- [remote exploits] - Elastix PBX 2.x.x Remote Command Execution 0day Exploit
- [shellcode] - Obfuscated Shellcode Linux x86 - chmod 777 (/etc/passwd + /etc/shadow)
- [papers] - Breaking the Sandbox
- [dos] - PHP Stock Management System 1.02 - Multiple Vulnerabilty
- [webapps] - TP-LINK Model No. TL-WR841N / TL-WR841ND - Multiple Vulnerabilities
- [webapps] - TP-LINK Model No. TL-WR340G / TL-WR340GD - Multiple Vulnerabilities
- [webapps] - osCommerce 2.3.4 - Multiple vulnerabilities
- [remote] - ALCASAR 2.8 Remote Root Code Execution Vulnerability
- [webapps] - Atmail Webmail 7.2 - Multiple Vulnerabilities
- [remote] - ManageEngine Desktop Central StatusUpdate Arbitrary File Upload
- [remote exploits] - GDB Server Remote Payload Execution Exploit
- [web applications] - TNG Sitebuilding v. 10.0.3 - Admin Panel Motion Logs Downloader
- [web applications] - PHP Stock Management System 1.02 - Multiple Vulnerabilty
- [shellcode] - linux/x86 - chmod 777 (/etc/passwd + /etc/shadow) & Add New Root User &
- [remote exploits] - ALCASAR 2.8 Remote Root Code Execution Exploit
- [web applications] - WordPress Urban City Arbitrary File Download Vulnerability
- [web applications] - WordPress Epic Arbitrary File Download Vulnerability
- [web applications] - WordPress Authentic Arbitrary File Download Vulnerability
- [web applications] - WordPress Antioch Arbitrary File Download Vulnerability
- [webapps] - Wordpress WP Support Plus Responsive Ticket System 2.0 Plugin - Multiple
- [web applications] - Wordpress shorttermbraces theme Arbitrary File Download Vulnerab
- [web applications] - WordPress Trinity theme Arbitrary File Download Vulnerability
- [web applications] - WordPress striking_r2 Arbitrary File Download Vulnerability
- [web applications] - Joomla Spider Contacts
- [web applications] - WordPress MichaelCanthony theme Arbitrary File Download Vulnerab
- [web applications] - Wordpress Support Plus Responsive Ticket System 2.0 Plugin - Mul
- [web applications] - OroCRM - Stored XSS Vulnerability
- [web applications] - WordPress felis theme Arbitrary File Download Vulnerability
- [webapps] - ChatSecure IM 2.2.4 iOS - Persistent XSS Vulnerability
- [webapps] - Photorange 1.0 iOS - File Inclusion Vulnerability
- [webapps] - Joomla Spider Contacts 1.3.6 (index.php, contacts_id param) - SQL Injecti
- [webapps] - OroCRM - Stored XSS Vulnerability
- [remote exploits] - Oracle GENERATESCHEMA Buffer Overflow Exploit
- [web applications] - WordPress TheLoft Theme Arbitrary File Download Vulnerability
- [web applications] - WordPress core theme Arbitrary File Download Vulnerability
- [web applications] - WordPress eboard theme Arbitrary File Download
- [remote exploits] - SolarWinds Storage Manager Authentication Bypass Exploit
- [remote exploits] - ManageEngine Eventlog Analyzer Arbitrary File Upload Exploit
- [remote exploits] - Railo 4.2.1 Remote File Inclusion Exploit
- [web applications] - Joomla Spider Form Maker
- [web applications] - WordPress SMWF Theme Arbitrary File Download Vulnerability
- [web applications] - WordPress Markant Theme Arbitrary File Download Vulnerability
- [web applications] - WordPress yakimabait Theme Arbitrary File Download Vulnerability
- [remote exploits] - Internet Explorer 11 Remote Code Execution 0day Exploit
- [remote exploits] - HttpFileServer 2.3.x Remote Command Execution Vulnerability
- [remote exploits] - Rooted SSH/SFTP Daemon Default Login Credentials
- [remote exploits] - Booter Website Remote Root Exploit
- [web applications] - EGYWEB (Mantrac)
- [webapps] - ALCASAR
- [webapps] - CacheGuard-OS 5.7.7 - CSRF Vulnerability
- [remote] - SolarWinds Storage Manager Authentication Bypass
- [remote] - ManageEngine Eventlog Analyzer Arbitrary File Upload
- [remote] - Railo Remote File Include
- [remote] - Http File Server 2.3.x - Remote Command Execution
- [web applications] - ALCASAR
- [web applications] - CacheGuard-OS 5.7.7 - CSRF Vulnerability
- [webapps] - USB&WiFi Flash Drive 1.3 iOS - Code Execution Vulnerability
- [web applications] - Phpwiki Ploticus Remote Code Execution Exploit
- [web applications] - Wordpress Webcam 2Way Videochat Plagin XSS Vulnerability
- [web applications] - Wordpress Plugin FormCraft Premium Arbitrary File Deletion
- [web applications] - ZTE ZXDSL-931VII Unauthenticated Configuration Dump
- [remote exploits] - Safari SVGPathSegList Use-After-Free Exploit
- [web applications] - WordPress Theme Marble Arbitrary File Download Vulnerability
- [web applications] - WordPress Theme LaBomba Arbitrary File Download Vulnerability
- [webapps] - Briefcase 4.0 iOS - Code Execution & File Include Vulnerability
- [web applications] - MODX Revolution 2.3.1-pl Cross Site Scripting Vulnerability
- [web applications] - webEdition 6.3.8.0 Path Traversal Vulnerability
- [web applications] - WordPress WP-Ban 1.62 Bypass Vulnerability
- [web applications] - WordPress Login Widget With Shortcode 3.1.1 CSRF / XSS
- [web applications] - WordPress Theme !LesPaul Arbitrary File Download Vulnerability
- [web applications] - WordPress Plugin Max Banner Ads XSS Vulnerablity
- [web applications] - WordPress Plugin Sticky Social Bar XSS Vulnerablity
- [web applications] - WordPress Theme Jupiter Arbitrary File Download Vulnerability
- [web applications] - WordPress Theme Forall Arbitrary File Download Vulnerability
- [web applications] - WordPress Theme X Arbitrary File Download Vulnerability
- [web applications] - WordPress Theme Celestial-Lite Arbitrary File Download Vulnerabi
- [web applications] - WordPress Theme Centum Arbitrary File Download Vulnerability
- [web applications] - WordPress Theme 3clicks Arbitrary File Download Vulnerability
- [web applications] - WordPress 0day - Hades Plus Framework Add Administrator
- [web applications] - WordPress Login Widget With Shortcode 3.1.1 CSRF / XSS Vulnerabi
- [web applications] - WordPress Theme Konzept Arbitrary File Upload Vulnerability
- [web applications] - GetSimpleCMS PHP File Upload Exploit
- [web applications] - M/Monit 3.2.2 Cross Site Request Forgery Vulnerability
- [web applications] - Wordpress Plugin CSSJockey Membership Modules Code Execution Vul
- [dos] - Seafile-server
- [webapps] - ClassApps SelectSurvey.net - Multiple SQL Injection Vulnerabilities
- [webapps] - Livefyre LiveComments Plugin - Stored XSS
- [web applications] - ClassApps SelectSurvey.net - Multiple SQL Injection Vulnerabilit
- [dos / poc] - Seafile-server
- [web applications] - Livefyre LiveComments Plugin - Stored XSS Vulnerability
- [web applications] - Wordpress Theme Strange File Upload / File Deletion
- [web applications] - Joomla Face Gallery 1.0 Multiple Vulnerabilities
- [web applications] - Joomla Mac Gallery
- [web applications] - Wordpress jQuery mOover Admin Bypass Vulnerability
- [webapps] - LittleSite 0.1 'file' Parameter Local File Include Vulnerability
- [dos] - Fast Image Resizer 098 - Local Crash Poc