- [papers] Rootkit analysis - Use case on HideDRV
- [webapps] Spring Data REST < 2.6.9 (Ingalls SR9), 3.0.1 (Kay SR1) - PATCH Request Rem
- [webapps] WordPress Plugin Duplicator 1.2.32 - Cross-Site Scripting
- [remote] MikroTik RouterOS < 6.41.3/6.42rc27 - SMB Buffer Overflow
- [remote] SAP NetWeaver AS JAVA CRM - Log injection Remote Command Execution
- [dos] Android DRM Services - Buffer Overflow
- [remote] Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
- [remote] Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
- [webapps] Contec Smart Home 4.15 - Unauthorized Password Reset
- [papers] Analyze & Attack SSH Protocol
- [local] Huawei Mate 7 - '/dev/hifi_misc' Privilege Escalation
- [dos] Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
- [dos] Linux Kernel - 'mincore()' Heap Page Disclosure (PoC)
- [local] Linux Kernel 4.13 (Debian 9) - Local Privilege Escalation
- [local] Linux Kernel < 3.16.39 (Debian 8 x64) - 'inotfiy' Local Privilege Escalation
- [dos] Linux Kernel < 4.5.1 - Off-By-One (PoC)
- [local] Linux Kernel < 4.4.0-21 (Ubuntu 16.04 x64) - 'netfilter target_offset' Local
- [local] Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local
- [local] Linux Kernel < 4.4.0-116 (Ubuntu 16.04.4) - Local Privilege Escalation
- [papers] Analyze & Attack SSH Protocol
- [dos] Microsoft Windows Kernel - 'NtQueryVirtualMemory(MemoryMappedFilenameInformat io
- [local] Google Software Updater macOS - Unsafe use of Distributed Objects Privilege E
- [dos] Kamailio 5.1.1 / 5.1.0 / 5.0.0 - Off-by-One Heap Overflow
- [local] Microsoft Windows - Desktop Bridge Virtual Registry NtLoadKey Arbitrary File
- [local] Microsoft Windows - Desktop Bridge Virtual Registry Arbitrary File Read/Write
- [local] Microsoft Windows - Desktop Bridge VFS Privilege Escalation
- [dos] Internet Explorer - 'RegExp.lastMatch' Memory Disclosure
- [dos] Microsoft Windows Kernel - 'nt!NtWaitForDebugEvent' 64-bit Stack Memory Disclos
- [dos] Microsoft Windows Kernel - 'nt!KiDispatchException' 64-bit Stack Memory Disclos
- [dos] Microsoft Windows Kernel - 'NtQueryInformationThread(ThreadBasicInformation)' 6
- [webapps] Intelbras Telefone IP TIP200 LITE - Local File Disclosure
- [webapps] Vehicle Sales Management System - Multiple Vulnerabilities
- [shellcode] Linux/x86 - execve(/bin/sh) Shellcode (18 bytes)
- [papers] Web Application Security Testing
- [webapps] Cisco node-jos < 0.11.0 - Re-sign Tokens
- [papers] Windows Kernel Exploitation Tutorial Part 7: Uninitialized Heap Variable
- [papers] Windows Kernel Exploitation Tutorial Part 6: Uninitialized Stack Variable
- [local] Linux Kernel < 4.15.4 - 'show_floppy' KASLR Address Leak
- [dos] Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
- [dos] Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
- [webapps] Hikvision IP Camera versions 5.2.0 - 5.3.9 (Builds 140721 - 170109) - Acces
- [shellcode] Linux/x86 - EggHunter Shellcode (11 Bytes)
- [dos] WM Recorder 16.8.1 - Denial of Service
- [dos] Dell EMC NetWorker - Denial of Service
- [local] Crashmail 1.6 - Stack-Based Buffer Overflow ( ROP execve )
- [local] Allok Quicktime to AVI MPEG DVD Converter 4.6.1217 - Stack-Based Buffer Overf
- [webapps] 3CX Phone System < 12.5 - Remote Code Execution
- [webapps] Wordpress Plugin Site Editor 1.1.1 - Local File Inclusion
- [webapps] MyBB Plugin Last User's Threads in Profile Plugin 1.2 - Persistent Cross-Si
- [dos] Easy Avi Divx Xvid to DVD Burner 2.9.11 - '.avi' Denial of Service
- [local] Easy CD DVD Copy 1.3.24 - Local Buffer Overflow (SEH)
- [webapps] XenForo 2 - CSS Loader Denial of Service
- [webapps] TL-WR720N 150Mbps Wireless N Router - Cross-Site Request Forgery
- [local] LabF nfsAxe 3.7 - Privilege Escalation
- [webapps] Laravel Log Viewer < 0.13.0 - Local File Download
- [local] Fast AVI MPEG Splitter 1.2 - Stack-Based Buffer Overflow
- [papers] Cross Site Scripting in a Nutshell
- [remote] Acrolinx Server < 5.2.5 - Directory Traversal
- [webapps] ClipBucket - beats_uploader Unauthenticated Arbitrary File Upload (Metasplo
- [remote] TestLink Open Source Test Management < 1.9.16 - Remote Code Execution (PoC)
- [papers] Error based SQL Injection in "Order By" clause (MSSQL)
- [papers] DOSfuscation: Exploring the Depths of Cmd.exe Obfuscation and Detection Tech
- [webapps] Open-AuditIT Professional 2.1 - Cross-Site Scripting
- [webapps] Tenda N11 Wireless Router 5.07.43_en_NEX01 - Remote DNS Change
- [webapps] Microsoft Windows Remote Assistance - XML External Entity Injection
- [webapps] TwonkyMedia Server 7.0.11-8.5 - Persistent Cross-Site Scripting
- [webapps] TwonkyMedia Server 7.0.11-8.5 - Directory Traversal
- [papers] Error based SQL Injection in "Order By" clause (MSSQL)
- [papers] DOSfuscation: Exploring the Depths of Cmd.exe Obfuscation and Detection Tech
- [webapps] Joomla Component Fields - SQLi Remote Code Execution (Metasploit)
- [remote] Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)
- [remote] GitStack - Unsanitized Argument Remote Code Execution (Metasploit)
- [webapps] Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)
- [papers] Sony Playstation 4 (PS4) - PS4 4.55 BPF Race Condition Kernel Exploit Writeu
- [webapps] MiniCMS 1.10 - Cross-Site Request Forgery
- [webapps] Homematic CCU2 2.29.23 - Arbitrary File Write
- [webapps] Open-AuditIT Professional 2.1 - Cross-Site Request Forgery
- [webapps] Wordpress Plugin Contact Form 7 to Database Extension 2.10.32 - CSV Injecti
- [webapps] Wordpress Plugin Relevanssi 4.0.4 - Reflected Cross-Site Scripting
- [local] Allok WMV to AVI MPEG DVD WMV Converter 4.6.1217 - Buffer Overflow
- [local] Allok Video Joiner 4.6.1217 - Stack-Based Buffer Overflow
- [local] Allok AVI DivX MPEG to DVD Converter 2.6.1217 - Buffer Overflow (SEH)
- [webapps] WordPress Plugin WP Security Audit Log 3.1.1 - Sensitive Information Disclo
- [webapps] Joomla! Component AcySMS 3.5.0 - CSV Macro Injection
- [webapps] Joomla! Component Acymailing Starter 5.9.5 - CSV Macro Injection
- [webapps] Homematic CCU2 2.29.23 - Remote Command Execution
- [webapps] Tenda W308R v2 Wireless Router 5.07.48 - Cookie Session Weakness Remote DNS
- [dos] SysGauge 4.5.18 - Local Denial of Service
- [webapps] D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router - Authentica
- [webapps] Tenda W316R Wireless Router 5.07.50 - Remote DNS Change (PoC)
- [remote] Advantech WebAccess < 8.1 - webvrpcs DrawSrv.dll Path BwBuildPath Stack-Base
- [dos] Systematic SitAware - NVG Denial of Service
- [webapps] osCommerce 2.3.4.1 - Remote Code Execution
- [local] Faleemi Windows Desktop Software - (DDNS/IP) Local Buffer Overflow
- [webapps] Tenda FH303/A300 Firmware V5.07.68_EN - Remote DNS Change
- [webapps] Tenda W3002R/A302/w309r Wireless Router V5.07.64_en - Remote DNS Change (Po
- [webapps] Vtiger CRM 6.3.0 - Authenticated Arbitrary File Upload (Metasploit)
- [webapps] WampServer 3.1.1 - Cross-Site Scripting / Cross-Site Request Forgery
- [webapps] Frog CMS 0.9.5 - Cross-Site Request Forgery (Add User)
- [webapps] DLink DIR-601 - Admin Password Disclosure
- [webapps] VideoFlow Digital Video Protection (DVP) 2.10 - Hard-Coded Credentials
- [webapps] VideoFlow Digital Video Protection (DVP) 2.10 - Directory Traversal
- [webapps] WampServer 3.1.2 - Cross-Site Request Forgery
- [local] WebLog Expert Enterprise 9.4 - Privilege Escalation
- [webapps] OpenCMS 10.5.3 - Cross-Site Request Forgery
- [webapps] Secutech RiS-11/RiS-22/RiS-33 - Remote DNS Change
- [webapps] OpenCMS 10.5.3 - Cross-Site Scripting
- [dos] Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix 2)
- [dos] Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix)
- [dos] Google Chrome V8 - 'Genesis::InitializeGlobal' Out-of-Bounds Read/Write
- [dos] Google Chrome V8 - 'ElementsAccessorBase::CollectValuesOrEntriesImpl' Type Conf
- [remote] Moxa AWK-3131A 1.4 < 1.7 - 'Username' OS Command Injection
- [webapps] ProcessMaker - Plugin Upload (Metasploit)
- [webapps] Joomla! Component JS Jobs 1.2.0 - Cross-Site Scripting
- [webapps] MyBB Plugin Downloads 2.0.3 - Cross-Site Scripting
- [dos] Microsoft Windows - Multiple Use-After-Free Issues in jscript Array Methods
- [dos] Microsoft Windows Defender - 'mpengine.dll' Memory Corruption
- [webapps] Z-Blog 1.5.1.1740 - Full Path Disclosure
- [webapps] Z-Blog 1.5.1.1740 - Cross-Site Scripting
- [webapps] YzmCMS 3.6 - Cross-Site Scripting
- [webapps] WebRTC - Private IP Leakage (Metasploit)
- [webapps] GetSimple CMS 3.3.13 - Cross-Site Scripting
- [local] Sophos Endpoint Protection 10.7 - Tamper-Protection Bypass
- [local] Sophos Endpoint Protection Control Panel 10.7 - Weak Password Encryption
- [remote] LineageOS 14.1 Blueborne - RCE
- [webapps] DotNetNuke DNNarticle Module 11 - Directory Traversal
- [webapps] FiberHome VDSL2 Modem HG 150-UB - Authentication Bypass
- [webapps] Cobub Razor 0.7.2 - Cross Site Request Forgery
- [webapps] Flowise 1.6.5 - Authentication Bypass
- [webapps] Laravel Framework 11 - Credential Leakage
- [webapps] SofaWiki 3.9.2 - Remote Command Execution (RCE) (Authenticated)
- [webapps] Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution
- [webapps] FlatPress v1.3 - Remote Command Execution
- [remote] Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creat
- [webapps] OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
- [webapps] OpenClinic GA 5.247.01 - Information Disclosure
- [webapps] Jenkins 2.441 - Local File Inclusion
- [webapps] djangorestframework-simplejwt 5.3.1 - Information Disclosure
- [webapps] BMC Compuware iStrobe Web - 20.13 - Pre-auth RCE
- [webapps] Stock Management System v1.0 - Unauthenticated SQL Injection
- [webapps] Online Fire Reporting System OFRS - SQL Injection Authentication Bypass
- [webapps] Savsoft Quiz v6.0 Enterprise - Stored XSS
- [webapps] Wordpress Plugin WP Video Playlist 1.1.1 - Stored Cross-Site Scripting (XSS
- [webapps] WBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)
- [webapps] WBCE 1.6.0 - Unauthenticated SQL injection
- [webapps] Moodle 3.10.1 - Authenticated Blind Time-Based SQL Injection - "sort" param
- [local] PrusaSlicer 2.6.1 - Arbitrary code execution
- [webapps] PopojiCMS Version 2.0.1 - Remote Command Execution
- [webapps] Wordpress Plugin Playlist for Youtube 1.32 - Stored Cross-Site Scripting (X
- [webapps] HTMLy Version v2.9.6 - Stored XSS
- [webapps] Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
- [local] Terratec dmx_6fire USB - Unquoted Service Path
- [remote] MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
- [webapps] GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted Fi
- [webapps] Open Source Medicine Ordering System v1.0 - SQLi
- [webapps] Daily Expense Manager 1.0 - 'term' SQLi
- [webapps] Best Student Result Management System v1.0 - Multiple SQLi
- [webapps] Human Resource Management System v1.0 - Multiple SQLi
- [remote] Positron Broadcast Signal Processor TRA7005 v1.20 - Authentication Bypass
- [webapps] Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload
- [local] AnyDesk 7.0.15 - Unquoted Service Path
- [webapps] Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XS
- [webapps] Computer Laboratory Management System v1.0 - Multiple-SQLi
- [local] ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path
- [webapps] Axigen < 10.5.7 - Persistent Cross-Site Scripting
- [webapps] Gibbon LMS v26.0.00 - SSTI vulnerability
- [webapps] Casdoor < v1.331.0 - '/api/set-password' CSRF
- [local] Microsoft Windows Defender - Detection Mitigation Bypass TrojanWin32Powessere
- [webapps] Wordpress Plugin - Membership For WooCommerce < v2.1.7 - Arbitrary File Upl
- [webapps] Smart School 6.4.1 - SQL Injection
- [webapps] CE Phoenix v1.0.8.20 - Remote Code Execution
- [webapps] Elementor Website Builder < 3.12.2 - Admin+ SQLi
- [webapps] Blood Bank v1.0 - Stored Cross Site Scripting (XSS)
- [webapps] Daily Habit Tracker 1.0 - Broken Access Control
- [webapps] Daily Habit Tracker 1.0 - SQL Injection
- [webapps] Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
- [webapps] Employee Management System 1.0 - `txtusername` and `txtpassword` SQL Inject
- [webapps] Employee Management System 1.0 - `txtfullname` and `txtphone` SQL Injection
- [webapps] Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link - Device Config Disclos
- [webapps] Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link - Authentication Bypass
- [webapps] Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 - Device Config Discl
- [webapps] Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 - Authentication Bypa
- [webapps] Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 - Device Config Disclosu
- [webapps] Elber Signum DVB-S/S2 IRD For Radio Networks 1.999 - Authentication Bypass
- [webapps] iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS)
- [webapps] Clinic Queuing System 1.0 - RCE
- [local] Plantronics Hub 3.25.1 - Arbitrary File Read
- [webapps] Apache mod_proxy_cluster - Stored XSS
- [webapps] Prison Management System - SQL Injection Authentication Bypass
- [webapps] PyroCMS v3.0.1 - Stored XSS
- [webapps] CE Phoenix Version 1.0.8.20 - Stored XSS
- [webapps] Leafpub 1.1.9 - Stored Cross-Site Scripting (XSS)
- [webapps] Chyrp 2.5.2 - Stored Cross-Site Scripting (XSS)
- [remote] CrushFTP < 11.1.0 - Directory Traversal
- [webapps] htmlLawed 1.2.5 - Remote Code Execution (RCE)
- [webapps] PopojiCMS 2.0.1 - Remote Command Execution (RCE)
- [webapps] Backdrop CMS 1.27.1 - Remote Command Execution (RCE)
- [webapps] Apache OFBiz 18.12.12 - Directory Traversal
- [webapps] Wordpress Theme XStore 9.3.8 - SQLi
- [webapps] Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
- [webapps] Aquatronica Control System 5.1.6 - Information Disclosure
- [webapps] changedetection < 0.45.20 - Remote Code Execution (RCE)
- [webapps] ElkArte Forum 1.1.9 - Remote Code Execution (RCE) (Authenticated)
- [webapps] iMLog < 1.307 - Persistent Cross Site Scripting (XSS)
- [webapps] BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL Injection
- [webapps] Check Point Security Gateway - Information Disclosure (Unauthenticated)
- [remote] ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) & SSH Access
- [remote] Wipro Holmes Orchestrator 20.4.1 - Log File Disclosure
- [webapps] FreePBX 16 - Remote Code Execution (RCE) (Authenticated)
- [webapps] Akaunting 3.1.8 - Server-Side Template Injection (SSTI)
- [webapps] Craft CMS Logs Plugin 3.0.3 - Path Traversal (Authenticated)
- [webapps] Serendipity 2.5.0 - Remote Code Execution (RCE)
- [webapps] Sitefinity 15.0 - Cross-Site Scripting (XSS)
- [webapps] appRain CMF 4.0.5 - Remote Code Execution (RCE) (Authenticated)
- [webapps] CMSimple 5.15 - Remote Code Execution (RCE) (Authenticated)
- [webapps] WBCE CMS v1.6.2 - Remote Code Execution (RCE)
- [webapps] Monstra CMS 3.0.4 - Remote Code Execution (RCE)
- [webapps] Dotclear 2.29 - Remote Code Execution (RCE)
- [webapps] Boelter Blue System Management 1.3 - SQL Injection
- [webapps] Rebar3 3.13.2 - Command Injection
- [webapps] ZwiiCMS 12.2.04 - Remote Code Execution (Authenticated)
- [remote] Zyxel IKE Packet Decoder - Unauthenticated Remote Code Execution (Metasploit
- [webapps] WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS) (Authenticated)
- [webapps] PHP < 8.3.8 - Remote Code Execution (Unauthenticated) (Windows)
- [webapps] AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerabil
- [webapps] AEGON LIFE v1.0 Life Insurance Management System - Unauthenticated Remote C
- [webapps] XMB 1.9.12.06 - Stored XSS
- [webapps] Carbon Forum 5.9.0 - Stored XSS
- [webapps] AEGON LIFE v1.0 Life Insurance Management System - Stored cross-site script
- [webapps] Automad 2.0.0-alpha.4 - Stored Cross-Site Scripting (XSS)
- [webapps] SolarWinds Platform 2024.1 SR1 - Race Condition
- [webapps] Flatboard 3.2 - Stored Cross-Site Scripting (XSS) (Authenticated)
- [webapps] Poultry Farm Management System v1.0 - Remote Code Execution (RCE)
- [webapps] Xhibiter NFT Marketplace 1.10.2 - SQL Injection
- [webapps] Azon Dominator Affiliate Marketing Script - SQL Injection
- [webapps] Microweber 2.0.15 - Stored XSS
- [webapps] Customer Support System 1.0 - Stored XSS
- [local] Bonjour Service 'mDNSResponder.exe' - Unquoted Service Path Privilege Escalat
- [webapps] Devika v1 - Path Traversal via 'snapshot_path'
- [local] Genexus Protection Server 9.7.2.10 - 'protsrvservice' Unquoted Service Path
- [local] SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
- [local] Oracle Database 12c Release 1 - Unquoted Service Path
- [webapps] Ivanti vADC 9.9 - Authentication Bypass
- [webapps] Helpdeskz v2.0.2 - Stored XSS
- [webapps] Calibre-web 0.6.21 - Stored XSS
- [webapps] HughesNet HT2000W Satellite Modem - Password Reset
- [webapps] Elber Wayber Analog/Digital Audio STL 4.00 - Device Config Disclosure
- [webapps] Elber Wayber Analog/Digital Audio STL 4.00 - Authentication Bypass
- [webapps] Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Device Config
- [webapps] Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass