2022-03-22
|
|
ICT Protege GX/WX 2.08 - Stored Cross-Site Scripting (XSS)
|
1 |
REMOTE
|
LiquidWorm
|
2022-03-22
|
|
Ivanti Endpoint Manager 4.6 - Remote Code Execution (RCE)
|
1 |
REMOTE
|
d7x
|
2022-03-22
|
|
iRZ Mobile Router - CSRF to RCE
|
1 |
REMOTE
|
John Jackson
|
2022-03-16
|
|
Apache APISIX 2.12.1 - Remote Code Execution (RCE)
|
4 |
REMOTE
|
Ven3xy
|
2022-03-11
|
|
Tdarr 2.00.15 - Command Injection
|
2 |
REMOTE
|
Sam Smith
|
2022-03-11
|
|
Seowon SLR-120 Router - Remote Code Execution (Unauthenticated)
|
1 |
REMOTE
|
Aryan Chehreghani
|
2022-03-02
|
|
Printix Client 1.3.1106.0 - Remote Code Execution (RCE)
|
2 |
REMOTE
|
Logan Latvala
|
2022-03-02
|
|
Prowise Reflect v1.0.9 - Remote Keystroke Injection
|
1 |
REMOTE
|
Rik Lutz
|
2022-02-28
|
|
WAGO 750-8212 PFC200 G2 2ETH RS - Privilege Escalation
|
2 |
REMOTE
|
Momen Eldawakhly
|
2022-02-23
|
|
ICL ScadaFlex II SCADA Controllers SC-1/SC-2 1.03.07 - Remote File CRUD
|
3 |
REMOTE
|
LiquidWorm
|
2022-02-23
|
|
Adobe ColdFusion 11 - LDAP Java Object Deserialization Remode Code Execution (RCE)
|
2 |
REMOTE
|
Amel BOUZIANE-LEBLOND
|
2022-02-16
|
|
H3C SSL VPN - Username Enumeration
|
0 |
REMOTE
|
LiquidWorm
|
2022-02-08
|
|
Wing FTP Server 4.3.8 - Remote Code Execution (RCE) (Authenticated)
|
0 |
REMOTE
|
notcos
|
2022-01-27
|
|
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
|
0 |
REMOTE
|
Jonah Tan
|
2022-01-18
|
|
Archeevo 5.0 - Local File Inclusion
|
0 |
REMOTE
|
Miguel Santareno
|
2022-01-10
|
|
CoreFTP Server build 725 - Directory Traversal (Authenticated)
|
0 |
REMOTE
|
LiamInfosec
|
2022-01-05
|
|
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
|
1 |
REMOTE
|
Jeremiasz Pluta
|
2022-01-05
|
|
Dixell XWEB 500 - Arbitrary File Write
|
1 |
REMOTE
|
Roberto Palamaro
|
2022-01-05
|
|
TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
|
0 |
REMOTE
|
Fabiano Golluscio
|
2022-01-05
|
|
AWebServer GhostBuilding 18 - Denial of Service (DoS)
|
1 |
REMOTE
|
Andres Ramos
|
2022-01-05
|
|
Accu-Time Systems MAXIMUS 1.0 - Telnet Remote Buffer Overflow (DoS)
|
0 |
REMOTE
|
Yehia Elghaly
|
2022-01-05
|
|
ConnectWise Control 19.2.24707 - Username Enumeration
|
0 |
REMOTE
|
Luca Cuzzolin
|
2021-12-15
|
|
Oliver Library Server v5 - Arbitrary File Download
|
0 |
REMOTE
|
Mandeep Singh
|
2021-12-14
|
|
Apache Log4j 2 - Remote Code Execution (RCE)
|
1 |
REMOTE
|
kozmer
|
2021-12-14
|
|
Apache Log4j2 2.14.1 - Information Disclosure
|
0 |
REMOTE
|
leonjza
|
2021-12-13
|
|
HD-Network Real-time Monitoring System 2.0 - Local File Inclusion (LFI)
|
0 |
REMOTE
|
Momen Eldawakhly
|
2021-12-09
|
|
Raspberry Pi 5.10 - Default Credentials
|
0 |
REMOTE
|
netspooky
|
2021-12-06
|
|
Auerswald COMpact 8.0B - Multiple Backdoors
|
0 |
REMOTE
|
RedTeam Pentesting GmbH
|
2021-12-06
|
|
Auerswald COMpact 8.0B - Arbitrary File Disclosure
|
1 |
REMOTE
|
RedTeam Pentesting GmbH
|
2021-12-06
|
|
Auerswald COMpact 8.0B - Privilege Escalation
|
0 |
REMOTE
|
RedTeam Pentesting GmbH
|
2021-12-06
|
|
Auerswald COMfortel 2.8F - Authentication Bypass
|
0 |
REMOTE
|
RedTeam Pentesting GmbH
|
2021-11-23
|
|
GNU gdbserver 9.2 - Remote Command Execution (RCE)
|
1 |
REMOTE
|
Roberto Gesteira Miñarro
|
2021-10-13
|
|
Cypress Solutions CTM-200 2.7.1 - Root Remote OS Command Injection
|
0 |
REMOTE
|
LiquidWorm
|
2021-10-13
|
|
Cypress Solutions CTM-200/CTM-ONE - Hard-coded Credentials Remote Root (Telnet/SSH)
|
0 |
REMOTE
|
LiquidWorm
|
2021-09-29
|
|
Mitrastar GPT-2541GNAC-N1 - Privilege escalation
|
0 |
REMOTE
|
Leonardo Nicolas Servalli
|
2021-09-28
|
|
Apache James Server 2.3.2 - Remote Command Execution (RCE) (Authenticated) (2)
|
0 |
REMOTE
|
shinris3n
|
2021-09-27
|
|
Cisco small business RV130W 1.0.3.44 - Inject Counterfeit Routers
|
0 |
REMOTE
|
Michael Alamoot
|
2017-01-14
|
|
Adobe Flash Player - Integer Overflow
|
0 |
REMOTE
|
ryujin
|
2021-09-13
|
|
ECOA Building Automation System - Hard-coded Credentials SSH Access
|
0 |
REMOTE
|
Neurogenesia
|
2021-08-18
|
|
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
|
1 |
REMOTE
|
Khaled Salem
|
2021-08-02
|
|
Neo4j 3.4.18 - RMI based Remote Code Execution (RCE)
|
0 |
REMOTE
|
Christopher Ellis
|
2021-07-28
|
|
Denver Smart Wifi Camera SHC-150 - 'Telnet' Remote Code Execution (RCE)
|
0 |
REMOTE
|
Ivan Nikolsky
|
2021-07-21
|
|
KevinLAB BEMS 1.0 - Undocumented Backdoor Account
|
0 |
REMOTE
|
LiquidWorm
|
2021-07-15
|
|
Aruba Instant (IAP) - Remote Code Execution
|
0 |
REMOTE
|
Aleph Security
|
2021-07-16
|
|
Aruba Instant 8.7.1.0 - Arbitrary File Modification
|
0 |
REMOTE
|
Gr33nh4t
|
2021-06-29
|
|
ES File Explorer 4.1.9.7.4 - Arbitrary File Read
|
1 |
REMOTE
|
Nehal Zaman
|
2021-06-21
|
|
Solaris SunSSH 11.0 x86 - libpam Remote Root (3)
|
1 |
REMOTE
|
Nathaniel Singer
|
2021-06-18
|
|
Dlink DSL2750U - 'Reboot' Command Injection
|
1 |
REMOTE
|
Mohammed Hadi
|
2021-06-03
|
|
CHIYU IoT Devices - 'Telnet' Authentication Bypass
|
0 |
REMOTE
|
sirpedrotavares
|
2021-05-26
|
|
ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
|
1 |
REMOTE
|
Shellbr3ak
|
2021-05-21
|
|
Solaris SunSSH 11.0 x86 - libpam Remote Root (2)
|
1 |
REMOTE
|
legend
|
2021-04-30
|
|
GNU Wget < 1.18 - Arbitrary File Upload (2)
|
0 |
REMOTE
|
liewehacksie
|
2021-04-21
|
|
Tenda D151 & D301 - Configuration Download (Unauthenticated)
|
1 |
REMOTE
|
BenChaliah
|
2021-04-12
|
|
vsftpd 2.3.4 - Backdoor Command Execution
|
0 |
REMOTE
|
HerculesRD
|
2021-04-08
|
|
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
|
1 |
REMOTE
|
Google Security Research
|
2021-04-06
|
|
Google Chrome 81.0.4044 V8 - Remote Code Execution
|
0 |
REMOTE
|
r4j0x00
|
2021-04-06
|
|
Google Chrome 86.0.4240 V8 - Remote Code Execution
|
0 |
REMOTE
|
r4j0x00
|
2021-03-29
|
|
vsftpd 3.0.3 - Remote Denial of Service
|
0 |
REMOTE
|
xynmaps
|
2021-03-22
|
|
KZTech T3500V 4G LTE CPE 2.0.1 - Weak Default WiFi Password Algorithm
|
1 |
REMOTE
|
LiquidWorm
|
2021-03-19
|
|
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Hard coded Credentials Shell Access
|
0 |
REMOTE
|
LiquidWorm
|
2021-03-14
|
|
Microsoft Exchange 2019 - Server-Side Request Forgery
|
1 |
REMOTE
|
F5
|
2021-03-09
|
|
Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
|
1 |
REMOTE
|
1F98D
|
2021-03-05
|
|
CatDV 9.2 - RMI Authentication Bypass
|
1 |
REMOTE
|
Christopher Ellis
|
2021-03-03
|
|
AnyDesk 5.5.2 - Remote Code Execution
|
0 |
REMOTE
|
scryh
|
2021-03-01
|
|
WiFi Mouse 1.7.8.5 - Remote Code Execution
|
0 |
REMOTE
|
H4rk3nz0
|
2021-02-26
|
|
Remote Desktop Web Access - Authentication Timing Attack (Metasploit Module)
|
0 |
REMOTE
|
Matthew Dunn
|
2021-02-25
|
|
ASUS Remote Link 1.1.2.13 - Remote Code Execution
|
0 |
REMOTE
|
H4rk3nz0
|
2021-02-24
|
|
Unified Remote 3.9.0.2463 - Remote Code Execution
|
0 |
REMOTE
|
H4rk3nz0
|
2021-02-24
|
|
python jsonpickle 2.0.0 - Remote Code Execution
|
0 |
REMOTE
|
Adi Malyanker
|
2021-02-23
|
|
HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
|
1 |
REMOTE
|
Pergyz
|
2021-01-13
|
|
Erlang Cookie - Remote Code Execution
|
1 |
REMOTE
|
1F98D
|
2020-12-18
|
|
FRITZ!Box 7.20 - DNS Rebinding Protection Bypass
|
0 |
REMOTE
|
RedTeam Pentesting GmbH
|
2020-12-15
|
|
Solaris SunSSH 11.0 x86 - libpam Remote Root
|
1 |
REMOTE
|
Hacker Fantastic
|
2020-12-09
|
|
Huawei HedEx Lite 200R006C00SPC005 - Path Traversal
|
1 |
REMOTE
|
Vulnerability-Lab
|
2020-12-09
|
|
Dup Scout Enterprise 10.0.18 - 'sid' Remote Buffer Overflow (SEH)
|
0 |
REMOTE
|
Andrés Roldán
|
2020-12-09
|
|
SmarterMail Build 6985 - Remote Code Execution
|
1 |
REMOTE
|
1F98D
|
2020-12-07
|
|
Dup Scout Enterprise 10.0.18 - 'online_registration' Remote Buffer Overflow
|
0 |
REMOTE
|
0rbz_
|
2020-12-02
|
|
Mitel mitel-cs018 - Call Data Information Disclosure
|
0 |
REMOTE
|
Andrea Intilangelo
|
2020-12-02
|
|
Ksix Zigbee Devices - Playback Protection Bypass (PoC)
|
0 |
REMOTE
|
Alejandro Vazquez Vazquez
|
2020-11-30
|
|
YATinyWinFTP - Denial of Service (PoC)
|
1 |
REMOTE
|
strider
|
2020-11-26
|
|
Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
|
1 |
REMOTE
|
Loke Hui Yi
|
2020-11-19
|
|
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
|
0 |
REMOTE
|
Nitesh Surana
|
2020-11-18
|
|
ZeroLogon - Netlogon Elevation of Privilege
|
0 |
REMOTE
|
West Shepherd
|
2020-11-17
|
|
Apache Struts 2.5.20 - Double OGNL evaluation
|
1 |
REMOTE
|
West Shepherd
|
2020-11-17
|
|
Aerospike Database 5.1.0.3 - OS Command Execution
|
0 |
REMOTE
|
Matt S
|
2020-11-16
|
|
Cisco 7937G - DoS/Privilege Escalation
|
1 |
REMOTE
|
Cody Martin
|
2020-11-05
|
|
TP-Link WDR4300 - Remote Code Execution (Authenticated)
|
0 |
REMOTE
|
Patrik Lantz
|
2020-10-27
|
|
GoAhead Web Server 5.1.1 - Digest Authentication Capture Replay Nonce Reuse
|
0 |
REMOTE
|
LiquidWorm
|
2020-10-27
|
|
Adtec Digital Multiple Products - Default Hardcoded Credentials Remote Root
|
0 |
REMOTE
|
LiquidWorm
|
2020-10-01
|
|
Sony IPELA Network Camera 1.82.01 - 'ftpclient.cgi' Remote Stack Buffer Overflow
|
0 |
REMOTE
|
LiquidWorm
|
2020-09-17
|
|
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
|
0 |
REMOTE
|
West Shepherd
|
2020-07-10
|
|
Aruba ClearPass Policy Manager 6.7.0 - Unauthenticated Remote Command Execution
|
0 |
REMOTE
|
SpicyItalian
|
2020-07-09
|
|
CompleteFTP Professional 12.1.3 - Remote Code Execution
|
0 |
REMOTE
|
1F98D
|
2020-07-08
|
|
Qmail SMTP 1.03 - Bash Environment Variable Injection
|
0 |
REMOTE
|
1F98D
|
2020-07-07
|
|
Microsoft Windows mshta.exe 2019 - XML External Entity Injection
|
0 |
REMOTE
|
hyp3rlinx
|
2020-06-25
|
|
mySCADA myPRO 7 - Hardcoded Credentials
|
1 |
REMOTE
|
Emre ÖVÜNÇ
|
2020-06-15
|
|
SOS JobScheduler 1.13.3 - Stored Password Decryption
|
0 |
REMOTE
|
Sander Ubink
|
2020-06-10
|
|
HFS Http File Server 2.3m Build 300 - Buffer Overflow (PoC)
|
0 |
REMOTE
|
hyp3rlinx
|
2020-06-02
|
|
vCloud Director 9.7.0.15498291 - Remote Code Execution
|
1 |
REMOTE
|
aaronsvk
|
2020-06-02
|
|
Microsoft Windows - 'SMBGhost' Remote Code Execution
|
1 |
REMOTE
|
chompie1337
|
2020-05-25
|
|
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
|
1 |
REMOTE
|
Metasploit
|
2020-05-25
|
|
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
|
1 |
REMOTE
|
Metasploit
|
2020-05-22
|
|
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-05-19
|
|
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-05-18
|
|
HP LinuxKI 6.01 - Remote Command Injection
|
0 |
REMOTE
|
Cody Winkler
|
2020-05-05
|
|
Saltstack 3000.1 - Remote Code Execution
|
1 |
REMOTE
|
Jasper Lievisse Adriaanse
|
2020-05-01
|
|
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-04-28
|
|
CloudMe 1.11.2 - Buffer Overflow (PoC)
|
0 |
REMOTE
|
Andy Bowden
|
2020-04-21
|
|
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
|
0 |
REMOTE
|
hyp3rlinx
|
2020-04-20
|
|
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-04-17
|
|
Nexus Repository Manager - Java EL Injection RCE (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-04-16
|
|
Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-04-16
|
|
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-04-16
|
|
PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metasploit)
|
1 |
REMOTE
|
Metasploit
|
2020-04-16
|
|
Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
|
1 |
REMOTE
|
Metasploit
|
2020-04-16
|
|
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-04-16
|
|
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
|
1 |
REMOTE
|
Metasploit
|
2020-04-16
|
|
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-03-31
|
|
SharePoint Workflows - XOML Injection (Metasploit)
|
1 |
REMOTE
|
Metasploit
|
2020-03-31
|
|
DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
|
1 |
REMOTE
|
Metasploit
|
2020-03-31
|
|
IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasploit)
|
1 |
REMOTE
|
Metasploit
|
2020-03-31
|
|
Redis - Replication Code Execution (Metasploit)
|
0 |
REMOTE
|
Metasploit
|
2020-03-30
|
|
Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
|
0 |
REMOTE
|
0xsha
|
2020-03-23
|
|
CyberArk PSMP 10.9.1 - Policy Restriction Bypass
|
0 |
REMOTE
|
LAHBAL Said
|
2020-03-18
|
|
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
|
0 |
REMOTE
|
Maurizio S
|