header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Vulnerability Type
No results found
Buffer Overflow (403)
SQL Injection (259)
Remote Code Execution (211)
Denial of Service (160)
Privilege Escalation (153)
Command Injection (85)
Remote Command Execution (77)
Authentication Bypass (66)
Directory Traversal (54)
Cross-Site Scripting (52)
Cross-Site Scripting (XSS) (43)
Format String Vulnerability (41)
Local Privilege Escalation (40)
Information Disclosure (37)
Use-After-Free (33)
Denial of Service (DoS) (31)
Remote Code Execution (RCE) (30)
Local File Inclusion (29)
Race Condition (28)
Stored Cross-Site Scripting (XSS) (27)
Memory Corruption (26)
Stack Overflow (25)
Arbitrary File Upload (24)
Blind SQL Injection (24)
Stored XSS (22)
Code Execution (21)
Remote File Inclusion (20)
Command Execution (17)
Cross-Site Request Forgery (17)
Persistent Cross Site Scripting (17)
Remote Denial of Service (17)
Buffer Overrun (15)
Multiple Vulnerabilities (15)
Cross-Site Request Forgery (CSRF) (14)
Integer Overflow (14)
OS Command Injection (14)
Remote Command Injection (14)
XSS (14)
Arbitrary Command Execution (13)
Heap-overflow (13)
Out-of-bounds Read (12)
Format String (11)
Remote Buffer Overflow (11)
Remote Root Exploit (11)
Local root exploit (10)
NULL pointer dereference (10)
Stack-Based Buffer Overflow (10)
Wrong input validation (10)
Path Traversal (9)
RCE (9)
CWE
No results found
119 (417)
78 (360)
89 (342)
79 (270)
264 (212)
120 (190)
N/A (150)
22 (136)
400 (135)
20 (131)
94 (113)
200 (110)
287 (96)
434 (66)
98 (57)
352 (54)
134 (53)
Unknown (50)
416 (44)
269 (40)
362 (33)
787 (22)
399 (20)
190 (19)
125 (17)
120 (Buffer Copy without Checking Size of Input) (15)
284 (15)
476 (13)
502 (12)
122 (11)
259 (11)
798 (11)
843 (11)
121 (10)
Buffer Overflow (9)
522 (8)
611 (8)
59 (6)
250 (5)
77 (5)
918 (5)
255 (4)
639 (4)
16 (3)
285 (3)
369 (3)
377 (3)
613 (3)
835 (3)
None (3)
CPE
No results found
N/A (937)
o:linux:linux_kernel (61)
Unknown (49)
None (26)
o:redhat:enterprise_linux:7.1 (12)
a:mozilla:firefox (11)
a:joomla:joomla (10)
a:petrol_pump_management_software:petrol_pump_management_software:1.0 (9)
o:adobe:flash_player (9)
a:mysql:mysql (8)
o:microsoft:windows (8)
a:adobe:flash_player (7)
a:oracle:java (6)
a:oracle:virtualbox (6)
a:samba:samba (6)
Not provided (6)
a:google:chrome (5)
a:php:php (5)
a:snort:snort (5)
a:wireshark:wireshark (5)
a:adobe:coldfusion (4)
a:code-projects:blood_bank:1.0 (4)
a:cpanel:cpanel (4)
a:dnsmasq:dnsmasq (4)
a:nginx:nginx (4)
a:openbsd:openssh (4)
a:oracle:weblogic_server (4)
a:petrol_pump_management_software:1.0 (4)
a:sudo:sudo (4)
a:vendor:product_name (4)
a:wordpress:wordpress (4)
o:freebsd:freebsd (4)
o:microsoft:windows_2000 (4)
a:adobe:acrobat_reader (3)
a:apache:http_server (3)
a:apache:struts:2.3.5 (3)
a:apache:tomcat (3)
a:aprelium:abyss_web_server (3)
a:borland:interbase:8.0.0.53 (3)
a:google:chromium (3)
a:libtiff:libtiff (3)
a:nullsoft:shoutcast_server (3)
a:openssl:openssl (3)
a:opera_software:opera (3)
a:sophos:web_appliance (3)
a:sourcecodester:online_job_portal:1.0 (3)
a:ulicms:ulicms:2023.1-sniffing-vicuna (3)
a:wu-ftpd:wu-ftpd:2.6.0 (3)
mozilla:firefox (3)
Not mentioned (3)
Vendor
No results found
N/A (270)
Linux (159)
Microsoft (63)
Apache (60)
Adobe (57)
Oracle (57)
Mozilla (53)
Unknown (36)
WordPress (34)
Joomla! (31)
RedHat (27)
D-Link (26)
GNU (26)
Google (26)
Cisco (24)
Red Hat (22)
MySQL (20)
Ubuntu (20)
Wireshark (18)
ManageEngine (17)
PHP (17)
Novell (16)
Apple (15)
HP (15)
IBM (15)
Sourcecodester (15)
Samba (13)
MyBB (12)
Petrol Pump Management Software (12)
Symantec (11)
VMware (11)
KDE (10)
SonicWall (10)
SuSE (10)
Debian (9)
NETGEAR (9)
Opera Software (9)
Borland (8)
Chromium (8)
DLink (8)
GNOME (8)
Intel (8)
Multiple Vendors (8)
Netscape (8)
ProFTPD (8)
Sun (8)
Sun Microsystems (8)
TP-Link (8)
Example (7)
OpenBSD (7)
Product Name
No results found
Linux Kernel (117)
N/A (116)
Kernel (47)
Firefox (38)
Flash Player (35)
Linux (24)
Unknown (20)
MySQL (19)
Joomla (16)
Windows (16)
Wireshark (16)
Chrome (15)
Java (15)
PHP (15)
Petrol Pump Management Software (13)
Samba (13)
Ubuntu Linux (13)
OpenSSH (12)
Struts (11)
RHEL 7.1 (10)
Safari (10)
Enterprise Linux (9)
Apache HTTP Server (8)
Chromium (8)
OpenSSL (8)
Opera (8)
ProFTPD (8)
sudo (8)
vBulletin (8)
Windows 2000 (8)
InterBase (7)
Moodle (7)
Oracle Database (7)
Sendmail (7)
BIND (6)
cPanel (6)
glibc (6)
man (6)
MyBB (6)
Product Name (6)
Snort (6)
VirtualBox (6)
WebLogic Server (6)
WordPress (6)
WU-FTPD (6)
Coldfusion (5)
exim (5)
Half-Life (5)
Internet Explorer (5)
Invision Power Board (5)
Version
From
No results found
N/A (489)
Unknown (148)
1 (76)
3.1 (71)
1.0 (61)
All versions (22)
2 (19)
1.0.0 (16)
2.1 (11)
1.1 (10)
1.2 (10)
3 (10)
All (10)
RHEL 7.1 (10)
0.1 (9)
1.3 (9)
1.5 (8)
1.6 (8)
2.2 (8)
2.0 (7)
4 (7)
1.0.6 (6)
1.7 (6)
2.0.0 (6)
5.3 (6)
v1.0 (6)
Windows 95 (6)
0.0.1 (5)
0.9 (5)
2.0.1 (5)
2.1.2001 (5)
2.3 (5)
2.4.2000 (5)
2.6 (5)
3.0 (5)
3.3.2001 (5)
3.4 (5)
4.0.0 (5)
6 (5)
8.0 (5)
Current git master (5)
Prior to 7u25 (5)
Windows XP (5)
1.0.1 (4)
1.4.2002 (4)
1.4.2004 (4)
1.6.2001 (4)
15 (4)
2.0.5 (4)
2.1.2000 (4)
To
No results found
N/A (537)
Unknown (180)
1 (54)
3.5-RC7 (42)
1.0 (41)
1.2 (27)
2 (25)
All versions (20)
2.0 (13)
All (10)
1.3 (9)
RHEL 7.1 (9)
0.1 (8)
1.1 (8)
2.1 (8)
2.1.2001 (8)
3 (8)
4 (8)
1.5 (7)
1.6 (7)
2.2 (6)
2.5 (6)
2.6 (6)
v1.0 (6)
0.9 (5)
1.0.0 (5)
1.0.1 (5)
1.0.6 (5)
1.4.2004 (5)
2.0.0 (5)
2.0.1 (5)
2.3 (5)
3.2 (5)
4.0.2 (5)
5 (5)
5.3 (5)
8 (5)
not specified (5)
Struts 2.5 - Struts 2.5.10 (5)
0.0.1 (4)
0.7 (4)
1.0.2 (4)
1.6.2001 (4)
1.7 (4)
2.3.4 (4)
2.4 (4)
2.6.1 (4)
2.6.x (4)
2.x (4)
3.1 (4)
Severity Type
No results found
HIGH (2706)
MEDIUM (307)
CRITICAL (221)
N/A (180)
LOW (22)
Severity Number
No results found
7.5 (1033)
7 (629)
5 (459)
8 (358)
7.2 (243)
9 (231)
N/A (207)
8.8 (168)
9.8 (138)
3 (130)
Exploit Author
No results found
SecurityFocus (320)
Unknown (81)
Anonymous (76)
indoushka (59)
Mirabbas Agalarov (49)
Project Zero (42)
juan vazquez (37)
Google Security Research (35)
sinn3r (32)
Luigi Auriemma (31)
Jann Horn (20)
LiquidWorm (19)
Pedro Ribeiro (19)
bcoles (17)
hdm (17)
Kingcope (17)
milw0rm.com (17)
jduck (16)
N/A (16)
John Doe (15)
Michael Messner (15)
CWH Underground (14)
Shubham Pandey (14)
Brendan Coles (13)
Jon Oberheide (13)
Todor Donev (13)
Amirhossein Bahramizadeh (12)
Daniel Godoy (12)
Gjoko 'LiquidWorm' Krstic (12)
halfdog (12)
Vulnerability-Lab (12)
Claudio Viviani (11)
Qualys (11)
TaurusOmar (11)
wvu (11)
Dawid Golunski (10)
Hendrik Schwartke (10)
Ihsan Sencan (10)
Ralf Spenneberg (10)
Sergej Schumilo (10)
h00die (9)
Inc (9)
mu-b (9)
qflb.wu (9)
egypt (8)
IhaQueR (8)
John Page (aka hyp3rlinx) (8)
Larry W. Cashdollar (8)
nu11secur1ty (8)
Number 7 (8)
Linux
No results found
N/A (12658)
Windows (4998)
Linux (3440)
None (1839)
Mac (981)
Unknown (939)
Windows XP SP3 (683)
WiN7_x64/KaLiLinuX_x64 (546)
Windows 10 (529)
unix (487)
Windows 7 (410)
Kali Linux (332)
PHP (305)
Kali linux X64 (296)
Win7 x64 (276)
Windows XP SP2 (267)
Windows XP (233)
WordPress (196)
iOS (151)
All (142)
Not mentioned (132)
macOS (126)
Ubuntu (120)
Microsoft Windows (117)
Not Specified (106)
Solaris (105)
Apache (99)
Windows 7 x64 (98)
Android (96)
Xampp (91)
FreeBSD (90)
Windows 10 Pro x64 es (80)
Mac OS X (78)
Windows 2000 (77)
Windows 10 x64 (73)
Ubuntu 18.04 (72)
Windows 7 SP1 (70)
Windows Vista (70)
Not provided (69)
Windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu) (68)
Windows 7 x86 (67)
Windows XP SP3 EN (62)
Kali Linux 2.0 (59)
Windows 10 Pro (59)
Windows XP Professional SP2 (59)
Debian (55)
Linux & Windows (55)
Windows XP Professional SP2 with Internet Explorer 7 (53)
Java (51)
Microsoft Windows XP Professional SP3 (EN) (50)
Year
Year
No results found
2002 (353)
2020 (283)
2009 (209)
2017 (172)
2010 (156)
2008 (155)
2018 (144)
2015 (138)
2005 (127)
2016 (124)
2023 (120)
2012 (118)
2019 (115)
2006 (114)
2013 (114)
2021 (112)
Unknown (107)
2011 (101)
2014 (90)
2001 (85)
2003 (74)
2000 (68)
2004 (58)
2022 (56)
2007 (40)
2024 (33)
1999 (27)
1997 (14)
1998 (12)
N/A (9)
1996 (4)
Not mentioned (3)
Not provided (2)
1993 (1)
April 2016 (1)
April-00 (1)
Author: K4P0 (1)
Copyright: NeoSecurity (1)
Discovered in 2014 (1)
Feb 05 2013 (1)
Feb 11 2013 (1)
Jun 07 2013 (1)
Jun 28 2016 (1)
March 2017 (1)
May 11 2012 (1)
May 13 2013 (1)
None (1)
Not Specified (1)

Explore all Exploits:

openSIS 9.1 – SQL Injection (Authenticated)

A SQL injection vulnerability was discovered in OS4Ed Open Source Information System Community version 9.1. By manipulating the 'X-Forwarded-For' header parameters in a POST request to /Ajax.php, an attacker can execute malicious SQL queries.

dizqueTV 1.5.3 – Remote Code Execution (RCE)

dizqueTV version 1.5.3 is susceptible to a remote code execution vulnerability that allows attackers to execute unauthorized commands remotely. By manipulating the FFMPEG Executable Path in the settings to include a malicious command like "; cat /etc/passwd && echo 'poc'", an attacker can view the content of /etc/passwd.

Stored Cross-Site Scripting (XSS) in NoteMark

The vulnerability exists in NoteMark version 0.13.0 and below. By injecting a malicious payload into a note and rendering it using the 'Rendered' tab, an attacker can execute arbitrary JavaScript code in the context of the user's session.

HughesNet HT2000W Satellite Modem Password Reset

The exploit allows an attacker to reset the administrator password for HughesNet HT2000W Satellite Modem by taking advantage of CVE-2021-20090, a path traversal vulnerability in the HTTP daemon. The exploit also exploits other vulnerabilities like improper use of httokens for authentication and leaking the MD5 hash of the password.

Stored XSS in Calibre-web

Calibre-web 0.6.21 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. This allows an attacker to insert malicious scripts stored on the server and run in the context of another user's session. By exploiting this vulnerability, an attacker can execute arbitrary scripts in the victim's browser.

Sitefinity 15.0 – Cross-Site Scripting (XSS)

A Cross-Site Scripting (XSS) vulnerability was found in Sitefinity CMS versions prior to 15.0.0. The vulnerability exists in all features using SF-Editor in the backend of the CMS. An attacker with lower privileges can insert malicious XSS payloads in the content form, which will be executed when a user with higher privileges, the victim, views the affected page.

ASUS ASMB8 iKVM 1.14.51 – Remote Code Execution (RCE) & SSH Access

A vulnerability was found in ASUS ASMB8 iKVM firmware version 1.14.51 and possibly others, allowing for Remote Code Execution (RCE) via SNMP arbitrary extensions. By exploiting this vulnerability, an attacker can run commands on the system with root privileges and introduce a new user to bypass SSH restrictions. Additionally, a hardcoded account 'sysadmin:superuser' was discovered. The vulnerability is identified as CVE-2023-26602.

Recent Exploits:

cqrsecured