February 15, 2023Arris Router Firmware 9.1.103 Remote Code Execution

Arris Router Firmware version 9.1.103 authenticated remote code execution exploit that has been tested against the TG2482A, TG2492, and SBG10 models.

February 14, 2023Cisco RV Series Authentication Bypass / Command Injection

This Metasploit module exploits two vulnerabilities, a session ID directory traversal authentication bypass (CVE-2022-20705) and a command injection vulnerability (CVE-2022-20707), on Cisco RV160, RV260, RV340, and RV345 Small Business Routers, allowing a

February 14, 2023XWorm Trojan 2.1 NULL Pointer Dereference

XWorm Trojan version 2.1 suffers from a denial of service condition due to a null pointer vulnerability.

February 10, 2023ChiKoi 1.0 Directory Traversal

ChiKoi version 1.0 suffers from a directory traversal vulnerability.

February 10, 2023ChiKoi 1.0 Cross Site Scripting

ChiKoi version 1.0 suffers from a cross site scripting vulnerability.

February 10, 2023Monitorr 1.7.6 Shell Upload

Monitorr version 1.7.6 remote shell upload proof of concept exploit written in Python.

February 10, 2023WEBY 1.2.5 Cross Site Request Forgery

WEBY version 1.2.5 suffers from a cross site request forgery vulnerability.

February 9, 2023SOUND4 LinkAndShare Transmitter 1.1.2 Format String Stack Buffer Overflow

SOUND4 LinkAndShare Transmitter version 1.1.2 suffers from a format string memory leak and stack buffer overflow vulnerability because it fails to properly sanitize user supplied input when calling the getenv() function from MSVCR120.DLL resulting in a cr

February 9, 2023Zoho ManageEngine Endpoint Central / MSP 10.1.2228.10 Remote Code Execution

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine Endpoint Central and MSP versions 10.1.2228.10 and below (CVE-2022-47966). Due to a dependency to an outdated library (Apache Santuario v

February 9, 2023Fortra GoAnywhere MFT Unsafe Deserialization Remote Code Execution

This Metasploit module exploits an object deserialization vulnerability in Fortra GoAnywhere MFT.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow