{"pocs":[{"id":"252131233","cve_id":"CVE-2019-17558","name":"exphub","owner":"zhzyker","full_name":"zhzyker\/exphub","html_url":"https:\/\/github.com\/zhzyker\/exphub","description":"Exphub[\u6f0f\u6d1e\u5229\u7528\u811a\u672c\u5e93] \u5305\u62ecWebloigc\u3001Struts2\u3001Tomcat\u3001Nexus\u3001Solr\u3001Jboss\u3001Drupal\u7684\u6f0f\u6d1e\u5229\u7528\u811a\u672c\uff0c\u6700\u65b0\u6dfb\u52a0CVE-2020-14882\u3001CVE-2020-11444\u3001CVE-2020-10204\u3001CVE-2020-10199\u3001CVE-2020-1938\u3001CVE-2020-2551\u3001CVE-2020-2555\u3001CVE-2020-2883\u3001CVE-2019-17558\u3001CVE-2019-6340","stargazers_count":"3321","vuln_description":"Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity\/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).","created_at":"2020-04-01 18:33:35","updated_at":"2022-05-21 16:02:40","pushed_at":"2021-04-04 18:13:57","inserted_at":null},{"id":"1224571990","cve_id":"CVE-2026-31431","name":"copy-fail-CVE-2026-31431","owner":"theori-io","full_name":"theori-io\/copy-fail-CVE-2026-31431","html_url":"https:\/\/github.com\/theori-io\/copy-fail-CVE-2026-31431","description":"Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code","stargazers_count":"3168","vuln_description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.","created_at":"2026-04-29 21:15:28","updated_at":"2026-05-05 09:34:09","pushed_at":"2026-04-30 06:21:46","inserted_at":"2026-05-05 10:36:27"},{"id":"437729997","cve_id":"CVE-2021-44228","name":"log4j-scan","owner":"fullhunt","full_name":"fullhunt\/log4j-scan","html_url":"https:\/\/github.com\/fullhunt\/log4j-scan","description":"A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228 ","stargazers_count":"2884","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-13 12:57:50","updated_at":"2022-05-22 01:26:13","pushed_at":"2022-05-17 22:25:17","inserted_at":null},{"id":"18537678","cve_id":"CVE-2014-0160","name":"Heartbleed","owner":"FiloSottile","full_name":"FiloSottile\/Heartbleed","html_url":"https:\/\/github.com\/FiloSottile\/Heartbleed","description":"A checker (site and tool) for CVE-2014-0160","stargazers_count":"2273","vuln_description":"The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.","created_at":"2014-04-08 08:03:09","updated_at":"2022-05-19 19:38:37","pushed_at":"2021-02-24 18:17:24","inserted_at":null},{"id":"210457246","cve_id":"CVE-2019-11043","name":"phuip-fpizdam","owner":"neex","full_name":"neex\/phuip-fpizdam","html_url":"https:\/\/github.com\/neex\/phuip-fpizdam","description":"Exploit for CVE-2019-11043","stargazers_count":"1718","vuln_description":"In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.","created_at":"2019-09-24 06:37:27","updated_at":"2022-05-17 14:49:17","pushed_at":"2019-11-13 03:53:14","inserted_at":null},{"id":"381444656","cve_id":"CVE-2021-1675","name":"CVE-2021-1675","owner":"cube0x0","full_name":"cube0x0\/CVE-2021-1675","html_url":"https:\/\/github.com\/cube0x0\/CVE-2021-1675","description":"C# and Impacket implementation of PrintNightmare CVE-2021-1675\/CVE-2021-34527","stargazers_count":"1565","vuln_description":"Windows Print Spooler Elevation of Privilege Vulnerability","created_at":"2021-06-30 02:24:14","updated_at":"2022-05-19 05:49:35","pushed_at":"2021-07-21 00:28:13","inserted_at":null},{"id":"452081015","cve_id":"CVE-2021-4034","name":"CVE-2021-4034","owner":"berdav","full_name":"berdav\/CVE-2021-4034","html_url":"https:\/\/github.com\/berdav\/CVE-2021-4034","description":"CVE-2021-4034 1day","stargazers_count":"1530","vuln_description":"A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.","created_at":"2022-01-26 08:51:37","updated_at":"2022-05-20 20:32:46","pushed_at":"2022-01-30 23:22:23","inserted_at":null},{"id":"293756101","cve_id":"CVE-2020-1472","name":"CVE-2020-1472","owner":"SecuraBV","full_name":"SecuraBV\/CVE-2020-1472","html_url":"https:\/\/github.com\/SecuraBV\/CVE-2020-1472","description":"Test tool for CVE-2020-1472","stargazers_count":"1453","vuln_description":"An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka 'Netlogon Elevation of Privilege Vulnerability'.","created_at":"2020-09-08 17:58:37","updated_at":"2022-05-18 08:29:16","pushed_at":"2021-12-08 19:31:54","inserted_at":null},{"id":"405152543","cve_id":"CVE-2021-40444","name":"CVE-2021-40444","owner":"lockedbyte","full_name":"lockedbyte\/CVE-2021-40444","html_url":"https:\/\/github.com\/lockedbyte\/CVE-2021-40444","description":"CVE-2021-40444 PoC","stargazers_count":"1413","vuln_description":"Microsoft MSHTML Remote Code Execution Vulnerability","created_at":"2021-09-11 01:55:53","updated_at":"2022-05-20 05:29:27","pushed_at":"2021-12-26 03:31:02","inserted_at":null},{"id":"233997916","cve_id":"CVE-2014-4210","name":"weblogicScanner","owner":"0xn0ne","full_name":"0xn0ne\/weblogicScanner","html_url":"https:\/\/github.com\/0xn0ne\/weblogicScanner","description":"weblogic \u6f0f\u6d1e\u626b\u63cf\u5de5\u5177\u3002\u76ee\u524d\u5305\u542b\u5bf9\u4ee5\u4e0b\u6f0f\u6d1e\u7684\u68c0\u6d4b\u80fd\u529b\uff1aCVE-2014-4210\u3001CVE-2016-0638\u3001CVE-2016-3510\u3001CVE-2017-3248\u3001CVE-2017-3506\u3001CVE-2017-10271\u3001CVE-2018-2628\u3001CVE-2018-2893\u3001CVE-2018-2894\u3001CVE-2018-3191\u3001CVE-2018-3245\u3001CVE-2018-3252\u3001CVE-2019-2618\u3001CVE-2019-2725\u3001CVE-2019-2729\u3001CVE-2019-2890\u3001CVE-2020-2551\u3001CVE-2020-14882\u3001CVE-2020-14883","stargazers_count":"1363","vuln_description":"Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.","created_at":"2020-01-15 13:26:29","updated_at":"2022-05-21 23:25:20","pushed_at":"2020-11-28 00:10:58","inserted_at":null},{"id":"437139341","cve_id":"CVE-2021-44228","name":"log4j-shell-poc","owner":"kozmer","full_name":"kozmer\/log4j-shell-poc","html_url":"https:\/\/github.com\/kozmer\/log4j-shell-poc","description":"A Proof-Of-Concept for the CVE-2021-44228 vulnerability. ","stargazers_count":"1362","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-11 08:19:28","updated_at":"2022-05-20 22:23:21","pushed_at":"2022-03-21 01:33:49","inserted_at":null},{"id":"251287681","cve_id":"CVE-2020-0796","name":"CVE-2020-0796","owner":"danigargu","full_name":"danigargu\/CVE-2020-0796","html_url":"https:\/\/github.com\/danigargu\/CVE-2020-0796","description":"CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost","stargazers_count":"1199","vuln_description":"A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client\/Server Remote Code Execution Vulnerability'.","created_at":"2020-03-30 20:42:56","updated_at":"2022-05-21 19:58:26","pushed_at":"2020-12-08 05:04:27","inserted_at":null},{"id":"189265014","cve_id":"CVE-2019-0708","name":"BlueKeep","owner":"Ekultek","full_name":"Ekultek\/BlueKeep","html_url":"https:\/\/github.com\/Ekultek\/BlueKeep","description":"Proof of concept for CVE-2019-0708","stargazers_count":"1114","vuln_description":"A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.","created_at":"2019-05-30 01:53:54","updated_at":"2022-05-14 18:35:38","pushed_at":"2021-12-02 21:00:46","inserted_at":null},{"id":"437370545","cve_id":"CVE-2021-42287","name":"noPac","owner":"cube0x0","full_name":"cube0x0\/noPac","html_url":"https:\/\/github.com\/cube0x0\/noPac","description":"CVE-2021-42287\/CVE-2021-42278 Scanner & Exploiter.","stargazers_count":"1093","vuln_description":"Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291.","created_at":"2021-12-12 04:27:30","updated_at":"2022-05-21 18:14:11","pushed_at":"2021-12-16 18:50:15","inserted_at":null},{"id":"436974241","cve_id":"CVE-2021-44228","name":"log4shell-vulnerable-app","owner":"christophetd","full_name":"christophetd\/log4shell-vulnerable-app","html_url":"https:\/\/github.com\/christophetd\/log4shell-vulnerable-app","description":"Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).","stargazers_count":"984","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-10 21:38:20","updated_at":"2022-05-19 18:29:52","pushed_at":"2022-02-24 21:04:51","inserted_at":null},{"id":"346861222","cve_id":"CVE-2020-14883","name":"PocList","owner":"1n7erface","full_name":"1n7erface\/PocList","html_url":"https:\/\/github.com\/1n7erface\/PocList","description":"Alibaba-Nacos-Unauthorized\/ApacheDruid-RCE_CVE-2021-25646\/MS-Exchange-SSRF-CVE-2021-26885\/Oracle-WebLogic-CVE-2021-2109_RCE\/RG-CNVD-2021-14536\/RJ-SSL-VPN-UltraVires\/Redis-Unauthorized-RCE\/TDOA-V11.7-GetOnlineCookie\/VMware-vCenter-GetAnyFile\/yongyou-GRP-U8-XXE\/Oracle-WebLogic-CVE-2020-14883\/Oracle-WebLogic-CVE-2020-14882\/Apache-Solr-GetAnyFile\/F5-BIG-IP-CVE-2021-22986\/Sonicwall-SSL-VPN-RCE\/GitLab-Graphql-CNVD-2021-14193\/D-Link-DCS-CVE-2020-25078\/WLAN-AP-WEA453e-RCE\/360TianQing-Unauthorized\/360TianQing-SQLinj","stargazers_count":"952","vuln_description":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H).","created_at":"2021-03-12 07:49:17","updated_at":"2022-05-16 15:51:16","pushed_at":"2021-07-30 12:28:00","inserted_at":null},{"id":"467221382","cve_id":"CVE-2022-0847","name":"CVE-2022-0847-DirtyPipe-Exploit","owner":"Arinerron","full_name":"Arinerron\/CVE-2022-0847-DirtyPipe-Exploit","html_url":"https:\/\/github.com\/Arinerron\/CVE-2022-0847-DirtyPipe-Exploit","description":"A root exploit for CVE-2022-0847 (Dirty Pipe)","stargazers_count":"943","vuln_description":"A flaw was found in the way the \"flags\" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.","created_at":"2022-03-08 03:55:20","updated_at":"2022-05-17 15:23:45","pushed_at":"2022-03-08 15:20:05","inserted_at":null},{"id":"295481822","cve_id":"CVE-2020-1472","name":"CVE-2020-1472","owner":"dirkjanm","full_name":"dirkjanm\/CVE-2020-1472","html_url":"https:\/\/github.com\/dirkjanm\/CVE-2020-1472","description":"PoC for Zerologon - all research credits go to Tom Tervoort of Secura","stargazers_count":"930","vuln_description":"An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka 'Netlogon Elevation of Privilege Vulnerability'.","created_at":"2020-09-15 01:56:51","updated_at":"2022-05-20 03:05:13","pushed_at":"2020-11-03 18:45:24","inserted_at":null},{"id":"382182179","cve_id":"CVE-2021-1675","name":"CVE-2021-1675","owner":"calebstewart","full_name":"calebstewart\/CVE-2021-1675","html_url":"https:\/\/github.com\/calebstewart\/CVE-2021-1675","description":"Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)","stargazers_count":"911","vuln_description":"Windows Print Spooler Elevation of Privilege Vulnerability","created_at":"2021-07-02 08:45:58","updated_at":"2023-06-09 04:59:35","pushed_at":"2021-07-05 17:54:06","inserted_at":"2023-06-09 21:37:00"},{"id":"71558821","cve_id":"CVE-2016-5195","name":"CVE-2016-5195","owner":"timwr","full_name":"timwr\/CVE-2016-5195","html_url":"https:\/\/github.com\/timwr\/CVE-2016-5195","description":"CVE-2016-5195 (dirtycow\/dirtyc0w) proof of concept for Android","stargazers_count":"902","vuln_description":"Race condition in mm\/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka \"Dirty COW.\"","created_at":"2016-10-21 20:19:21","updated_at":"2022-05-20 22:54:03","pushed_at":"2021-02-04 01:03:40","inserted_at":null},{"id":"234191063","cve_id":"CVE-2020-0601","name":"CurveBall","owner":"ly4k","full_name":"ly4k\/CurveBall","html_url":"https:\/\/github.com\/ly4k\/CurveBall","description":"PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll)","stargazers_count":"876","vuln_description":"A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.","created_at":"2020-01-16 08:07:41","updated_at":"2022-05-13 01:55:27","pushed_at":"2020-01-21 08:33:19","inserted_at":null},{"id":"188316989","cve_id":"CVE-2019-0708","name":"rdpscan","owner":"robertdavidgraham","full_name":"robertdavidgraham\/rdpscan","html_url":"https:\/\/github.com\/robertdavidgraham\/rdpscan","description":"A quick scanner for the CVE-2019-0708 \"BlueKeep\" vulnerability.","stargazers_count":"855","vuln_description":"A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.","created_at":"2019-05-24 07:50:12","updated_at":"2022-04-29 19:27:49","pushed_at":"2019-06-23 06:48:45","inserted_at":null},{"id":"452094681","cve_id":"CVE-2021-4034","name":"CVE-2021-4034","owner":"arthepsy","full_name":"arthepsy\/CVE-2021-4034","html_url":"https:\/\/github.com\/arthepsy\/CVE-2021-4034","description":"PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit\u2019s pkexec (CVE-2021-4034)","stargazers_count":"854","vuln_description":"A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.","created_at":"2022-01-26 09:56:36","updated_at":"2022-05-19 06:00:16","pushed_at":"2022-02-12 14:22:58","inserted_at":null},{"id":"437261211","cve_id":"CVE-2021-44228","name":"CVE-2021-44228-Scanner","owner":"logpresso","full_name":"logpresso\/CVE-2021-44228-Scanner","html_url":"https:\/\/github.com\/logpresso\/CVE-2021-44228-Scanner","description":"Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228","stargazers_count":"815","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-11 20:18:46","updated_at":"2022-05-18 23:16:36","pushed_at":"2022-04-07 23:47:03","inserted_at":null},{"id":"367930039","cve_id":"CVE-2021-31166","name":"CVE-2021-31166","owner":"0vercl0k","full_name":"0vercl0k\/CVE-2021-31166","html_url":"https:\/\/github.com\/0vercl0k\/CVE-2021-31166","description":"Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.","stargazers_count":"814","vuln_description":"HTTP Protocol Stack Remote Code Execution Vulnerability","created_at":"2021-05-17 01:15:56","updated_at":"2022-05-21 15:45:16","pushed_at":"2021-06-12 17:27:09","inserted_at":null},{"id":"193069571","cve_id":"CVE-2019-2618","name":"WeblogicScan","owner":"dr0op","full_name":"dr0op\/WeblogicScan","html_url":"https:\/\/github.com\/dr0op\/WeblogicScan","description":"\u589e\u5f3a\u7248WeblogicScan\u3001\u68c0\u6d4b\u7ed3\u679c\u66f4\u7cbe\u786e\u3001\u63d2\u4ef6\u5316\u3001\u6dfb\u52a0CVE-2019-2618\uff0cCVE-2019-2729\u68c0\u6d4b\uff0cPython3\u652f\u6301","stargazers_count":"807","vuln_description":"Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:L\/A:N).","created_at":"2019-06-21 18:22:43","updated_at":"2022-05-19 17:03:09","pushed_at":"2020-04-26 19:49:25","inserted_at":null},{"id":"437314230","cve_id":"CVE-2021-42278","name":"sam-the-admin","owner":"WazeHell","full_name":"WazeHell\/sam-the-admin","html_url":"https:\/\/github.com\/WazeHell\/sam-the-admin","description":"Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user ","stargazers_count":"801","vuln_description":"Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291.","created_at":"2021-12-12 00:10:30","updated_at":"2022-05-21 18:21:52","pushed_at":"2022-03-19 01:32:13","inserted_at":null},{"id":"437131550","cve_id":"CVE-2021-44228","name":"CVE-2021-44228-PoC-log4j-bypass-words","owner":"Puliczek","full_name":"Puliczek\/CVE-2021-44228-PoC-log4j-bypass-words","html_url":"https:\/\/github.com\/Puliczek\/CVE-2021-44228-PoC-log4j-bypass-words","description":"\ud83d\udc31\u200d\ud83d\udcbb \u2702\ufe0f \ud83e\udd2c CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks","stargazers_count":"759","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-11 07:35:00","updated_at":"2022-05-19 19:41:55","pushed_at":"2022-01-16 01:18:44","inserted_at":null},{"id":"206106300","cve_id":"CVE-2019-12586","name":"esp32_esp8266_attacks","owner":"Matheus-Garbelini","full_name":"Matheus-Garbelini\/esp32_esp8266_attacks","html_url":"https:\/\/github.com\/Matheus-Garbelini\/esp32_esp8266_attacks","description":"Proof of Concept of ESP32\/8266 Wi-Fi vulnerabilties (CVE-2019-12586, CVE-2019-12587, CVE-2019-12588)","stargazers_count":"726","vuln_description":"The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.","created_at":"2019-09-04 00:08:49","updated_at":"2022-05-01 01:24:41","pushed_at":"2019-09-08 15:09:11","inserted_at":null},{"id":"116195445","cve_id":"CVE-2017-5753","name":"spectre-attack","owner":"Eugnis","full_name":"Eugnis\/spectre-attack","html_url":"https:\/\/github.com\/Eugnis\/spectre-attack","description":"Example of using revealed \"Spectre\" exploit (CVE-2017-5753 and CVE-2017-5715)","stargazers_count":"711","vuln_description":"Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.","created_at":"2018-01-04 09:28:50","updated_at":"2022-05-19 06:32:24","pushed_at":"2018-01-10 10:14:44","inserted_at":null},{"id":"383254488","cve_id":"CVE-2021-34527","name":"ItWasAllADream","owner":"byt3bl33d3r","full_name":"byt3bl33d3r\/ItWasAllADream","html_url":"https:\/\/github.com\/byt3bl33d3r\/ItWasAllADream","description":"A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE","stargazers_count":"701","vuln_description":"Windows Print Spooler Remote Code Execution Vulnerability","created_at":"2021-07-06 05:13:49","updated_at":"2022-12-10 03:44:36","pushed_at":"2022-12-07 21:52:32","inserted_at":"2022-12-10 09:40:36"},{"id":"88486475","cve_id":"CVE-2017-0199","name":"CVE-2017-0199","owner":"bhdresh","full_name":"bhdresh\/CVE-2017-0199","html_url":"https:\/\/github.com\/bhdresh\/CVE-2017-0199","description":"Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE. It could generate a malicious RTF\/PPSX file and deliver metasploit \/ meterpreter \/ other payload to victim without any complex configuration.","stargazers_count":"677","vuln_description":"Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka \"Microsoft Office\/WordPad Remote Code Execution Vulnerability w\/Windows API.\"","created_at":"2017-04-17 17:10:07","updated_at":"2022-05-13 21:18:39","pushed_at":"2017-11-19 20:01:16","inserted_at":null},{"id":"482104718","cve_id":"CVE-2022-29072","name":"CVE-2022-29072","owner":"kagancapar","full_name":"kagancapar\/CVE-2022-29072","html_url":"https:\/\/github.com\/kagancapar\/CVE-2022-29072","description":"7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area.","stargazers_count":"665","vuln_description":"** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur.","created_at":"2022-04-16 07:59:03","updated_at":"2022-05-21 12:37:58","pushed_at":"2022-04-22 20:26:31","inserted_at":null},{"id":"164948400","cve_id":"CVE-2019-6447","name":"ESFileExplorerOpenPortVuln","owner":"fs0c131y","full_name":"fs0c131y\/ESFileExplorerOpenPortVuln","html_url":"https:\/\/github.com\/fs0c131y\/ESFileExplorerOpenPortVuln","description":"ES File Explorer Open Port Vulnerability - CVE-2019-6447","stargazers_count":"649","vuln_description":"The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application\/json data over HTTP.","created_at":"2019-01-10 07:30:42","updated_at":"2022-05-05 21:35:08","pushed_at":"2021-09-01 17:56:40","inserted_at":null},{"id":"437419010","cve_id":"CVE-2021-44228","name":"log4j-detector","owner":"mergebase","full_name":"mergebase\/log4j-detector","html_url":"https:\/\/github.com\/mergebase\/log4j-detector","description":"Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too!","stargazers_count":"625","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-12 09:29:03","updated_at":"2022-05-12 16:11:35","pushed_at":"2022-03-11 03:44:50","inserted_at":null},{"id":"170261590","cve_id":"CVE-2019-7304","name":"dirty_sock","owner":"initstring","full_name":"initstring\/dirty_sock","html_url":"https:\/\/github.com\/initstring\/dirty_sock","description":"Linux privilege escalation exploit via snapd (CVE-2019-7304)","stargazers_count":"623","vuln_description":"Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.","created_at":"2019-02-12 15:02:06","updated_at":"2022-05-20 03:25:35","pushed_at":"2019-05-10 06:34:26","inserted_at":null},{"id":"272659155","cve_id":"CVE-2020-0787","name":"CVE-2020-0787-EXP-ALL-WINDOWS-VERSION","owner":"cbwang505","full_name":"cbwang505\/CVE-2020-0787-EXP-ALL-WINDOWS-VERSION","html_url":"https:\/\/github.com\/cbwang505\/CVE-2020-0787-EXP-ALL-WINDOWS-VERSION","description":"Support ALL Windows Version","stargazers_count":"621","vuln_description":"An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.","created_at":"2020-06-16 17:57:51","updated_at":"2022-05-18 12:35:14","pushed_at":"2020-09-11 16:38:22","inserted_at":null},{"id":"246606759","cve_id":"CVE-2020-0796","name":"SMBGhost","owner":"ly4k","full_name":"ly4k\/SMBGhost","html_url":"https:\/\/github.com\/ly4k\/SMBGhost","description":"Scanner for CVE-2020-0796 - SMBv3 RCE","stargazers_count":"618","vuln_description":"A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client\/Server Remote Code Execution Vulnerability'.","created_at":"2020-03-12 00:21:27","updated_at":"2022-04-28 11:48:43","pushed_at":"2020-10-01 17:36:29","inserted_at":null},{"id":"74788180","cve_id":"CVE-2016-5195","name":"dirtycow","owner":"firefart","full_name":"firefart\/dirtycow","html_url":"https:\/\/github.com\/firefart\/dirtycow","description":"Dirty Cow exploit - CVE-2016-5195","stargazers_count":"603","vuln_description":"Race condition in mm\/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka \"Dirty COW.\"","created_at":"2016-11-26 06:08:01","updated_at":"2022-05-19 15:57:05","pushed_at":"2021-04-08 20:35:12","inserted_at":null},{"id":"406942491","cve_id":"CVE-2021-40444","name":"CVE-2021-40444","owner":"klezVirus","full_name":"klezVirus\/CVE-2021-40444","html_url":"https:\/\/github.com\/klezVirus\/CVE-2021-40444","description":"CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit","stargazers_count":"600","vuln_description":"Microsoft MSHTML Remote Code Execution Vulnerability","created_at":"2021-09-16 07:34:35","updated_at":"2022-05-31 20:47:51","pushed_at":"2022-05-31 17:53:53","inserted_at":"2022-05-31 21:38:00"},{"id":"211619802","cve_id":"CVE-2019-11708","name":"CVE-2019-11708","owner":"0vercl0k","full_name":"0vercl0k\/CVE-2019-11708","html_url":"https:\/\/github.com\/0vercl0k\/CVE-2019-11708","description":"Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.","stargazers_count":"599","vuln_description":"Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.","created_at":"2019-09-29 16:08:52","updated_at":"2022-05-07 04:22:17","pushed_at":"2020-06-14 02:40:14","inserted_at":null},{"id":"457033886","cve_id":"CVE-2022-21999","name":"SpoolFool","owner":"ly4k","full_name":"ly4k\/SpoolFool","html_url":"https:\/\/github.com\/ly4k\/SpoolFool","description":"Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)","stargazers_count":"591","vuln_description":"Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-22717, CVE-2022-22718.","created_at":"2022-02-09 02:25:44","updated_at":"2022-05-21 16:04:06","pushed_at":"2022-02-10 01:54:09","inserted_at":null},{"id":"170445833","cve_id":"CVE-2019-5736","name":"CVE-2019-5736-PoC","owner":"Frichetten","full_name":"Frichetten\/CVE-2019-5736-PoC","html_url":"https:\/\/github.com\/Frichetten\/CVE-2019-5736-PoC","description":"PoC for CVE-2019-5736","stargazers_count":"583","vuln_description":"runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to \/proc\/self\/exe.","created_at":"2019-02-13 14:26:32","updated_at":"2022-05-17 11:17:05","pushed_at":"2022-01-05 13:09:42","inserted_at":null},{"id":"18553786","cve_id":"CVE-2014-0160","name":"heartbleed-masstest","owner":"musalbas","full_name":"musalbas\/heartbleed-masstest","html_url":"https:\/\/github.com\/musalbas\/heartbleed-masstest","description":"Multi-threaded tool for scanning many hosts for CVE-2014-0160.","stargazers_count":"578","vuln_description":"The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.","created_at":"2014-04-08 19:10:43","updated_at":"2022-04-15 23:33:30","pushed_at":"2015-07-02 23:47:31","inserted_at":null},{"id":"51472663","cve_id":"CVE-2015-7547","name":"CVE-2015-7547","owner":"fjserna","full_name":"fjserna\/CVE-2015-7547","html_url":"https:\/\/github.com\/fjserna\/CVE-2015-7547","description":"Proof of concept for CVE-2015-7547","stargazers_count":"551","vuln_description":"Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing \"dual A\/AAAA DNS queries\" and the libnss_dns.so.2 NSS module.","created_at":"2016-02-11 06:13:54","updated_at":"2021-12-09 11:28:33","pushed_at":"2016-02-20 16:57:58","inserted_at":null},{"id":"233151210","cve_id":"CVE-2019-19781","name":"cve-2019-19781","owner":"trustedsec","full_name":"trustedsec\/cve-2019-19781","html_url":"https:\/\/github.com\/trustedsec\/cve-2019-19781","description":"This is a tool published for the Citrix ADC (NetScaler) vulnerability. We are only disclosing this due to others publishing the exploit code first.","stargazers_count":"551","vuln_description":"An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.","created_at":"2020-01-11 09:08:27","updated_at":"2022-05-21 22:58:12","pushed_at":"2020-01-23 05:23:51","inserted_at":null},{"id":"116214746","cve_id":"CVE-2017-5754","name":"SpecuCheck","owner":"ionescu007","full_name":"ionescu007\/SpecuCheck","html_url":"https:\/\/github.com\/ionescu007\/SpecuCheck","description":"SpecuCheck is a Windows utility for checking the state of the software mitigations and hardware against  CVE-2017-5754 (Meltdown), CVE-2017-5715 (Spectre v2), CVE-2018-3260 (Foreshadow), and CVE-2018-3639 (Spectre v4)","stargazers_count":"548","vuln_description":"Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.","created_at":"2018-01-04 13:32:26","updated_at":"2022-05-17 20:40:36","pushed_at":"2019-11-19 12:36:46","inserted_at":null},{"id":"229491909","cve_id":"CVE-2018-5955","name":"Cerberus","owner":"YagamiiLight","full_name":"YagamiiLight\/Cerberus","html_url":"https:\/\/github.com\/YagamiiLight\/Cerberus","description":"\u4e00\u6b3e\u529f\u80fd\u5f3a\u5927\u7684\u6f0f\u6d1e\u626b\u63cf\u5668\uff0c\u5b50\u57df\u540d\u7206\u7834\u4f7f\u7528aioDNS\uff0casyncio\u5f02\u6b65\u5feb\u901f\u626b\u63cf\uff0c\u8986\u76d6\u76ee\u6807\u5168\u65b9\u4f4d\u8d44\u4ea7\u8fdb\u884c\u6279\u91cf\u6f0f\u6d1e\u626b\u63cf\uff0c\u4e2d\u95f4\u4ef6\u4fe1\u606f\u6536\u96c6\uff0c\u81ea\u52a8\u6536\u96c6ip\u4ee3\u7406\uff0c\u63a2\u6d4bWaf\u4fe1\u606f\u65f6\u81ea\u52a8\u4f7f\u7528\u6765\u4fdd\u62a4\u672c\u673a\u771f\u5b9eIp\uff0c\u5728\u672c\u673aIp\u88abWaf\u6740\u6b7b\u540e\uff0c\u81ea\u52a8\u5207\u6362\u4ee3\u7406Ip\u8fdb\u884c\u626b\u63cf\uff0cWaf\u4fe1\u606f\u6536\u96c6(\u56fd\u5185\u5916100+\u6b3ewaf\u4fe1\u606f)\u5305\u62ec\u5b89\u5168\u72d7\uff0c\u4e91\u9501\uff0c\u963f\u91cc\u4e91\uff0c\u4e91\u76fe\uff0c\u817e\u8baf\u4e91\u7b49\uff0c\u63d0\u4f9b\u90e8\u5206\u5df2\u77e5waf bypass \u65b9\u6848\uff0c\u4e2d\u95f4\u4ef6\u6f0f\u6d1e\u68c0\u6d4b(Thinkphp,weblogic\u7b49 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759\u7b49)\uff0c\u652f\u6301SQL\u6ce8\u5165, XSS, \u547d\u4ee4\u6267\u884c,\u6587\u4ef6\u5305\u542b, ssrf \u6f0f\u6d1e\u626b\u63cf, \u652f\u6301\u81ea\u5b9a\u4e49\u6f0f\u6d1e\u90ae\u7bb1\u63a8\u9001\u529f\u80fd","stargazers_count":"548","vuln_description":"An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest\/user\/ URI.","created_at":"2019-12-22 07:45:55","updated_at":"2022-05-20 17:42:22","pushed_at":"2020-01-06 06:46:25","inserted_at":null},{"id":"116319052","cve_id":"CVE-2017-5754","name":"Am-I-affected-by-Meltdown","owner":"raphaelsc","full_name":"raphaelsc\/Am-I-affected-by-Meltdown","html_url":"https:\/\/github.com\/raphaelsc\/Am-I-affected-by-Meltdown","description":"Meltdown Exploit \/ Proof-of-concept \/ checks whether system is affected by Variant 3: rogue data cache load (CVE-2017-5754), a.k.a MELTDOWN.","stargazers_count":"546","vuln_description":"Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.","created_at":"2018-01-05 08:51:12","updated_at":"2022-04-28 04:26:18","pushed_at":"2018-02-27 14:22:38","inserted_at":null},{"id":"111505810","cve_id":"CVE-2017-11882","name":"CVE-2017-11882","owner":"Ridter","full_name":"Ridter\/CVE-2017-11882","html_url":"https:\/\/github.com\/Ridter\/CVE-2017-11882","description":"CVE-2017-11882 from https:\/\/github.com\/embedi\/CVE-2017-11882","stargazers_count":"526","vuln_description":"Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka \"Microsoft Office Memory Corruption Vulnerability\". This CVE ID is unique from CVE-2017-11884.","created_at":"2017-11-21 14:55:53","updated_at":"2022-05-20 17:26:51","pushed_at":"2017-11-29 12:33:53","inserted_at":null},{"id":"129319611","cve_id":"CVE-2018-7600","name":"Drupalgeddon2","owner":"dreadlocked","full_name":"dreadlocked\/Drupalgeddon2","html_url":"https:\/\/github.com\/dreadlocked\/Drupalgeddon2","description":"Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 \/ CVE-2018-7600 \/ SA-CORE-2018-002)","stargazers_count":"523","vuln_description":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.","created_at":"2018-04-13 07:53:14","updated_at":"2022-05-20 03:17:09","pushed_at":"2021-01-08 19:31:22","inserted_at":null},{"id":"452306200","cve_id":"CVE-2021-4034","name":"PwnKit","owner":"ly4k","full_name":"ly4k\/PwnKit","html_url":"https:\/\/github.com\/ly4k\/PwnKit","description":"Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation","stargazers_count":"508","vuln_description":"A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.","created_at":"2022-01-26 23:26:10","updated_at":"2022-05-21 17:04:45","pushed_at":"2022-01-28 05:09:24","inserted_at":null},{"id":"348065462","cve_id":"CVE-2021-3156","name":"CVE-2021-3156","owner":"worawit","full_name":"worawit\/CVE-2021-3156","html_url":"https:\/\/github.com\/worawit\/CVE-2021-3156","description":"Sudo Baron Samedit Exploit","stargazers_count":"498","vuln_description":"Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via \"sudoedit -s\" and a command-line argument that ends with a single backslash character.","created_at":"2021-03-16 02:37:02","updated_at":"2022-05-17 08:41:05","pushed_at":"2022-01-13 14:48:01","inserted_at":null},{"id":"111435936","cve_id":"CVE-2017-11882","name":"CVE-2017-11882","owner":"embedi","full_name":"embedi\/CVE-2017-11882","html_url":"https:\/\/github.com\/embedi\/CVE-2017-11882","description":"Proof-of-Concept exploits for CVE-2017-11882","stargazers_count":"495","vuln_description":"Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka \"Microsoft Office Memory Corruption Vulnerability\". This CVE ID is unique from CVE-2017-11884.","created_at":"2017-11-21 01:35:30","updated_at":"2022-04-29 15:50:25","pushed_at":"2017-11-30 01:13:23","inserted_at":null},{"id":"145483388","cve_id":"CVE-2018-15473","name":"CVE-2018-15473-Exploit","owner":"Rhynorater","full_name":"Rhynorater\/CVE-2018-15473-Exploit","html_url":"https:\/\/github.com\/Rhynorater\/CVE-2018-15473-Exploit","description":"Exploit written in Python for CVE-2018-15473 with threading and export formats","stargazers_count":"489","vuln_description":"OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.","created_at":"2018-08-21 09:09:56","updated_at":"2022-05-09 13:54:06","pushed_at":"2021-11-08 11:19:03","inserted_at":null},{"id":"437426386","cve_id":"CVE-2021-44228","name":"hotpatch-for-apache-log4j2","owner":"corretto","full_name":"corretto\/hotpatch-for-apache-log4j2","html_url":"https:\/\/github.com\/corretto\/hotpatch-for-apache-log4j2","description":"An  agent to hotpatch the log4j RCE from CVE-2021-44228.","stargazers_count":"488","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-12 10:24:51","updated_at":"2022-05-17 23:04:55","pushed_at":"2022-01-25 21:58:27","inserted_at":null},{"id":"187779603","cve_id":"CVE-2019-0708","name":"CVE-2019-0708","owner":"n1xbyte","full_name":"n1xbyte\/CVE-2019-0708","html_url":"https:\/\/github.com\/n1xbyte\/CVE-2019-0708","description":"dump","stargazers_count":"480","vuln_description":"A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.","created_at":"2019-05-21 15:57:19","updated_at":"2022-05-08 01:58:49","pushed_at":"2019-06-01 14:15:11","inserted_at":null},{"id":"153468806","cve_id":"CVE-2018-10933","name":"CVE-2018-10933","owner":"blacknbunny","full_name":"blacknbunny\/CVE-2018-10933","html_url":"https:\/\/github.com\/blacknbunny\/CVE-2018-10933","description":"Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)","stargazers_count":"479","vuln_description":"A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.","created_at":"2018-10-17 23:14:12","updated_at":"2022-05-19 01:30:08","pushed_at":"2022-03-30 06:56:08","inserted_at":null},{"id":"171996551","cve_id":"CVE-2018-20250","name":"CVE-2018-20250","owner":"WyAtu","full_name":"WyAtu\/CVE-2018-20250","html_url":"https:\/\/github.com\/WyAtu\/CVE-2018-20250","description":"exp for https:\/\/research.checkpoint.com\/extracting-code-execution-from-winrar","stargazers_count":"479","vuln_description":"In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.","created_at":"2019-02-22 13:52:08","updated_at":"2022-05-07 17:03:03","pushed_at":"2019-08-05 19:45:34","inserted_at":null},{"id":"134023459","cve_id":"CVE-2018-8120","name":"CVE-2018-8120","owner":"unamer","full_name":"unamer\/CVE-2018-8120","html_url":"https:\/\/github.com\/unamer\/CVE-2018-8120","description":"CVE-2018-8120 Windows LPE exploit","stargazers_count":"476","vuln_description":"An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k Elevation of Privilege Vulnerability.\" This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.","created_at":"2018-05-19 11:43:15","updated_at":"2022-05-13 13:18:35","pushed_at":"2018-05-30 22:09:54","inserted_at":null},{"id":"131525463","cve_id":"CVE-2018-9995","name":"CVE-2018-9995_dvr_credentials","owner":"ezelf","full_name":"ezelf\/CVE-2018-9995_dvr_credentials","html_url":"https:\/\/github.com\/ezelf\/CVE-2018-9995_dvr_credentials","description":"(CVE-2018-9995) Get DVR Credentials","stargazers_count":"472","vuln_description":"TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a \"Cookie: uid=admin\" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.","created_at":"2018-04-30 05:00:06","updated_at":"2022-05-21 01:40:05","pushed_at":"2019-01-23 23:27:21","inserted_at":null},{"id":"138456315","cve_id":"CVE-2018-14847","name":"WinboxPoC","owner":"BasuCert","full_name":"BasuCert\/WinboxPoC","html_url":"https:\/\/github.com\/BasuCert\/WinboxPoC","description":"Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)","stargazers_count":"466","vuln_description":"MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.","created_at":"2018-06-24 14:34:05","updated_at":"2022-05-18 04:48:15","pushed_at":"2020-10-16 21:09:45","inserted_at":null},{"id":"474473639","cve_id":"CVE-2022-0995","name":"CVE-2022-0995","owner":"Bonfee","full_name":"Bonfee\/CVE-2022-0995","html_url":"https:\/\/github.com\/Bonfee\/CVE-2022-0995","description":"CVE-2022-0995 exploit","stargazers_count":"463","vuln_description":"An out-of-bounds (OOB) memory write flaw was found in the Linux kernel\u2019s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.","created_at":"2022-03-27 06:46:09","updated_at":"2022-05-15 15:19:48","pushed_at":"2022-03-27 18:07:01","inserted_at":null},{"id":"257308744","cve_id":"CVE-2020-0796","name":"CVE-2020-0796-RCE-POC","owner":"ZecOps","full_name":"ZecOps\/CVE-2020-0796-RCE-POC","html_url":"https:\/\/github.com\/ZecOps\/CVE-2020-0796-RCE-POC","description":"CVE-2020-0796 Remote Code Execution POC","stargazers_count":"461","vuln_description":"A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client\/Server Remote Code Execution Vulnerability'.","created_at":"2020-04-20 23:35:48","updated_at":"2022-05-12 14:02:24","pushed_at":"2020-06-10 05:46:45","inserted_at":null},{"id":"18545207","cve_id":"CVE-2014-0160","name":"heartbleeder","owner":"titanous","full_name":"titanous\/heartbleeder","html_url":"https:\/\/github.com\/titanous\/heartbleeder","description":"OpenSSL CVE-2014-0160 Heartbleed vulnerability test","stargazers_count":"452","vuln_description":"The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.","created_at":"2014-04-08 13:25:23","updated_at":"2021-10-24 15:26:48","pushed_at":"2014-05-28 07:32:26","inserted_at":null},{"id":"131405057","cve_id":"CVE-2018-6242","name":"NXLoader","owner":"DavidBuchanan314","full_name":"DavidBuchanan314\/NXLoader","html_url":"https:\/\/github.com\/DavidBuchanan314\/NXLoader","description":"My first Android app: Launch Fus\u00e9e Gel\u00e9e payloads from stock Android (CVE-2018-6242)","stargazers_count":"451","vuln_description":"Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.","created_at":"2018-04-28 20:50:00","updated_at":"2022-05-21 04:20:00","pushed_at":"2018-08-30 14:37:03","inserted_at":null},{"id":"104278164","cve_id":"CVE-2017-0785","name":"CVE-2017-0785","owner":"ojasookert","full_name":"ojasookert\/CVE-2017-0785","html_url":"https:\/\/github.com\/ojasookert\/CVE-2017-0785","description":"Blueborne CVE-2017-0785 Android information leak vulnerability","stargazers_count":"443","vuln_description":"A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.","created_at":"2017-09-21 08:32:29","updated_at":"2022-05-16 18:41:43","pushed_at":"2017-09-23 14:11:45","inserted_at":null},{"id":"417881648","cve_id":"CVE-2021-40449","name":"CallbackHell","owner":"ly4k","full_name":"ly4k\/CallbackHell","html_url":"https:\/\/github.com\/ly4k\/CallbackHell","description":"Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)","stargazers_count":"437","vuln_description":"Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-40450, CVE-2021-41357.","created_at":"2021-10-17 01:17:44","updated_at":"2022-12-31 20:20:51","pushed_at":"2021-11-12 02:09:56","inserted_at":"2023-01-02 21:40:53"},{"id":"334318140","cve_id":"CVE-2021-3156","name":"CVE-2021-3156","owner":"stong","full_name":"stong\/CVE-2021-3156","html_url":"https:\/\/github.com\/stong\/CVE-2021-3156","description":"PoC for CVE-2021-3156 (sudo heap overflow)","stargazers_count":"433","vuln_description":"Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via \"sudoedit -s\" and a command-line argument that ends with a single backslash character.","created_at":"2021-01-30 12:22:04","updated_at":"2022-05-11 18:23:53","pushed_at":"2022-04-14 20:51:18","inserted_at":null},{"id":"295515909","cve_id":"CVE-2020-1472","name":"zerologon","owner":"risksense","full_name":"risksense\/zerologon","html_url":"https:\/\/github.com\/risksense\/zerologon","description":"Exploit for zerologon cve-2020-1472","stargazers_count":"428","vuln_description":"An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka 'Netlogon Elevation of Privilege Vulnerability'.","created_at":"2020-09-15 04:19:07","updated_at":"2022-05-13 17:50:14","pushed_at":"2020-10-16 03:31:15","inserted_at":null},{"id":"438203240","cve_id":"CVE-2021-44228","name":"log4j-finder","owner":"fox-it","full_name":"fox-it\/log4j-finder","html_url":"https:\/\/github.com\/fox-it\/log4j-finder","description":"Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)","stargazers_count":"425","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-14 19:04:42","updated_at":"2022-05-16 18:54:28","pushed_at":"2022-01-28 01:08:20","inserted_at":null},{"id":"189132043","cve_id":"CVE-2019-2725","name":"CVE-2019-2725","owner":"lufeirider","full_name":"lufeirider\/CVE-2019-2725","html_url":"https:\/\/github.com\/lufeirider\/CVE-2019-2725","description":"CVE-2019-2725 \u547d\u4ee4\u56de\u663e","stargazers_count":"421","vuln_description":"Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H).","created_at":"2019-05-29 10:57:05","updated_at":"2022-05-21 14:21:10","pushed_at":"2019-08-08 18:48:20","inserted_at":null},{"id":"452529582","cve_id":"CVE-2022-21882","name":"CVE-2022-21882","owner":"KaLendsi","full_name":"KaLendsi\/CVE-2022-21882","html_url":"https:\/\/github.com\/KaLendsi\/CVE-2022-21882","description":"win32k LPE ","stargazers_count":"414","vuln_description":"Win32k Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21887.","created_at":"2022-01-27 12:44:10","updated_at":"2022-05-17 16:48:04","pushed_at":"2022-01-27 13:18:18","inserted_at":null},{"id":"71647732","cve_id":"CVE-2016-5195","name":"dirtycow-vdso","owner":"scumjr","full_name":"scumjr\/dirtycow-vdso","html_url":"https:\/\/github.com\/scumjr\/dirtycow-vdso","description":"PoC for Dirty COW (CVE-2016-5195)","stargazers_count":"410","vuln_description":"Race condition in mm\/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka \"Dirty COW.\"","created_at":"2016-10-23 00:25:34","updated_at":"2022-05-16 04:07:11","pushed_at":"2022-03-16 21:08:54","inserted_at":null},{"id":"133268202","cve_id":"CVE-2018-8897","name":"CVE-2018-8897","owner":"can1357","full_name":"can1357\/CVE-2018-8897","html_url":"https:\/\/github.com\/can1357\/CVE-2018-8897","description":"Arbitrary code execution with kernel privileges using CVE-2018-8897.","stargazers_count":"406","vuln_description":"A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that transfers control to the ope","created_at":"2018-05-14 04:34:17","updated_at":"2022-04-19 09:15:09","pushed_at":"2018-05-18 21:26:53","inserted_at":null},{"id":"84693026","cve_id":"CVE-2017-5638","name":"struts-pwn","owner":"mazen160","full_name":"mazen160\/struts-pwn","html_url":"https:\/\/github.com\/mazen160\/struts-pwn","description":"An exploit for Apache Struts CVE-2017-5638","stargazers_count":"405","vuln_description":"The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.","created_at":"2017-03-12 11:02:25","updated_at":"2022-05-05 10:57:58","pushed_at":"2018-05-22 03:33:26","inserted_at":null},{"id":"558789477","cve_id":"CVE-2022-3602","name":"OpenSSL-2022","owner":"NCSC-NL","full_name":"NCSC-NL\/OpenSSL-2022","html_url":"https:\/\/github.com\/NCSC-NL\/OpenSSL-2022","description":"Operational information regarding CVE-2022-3602 and CVE-2022-3786, two vulnerabilities in OpenSSL 3","stargazers_count":"396","vuln_description":"A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution. Many platforms implement stack overflow protections which would mitigate against the risk of remote code execution. The risk may be further mitigated based on stack layout for any given platform\/compiler. Pre-announcements of CVE-2022-3602 described this issue as CRITICAL. Further analysis based on some of the mitigating factors described above have led this to be downgraded to HIGH. Users are still encouraged to upgrade to a new version a","created_at":"2022-10-28 18:51:41","updated_at":"2022-11-03 03:15:57","pushed_at":"2022-11-03 02:22:58","inserted_at":"2022-11-03 03:40:06"},{"id":"270575324","cve_id":"CVE-2020-12695","name":"CallStranger","owner":"yunuscadirci","full_name":"yunuscadirci\/CallStranger","html_url":"https:\/\/github.com\/yunuscadirci\/CallStranger","description":"Vulnerability checker for Callstranger (CVE-2020-12695)","stargazers_count":"384","vuln_description":"The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.","created_at":"2020-06-08 16:37:49","updated_at":"2022-05-18 08:44:21","pushed_at":"2021-08-08 01:48:55","inserted_at":null},{"id":"288624943","cve_id":"CVE-2020-2883","name":"WebLogic-Shiro-shell","owner":"Y4er","full_name":"Y4er\/WebLogic-Shiro-shell","html_url":"https:\/\/github.com\/Y4er\/WebLogic-Shiro-shell","description":"WebLogic\u5229\u7528CVE-2020-2883\u6253Shiro rememberMe\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e\uff0c\u4e00\u952e\u6ce8\u518c\u8681\u5251filter\u5185\u5b58shell","stargazers_count":"384","vuln_description":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H).","created_at":"2020-08-19 12:34:06","updated_at":"2022-05-22 01:08:26","pushed_at":"2020-08-25 12:17:32","inserted_at":null},{"id":"77386317","cve_id":"CVE-2016-10033","name":"exploit-CVE-2016-10033","owner":"opsxcq","full_name":"opsxcq\/exploit-CVE-2016-10033","html_url":"https:\/\/github.com\/opsxcq\/exploit-CVE-2016-10033","description":"PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container","stargazers_count":"381","vuln_description":"The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \\\" (backslash double quote) in a crafted Sender property.","created_at":"2016-12-26 22:39:03","updated_at":"2022-05-15 16:12:03","pushed_at":"2019-10-13 21:23:02","inserted_at":null},{"id":"344667460","cve_id":"CVE-2021-1732","name":"CVE-2021-1732-Exploit","owner":"KaLendsi","full_name":"KaLendsi\/CVE-2021-1732-Exploit","html_url":"https:\/\/github.com\/KaLendsi\/CVE-2021-1732-Exploit","description":"CVE-2021-1732 Exploit","stargazers_count":"379","vuln_description":"Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1698.","created_at":"2021-03-05 11:11:10","updated_at":"2022-05-05 11:28:30","pushed_at":"2021-03-05 12:10:26","inserted_at":null},{"id":"646147347","cve_id":"CVE-2023-34312","name":"qq-tim-elevation","owner":"vi3t1","full_name":"vi3t1\/qq-tim-elevation","html_url":"https:\/\/github.com\/vi3t1\/qq-tim-elevation","description":"CVE-2023-34312","stargazers_count":"377","vuln_description":"In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.","created_at":"2023-05-27 21:44:42","updated_at":"2023-07-06 12:18:24","pushed_at":"2023-05-27 21:45:10","inserted_at":"2023-07-06 21:35:19"},{"id":"467109253","cve_id":"CVE-2022-25636","name":"CVE-2022-25636","owner":"Bonfee","full_name":"Bonfee\/CVE-2022-25636","html_url":"https:\/\/github.com\/Bonfee\/CVE-2022-25636","description":"CVE-2022-25636","stargazers_count":"375","vuln_description":"net\/netfilter\/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.","created_at":"2022-03-07 22:38:41","updated_at":"2022-05-06 22:22:14","pushed_at":"2022-03-08 02:18:19","inserted_at":null},{"id":"186849775","cve_id":"CVE-2019-0708","name":"CVE-2019-0708","owner":"k8gege","full_name":"k8gege\/CVE-2019-0708","html_url":"https:\/\/github.com\/k8gege\/CVE-2019-0708","description":"3389\u8fdc\u7a0b\u684c\u9762\u4ee3\u7801\u6267\u884c\u6f0f\u6d1eCVE-2019-0708\u6279\u91cf\u68c0\u6d4b\u5de5\u5177(Rdpscan Bluekeep Check)","stargazers_count":"371","vuln_description":"A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.","created_at":"2019-05-16 00:01:38","updated_at":"2022-04-23 12:13:26","pushed_at":"2019-06-13 22:07:03","inserted_at":null},{"id":"105951164","cve_id":"CVE-2017-12617","name":"CVE-2017-12617","owner":"cyberheartmi9","full_name":"cyberheartmi9\/CVE-2017-12617","html_url":"https:\/\/github.com\/cyberheartmi9\/CVE-2017-12617","description":"Apache Tomcat < 9.0.1 (Beta) \/ < 8.5.23 \/ < 8.0.47 \/ < 7.0.8 - JSP Upload Bypass \/ Remote Code Execution ","stargazers_count":"370","vuln_description":"When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.","created_at":"2017-10-06 08:41:52","updated_at":"2022-05-02 09:18:55","pushed_at":"2017-10-11 16:43:50","inserted_at":null},{"id":"233143985","cve_id":"CVE-2019-19781","name":"CVE-2019-19781","owner":"projectzeroindia","full_name":"projectzeroindia\/CVE-2019-19781","html_url":"https:\/\/github.com\/projectzeroindia\/CVE-2019-19781","description":"Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]","stargazers_count":"369","vuln_description":"An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.","created_at":"2020-01-11 07:56:35","updated_at":"2022-04-02 16:52:11","pushed_at":"2020-01-18 16:01:29","inserted_at":null},{"id":"341874677","cve_id":"CVE-2021-21972","name":"CVE-2021-21972","owner":"NS-Sp4ce","full_name":"NS-Sp4ce\/CVE-2021-21972","html_url":"https:\/\/github.com\/NS-Sp4ce\/CVE-2021-21972","description":"CVE-2021-21972 Exploit","stargazers_count":"369","vuln_description":"The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).","created_at":"2021-02-24 20:14:58","updated_at":"2022-05-21 15:02:30","pushed_at":"2021-12-30 21:26:11","inserted_at":null},{"id":"436860437","cve_id":"CVE-2021-44228","name":"Log4j2-CVE-2021-44228","owner":"jas502n","full_name":"jas502n\/Log4j2-CVE-2021-44228","html_url":"https:\/\/github.com\/jas502n\/Log4j2-CVE-2021-44228","description":"Remote Code Injection In Log4j","stargazers_count":"366","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-10 14:23:44","updated_at":"2022-05-20 19:03:22","pushed_at":"2022-01-18 21:01:52","inserted_at":null},{"id":"277342661","cve_id":"CVE-2020-5902","name":"CVE-2020-5902","owner":"jas502n","full_name":"jas502n\/CVE-2020-5902","html_url":"https:\/\/github.com\/jas502n\/CVE-2020-5902","description":"CVE-2020-5902 BIG-IP","stargazers_count":"363","vuln_description":"In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.","created_at":"2020-07-06 01:38:32","updated_at":"2022-05-19 23:37:57","pushed_at":"2021-10-13 16:53:46","inserted_at":null},{"id":"448729790","cve_id":"CVE-2022-21907","name":"CVE-2022-21907","owner":"ZZ-SOCMAP","full_name":"ZZ-SOCMAP\/CVE-2022-21907","html_url":"https:\/\/github.com\/ZZ-SOCMAP\/CVE-2022-21907","description":"HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907","stargazers_count":"361","vuln_description":"HTTP Protocol Stack Remote Code Execution Vulnerability.","created_at":"2022-01-17 11:28:50","updated_at":"2022-05-15 20:34:43","pushed_at":"2022-01-20 11:07:59","inserted_at":null},{"id":"437215271","cve_id":"CVE-2021-44228","name":"log4j2burpscanner","owner":"f0ng","full_name":"f0ng\/log4j2burpscanner","html_url":"https:\/\/github.com\/f0ng\/log4j2burpscanner","description":"CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks","stargazers_count":"356","vuln_description":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","created_at":"2021-12-11 16:19:11","updated_at":"2022-06-02 14:59:48","pushed_at":"2022-06-02 11:16:13","inserted_at":"2022-06-02 15:38:02"},{"id":"203542766","cve_id":"CVE-2019-11510","name":"CVE-2019-11510","owner":"projectzeroindia","full_name":"projectzeroindia\/CVE-2019-11510","html_url":"https:\/\/github.com\/projectzeroindia\/CVE-2019-11510","description":"Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)","stargazers_count":"355","vuln_description":"In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .","created_at":"2019-08-21 17:40:26","updated_at":"2022-05-17 04:01:24","pushed_at":"2020-01-11 22:55:33","inserted_at":null},{"id":"189498490","cve_id":"CVE-2019-0708","name":"bluekeep_CVE-2019-0708_poc_to_exploit","owner":"algo7","full_name":"algo7\/bluekeep_CVE-2019-0708_poc_to_exploit","html_url":"https:\/\/github.com\/algo7\/bluekeep_CVE-2019-0708_poc_to_exploit","description":"An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits","stargazers_count":"348","vuln_description":"A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.","created_at":"2019-05-31 09:04:12","updated_at":"2022-03-15 16:18:41","pushed_at":"2021-01-10 13:31:22","inserted_at":null},{"id":"727775795","cve_id":"CVE-2025-52915","name":"BYOVD","owner":"BlackSnufkin","full_name":"BlackSnufkin\/BYOVD","html_url":"https:\/\/github.com\/BlackSnufkin\/BYOVD","description":"BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology.  (CVE-2025-52915,  CVE-2025-1055,).","stargazers_count":"348","vuln_description":"K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized processes to perform those actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications.","created_at":"2023-12-05 23:52:11","updated_at":"2025-09-07 07:03:32","pushed_at":"2025-09-03 22:44:33","inserted_at":"2025-09-07 10:36:42"},{"id":"437829160","cve_id":"CVE-2021-42278","name":"noPac","owner":"Ridter","full_name":"Ridter\/noPac","html_url":"https:\/\/github.com\/Ridter\/noPac","description":"Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user ","stargazers_count":"345","vuln_description":"Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291.","created_at":"2021-12-13 19:28:12","updated_at":"2022-05-19 17:15:17","pushed_at":"2022-04-25 16:53:41","inserted_at":null},{"id":"127436541","cve_id":"CVE-2018-7600","name":"CVE-2018-7600","owner":"a2u","full_name":"a2u\/CVE-2018-7600","html_url":"https:\/\/github.com\/a2u\/CVE-2018-7600","description":"\ud83d\udc80Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002","stargazers_count":"343","vuln_description":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.","created_at":"2018-03-30 23:23:18","updated_at":"2022-04-30 02:26:30","pushed_at":"2019-03-29 20:25:57","inserted_at":null},{"id":"167313064","cve_id":"CVE-2018-8581","name":"Exchange2domain","owner":"Ridter","full_name":"Ridter\/Exchange2domain","html_url":"https:\/\/github.com\/Ridter\/Exchange2domain","description":"CVE-2018-8581","stargazers_count":"342","vuln_description":"An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka \"Microsoft Exchange Server Elevation of Privilege Vulnerability.\" This affects Microsoft Exchange Server.","created_at":"2019-01-24 15:08:23","updated_at":"2022-04-19 22:13:33","pushed_at":"2019-06-21 20:29:41","inserted_at":null},{"id":"148616806","cve_id":"CVE-2017-10271","name":"javaserializetools","owner":"shack2","full_name":"shack2\/javaserializetools","html_url":"https:\/\/github.com\/shack2\/javaserializetools","description":"Java\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e\u5229\u7528\u5de5\u5177V1.0    Java\u53cd\u5e8f\u5217\u5316\u76f8\u5173\u6f0f\u6d1e\u7684\u68c0\u67e5\u5de5\u5177\uff0c\u91c7\u7528JDK 1.8+NetBeans8.2\u5f00\u53d1\uff0c\u8f6f\u4ef6\u8fd0\u884c\u5fc5\u987b\u5b89\u88c5JDK 1.8\u6216\u8005\u4ee5\u4e0a\u7248\u672c\u3002   \u652f\u6301\uff1aweblogic xml\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e CVE-2017-10271\/CNVD-C-2019-48814\/CVE-2019-2725\u68c0\u67e5\u3002","stargazers_count":"341","vuln_description":"Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H).","created_at":"2018-09-13 18:44:18","updated_at":"2022-05-18 07:29:41","pushed_at":"2020-10-02 05:20:41","inserted_at":null},{"id":"234192123","cve_id":"CVE-2020-0601","name":"chainoffools","owner":"kudelskisecurity","full_name":"kudelskisecurity\/chainoffools","html_url":"https:\/\/github.com\/kudelskisecurity\/chainoffools","description":"A PoC for CVE-2020-0601","stargazers_count":"340","vuln_description":"A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.","created_at":"2020-01-16 08:15:32","updated_at":"2022-05-03 08:08:19","pushed_at":"2020-03-23 00:14:31","inserted_at":null},{"id":"13021222","cve_id":"CVE-2008-0166","name":"debian-ssh","owner":"g0tmi1k","full_name":"g0tmi1k\/debian-ssh","html_url":"https:\/\/github.com\/g0tmi1k\/debian-ssh","description":"Debian OpenSSL Predictable PRNG (CVE-2008-0166)","stargazers_count":"339","vuln_description":"OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.","created_at":"2013-09-23 06:20:31","updated_at":"2022-05-19 15:35:42","pushed_at":"2017-04-24 23:16:56","inserted_at":null}]}