RSS Feed

Proof of Concept

Die aktuelle Feed-Übersicht bündelt kuratierte Themen, relevante Quellfeeds und Live-Interessensgebiete in einem konsistenten, schnell nutzbaren Layout.

🪟 Windows TippsOffice 2024 Pro Plus zum Top-Preis! Lizenzen ab 16,66 €(18.09.2026 um 04:55 Uhr)
🕵️ SicherheitslückenCVE-2026-93468 | HGiga OAKclouds up to 106 path traversal (EUVD-2026-82642)(18.09.2026 um 05:10 Uhr)
🪟 Windows TippsOffice 2024 Pro Plus zum Top-Preis! Lizenzen ab 16,66 €(18.09.2026 um 04:55 Uhr)
🕵️ SicherheitslückenCVE-2026-93468 | HGiga OAKclouds up to 106 path traversal (EUVD-2026-82642)(18.09.2026 um 05:10 Uhr)
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence

⚠️ PoC

PoC packetstormsecurity.com
0
GitLab Authenticated File Read

GitLab version 16.0 contains a directory traversal for arbitrary file read as the gitlab-www user.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump

This Metasploit module uses a blind SQL injection (CVE-2020-5724) affecting the Grandstream UCM62xx IP PBX to dump the users table.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
ColdFusion password.properties Hash Extraction

This Metasploit module uses a directory traversal vulnerability to extract information such as password, rdspassword, and "encrypted" properties.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Windows Secrets Dump

Dumps SAM hashes and LSA secrets (including cached creds) from the remote Windows target without executing any agent locally.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
CheckPoint Firewall-1 SecuRemote Topology Service Hostname Disclosure

This Metasploit module sends a query to the port 264/TCP on CheckPoint Firewall-1 firewalls to obtain the firewall name and management station (such…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Apache Superset Signed Cookie Privilege Escalation

Apache Superset versions less than or equal to 2.0.0 utilize Flask with a known default secret key which is used to sign HTTP cookies.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
MantisBT Admin SQL Injection Arbitrary File Read

Versions 1.2.13 through 1.2.16 are vulnerable to a SQL injection attack if an attacker can gain access to administrative credentials.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Roundcube TimeZone Authenticated File Disclosure

Roundcube Webmail allows unauthorized access to arbitrary files on the hosts filesystem, including configuration files.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
FortiOS Path Traversal Credential Gatherer

Fortinet FortiOS versions 5.4.6 to 5.4.12, 5.6.3 to 5.6.7 and 6.0.0 to 6.0.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
AlienVault Authenticated SQL Injection Arbitrary File Read

AlienVault 4.5.0 is susceptible to an authenticated SQL injection attack via a PNG generation PHP file.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
WordPress W3-Total-Cache 0.9.2.4 Username / Hash Extraction

The W3-Total-Cache Wordpress plugin versions 0.9.2.4 and below can cache database statements and its results in files for fast access.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Drupal OpenID External Entity Injection

This Metasploit module abuses an XML External Entity Injection vulnerability on the OpenID module from Drupal.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Jasmin Ransomware Web Server Unauthenticated Directory Traversal

The Jasmin Ransomware web server contains an unauthenticated directory traversal vulnerability within the download functionality.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Ray Static Arbitrary File Read

Ray versions prior to 2.8.1 are vulnerable to a local file inclusion vulnerability.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Lansweeper Credential Collector

Lansweeper stores the credentials it uses to scan the computers in its Microsoft SQL database.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
MS14-052 Microsoft Internet Explorer XMLDOM Filename Disclosure

This Metasploit module will use the Microsoft XMLDOM object to enumerate a remote machines filenames.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
MinIO Bootstrap Verify Information Disclosure

MinIO is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
NIS bootparamd Domain Name Disclosure

This Metasploit module discloses the NIS domain name from bootparamd. You must know a client address from the targets bootparams file.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Peplink Balance Routers SQL Injection

Firmware versions up to 7.0.0-build1904 of Peplink Balance routers are affected by an unauthenticated SQL injection vulnerability in the bauth…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC 🛡️ CVE-2023-26876 packetstormsecurity.com
0
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection

This Metasploit module allows an authenticated user to retrieve the usernames and encrypted passwords of other users in Piwigo through SQL injection…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Microsoft Windows Deployment Services Unattend Gatherer

This Metasploit module will search remote file shares for unattended installation files that may contain domain credentials.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Cerberus Helpdesk User Hash Disclosure

This Metasploit module extracts usernames and password hashes from the Cerberus Helpdesk through an unauthenticated access to a workers file.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Ruby On Rails File Content Disclosure

This Metasploit module uses a path traversal vulnerability in Ruby on Rails versions 5.2.2 and below to read files on a target server.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
IBM Lotus Notes Sametime Room Name Bruteforce

This Metasploit module bruteforces Sametime meeting room names via the IBM Lotus Notes Sametime web interface.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
EMC CTA 10.0 Unauthenticated XXE Arbitrary File Read

EMC CTA v10.0 is susceptible to an unauthenticated XXE attack that allows an attacker to read arbitrary files from the file system with the…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
vBulletin Password Collector via nodeid SQL Injection

This Metasploit module exploits a SQL injection vulnerability found in vBulletin 5 that has been used in the wild since March 2013.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Firefox PDF.js Browser File Theft

This Metasploit module abuses an XSS vulnerability in versions prior to Firefox 39.0.3, Firefox ESR 38.1.1, and Firefox OS 2.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
HTTP Client LAN IP Address Gather

This Metasploit module retrieves a browsers network interface IP addresses using WebRTC.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Android Browser Open in New Tab Cookie Theft

In Androids stock AOSP Browser application and WebView component, the "open in new tab" functionality allows a file URL to be opened.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Network Shutdown Module sort_values Credential Dumper

This Metasploit module will extract user credentials from Network Shutdown Module versions 3.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Huawei Datacard Information Disclosure

This Metasploit module exploits an unauthenticated information disclosure vulnerability in Huawei SOHO routers.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Cisco PVC2300 POE Video Camera Configuration Download

This Metasploit module exploits an information disclosure vulnerability in Cisco PVC2300 cameras in order to download the configuration file…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
DNS Record Scanner and Enumerator

This Metasploit module can be used to gather information about a domain from a given DNS server by performing various DNS queries such as zone…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Adobe ColdFusion Unauthenticated Arbitrary File Read

This Metasploit module exploits a remote unauthenticated deserialization of untrusted data vulnerability in Adobe ColdFusion 2021 Update 5 and…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
SSL Labs API Client

This Metasploit module is a simple client for the SSL Labs APIs, designed for SSL/TLS assessment during a penetration test.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Jenkins cli Ampersand Replacement Arbitrary File Read

This Metasploit module utilizes the Jenkins cli protocol to run the help command.

vor 2 Jahren 2 Min
Weiterlesen ↗
Weitere 36 Beiträge laden
Seite 32 von 840 • Gesamt: 30.218 Artikel
3 Quellen 10
CVE-2026-15650 | themewant RT Mega Menu Plugin up to 1.5.2 on WordPress Block Attribute pointer_menu_item cross site scripting (EUVD-2026-82643)
2 Quellen 10
CVE-2026-50696 | Microsoft Windows up to Server 2025 Internet Key Exchange buffer overflow
1 Quelle 15
Office 2024 Pro Plus zum Top-Preis! Lizenzen ab 16,66 €
1 Quelle 10
CVE-2026-92991 | bdthemes Element Pack Addons for Elementor Plugin on WordPress Sigmative API display_id cross site scripting (EUVD-2026-82645)
1 Quelle 10
CVE-2026-93468 | HGiga OAKclouds up to 106 path traversal (EUVD-2026-82642)
1 Quelle 10
CVE-2026-93467 | HGiga OAKclouds-custom_page-4.0 up to 25 deserialization (EUVD-2026-82641)
1 Quelle 10
CVE-2026-93371 | marcopiovanello yt-dlp-web-ui up to v4 generic.go NewGenericDownload params command injection (EUVD-2026-82640)
1 Quelle 10
CVE-2026-93331 | GPAC 26.08-DEV RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt size out-of-bounds (Issue 3868 / EUVD-2026-82639)
1 Quelle 10
CVE-2026-59258 | immich-app immich up to 3.0.2 id/user access control (EUVD-2026-44755)
1 Quelle 10
CVE-2026-59255 | SpecterOps BloodHound up to 9.4.0 Custom-Nodes API authorization (EUVD-2026-44754)
1 Quelle 10
CVE-2026-62240 | crewAIInc crewAI up to 1.15.0 URL Validation validate_url server-side request forgery
1 Quelle 10
CVE-2026-62239 | Dao-AILab FlashAttention up to 2.8.3.post1 Archive Extraction hopper/setup.py download_and_copy symlink
Threat Hunter Status-Update verfassen
Community Stream
News-Deck PoC 📖 0 · ⏭ 0 · 🗳️ 0

Karten werden geladen …

Links = lesen · Rechts = weitergehen · Hoch = Details · Runter = zurück · V = Voting