Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVEs — Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs | Kitploit
Strumenti/GitHubGitHub/rhinosecuritylabs/cves
Authentication & AuthorizationPrivilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubrhinosecuritylabs/cves

CVEs

Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

Vedi Repository
90525011 anno faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Exploit Proof-of-Concept di Rhino per CVE

Una raccolta di script exploit proof-of-concept scritti dal team di Rhino Security Labs per varie CVE.

  • CVE-2025-32815: Bypass dell'autenticazione in Infoblox NetMRI tramite credenziali hardcoded
  • CVE-2025-32814: SQL Injection non autenticata in Infoblox NetMRI tramite skipjackUsername
  • CVE-2025-32813: Command Injection non autenticata in Infoblox NetMRI tramite get_saml_request
  • CVE-2024-55965: Denial of Service tramite Broken Access Control che consente all'accesso "App Viewer" di effettuare la richiesta API 'Restart'
  • CVE-2024-55963: Remote Code Execution non autenticata come utente postgres
  • CVE-2024-54188: Lettura arbitraria di file autenticata come Root in Infoblox NetMRI
  • CVE-2024-52874: SQL Injection autenticata in Run.tdf di Infoblox NetMRI
  • CVE-2024-46507: SSTI nella piattaforma YETI
  • CVE-2024-2449: Cross-Site Request Forgery in Progress Kemp LoadMaster
  • CVE-2024-2448: Command Injection autenticata in Progress Kemp LoadMaster
  • CVE-2024-2389: Command Injection non autenticata in Progress Software Flowmon
  • CVE-2024-23724: XSS persistente in Ghost CMS che porta all'acquisizione dell'account proprietario
  • CVE-2024-1212: Command Injection non autenticata in Progress Kemp LoadMaster
  • CVE-2023-47327: La funzione Space Create di Silverpeas Core è vulnerabile a Broken Access Control
  • CVE-2023-47326: La creazione di domini in Silverpeas Core è vulnerabile a CSRF
  • CVE-2023-47325: Broken Access Control su "Bin" in Silverpeas Core consente la modifica di spazi eliminati
  • CVE-2023-47324: XSS persistente nei Messaggi di Silverpeas Core
  • CVE-2023-47323: Broken Access Control in Silverpeas Core consente la lettura di tutti i messaggi
  • CVE-2023-47322: CSRF in Silverpeas Core che porta a Privilege Escalation
  • CVE-2023-47321: Accesso al Portlet Deployer di Silverpeas Core tramite Broken Access Control
  • CVE-2023-47320: Denial of Service in Silverpeas Core tramite Broken Access Control
  • CVE-2023-43121: Lettura file non autenticata in Extreme Networks EXOS
  • CVE-2023-43120: Privilege Escalation in Extreme Networks EXOS da utente read-only ad Admin
  • CVE-2023-43119: Scrittura arbitraria di file come Root in Extreme Networks EXOS
  • CVE-2023-43118: Da CSRF a RCE in Extreme Networks EXOS
  • CVE-2022-25372: Privilege Escalation locale nel client VPN Pritunl
  • CVE-2022-25237: Bypass dell'autorizzazione che porta a RCE in Bonitasoft Web
  • CVE-2022-25166: Scrittura arbitraria di file come SYSTEM nel client VPN AWS
  • CVE-2022-25165: Divulgazione di informazioni nel client VPN AWS tramite percorso UNC
  • CVE-2021-38112: Remote Code Execution in AWS WorkSpaces
  • CVE-2020-5377 e CVE-2021-21514: Lettura arbitraria di file in Dell OpenManage Server Administrator
  • CVE-2020-13405: Divulgazione non autenticata del database degli utenti in MicroWeber
  • CVE-2019-9926: CSRF in LabKey Server
  • CVE-2019-9758: XSS persistente in LabKey Server
  • CVE-2019-9757: XXE in LabKey Server
  • CVE‑2019‑5678: Command Injection in Nvidia GeForce Experience Web Helper
  • CVE‑2019‑5674: Sovrascrittura arbitraria di file in NVIDIA GeForce Experience
  • CVE-2019-3722: XXE in Dell EMC OpenManage Server Administrator (OMSA)
  • CVE‑2019‑16864: Remote Command Execution autenticata in CompleteFTP Server
  • CVE‑2019‑16116: Privilege Escalation locale in CompleteFTP Server
  • CVE-2019-0227: Remote Code Execution in Apache Axis 1.4
  • CVE-2018-8024: Vulnerabilità XSS nell'interfaccia utente di Apache Spark
  • CVE-2018-5758: XXE in Jive-n
  • CVE-2018-5757: RCE nel telefono AudioCodes 450HD
  • CVE-2018-20621: Privilege Escalation locale nell'emulatore Android MEmu
  • CVE-2018-1335: Command Injection in Apache Tika-server
  • CVE-2018-1000110: Enumerazione di utenti e nodi tramite il plugin Git di Jenkins <v3.7
  • CVE-2017-7284: Modifica forzata della password senza password corrente in Unitrends
  • CVE-2017-7283: RCE in Unitrends Enterprise Backup Solution tramite file di ripristino
  • CVE-2017-7282: LFI in Unitrends Enterprise Backup Solution
  • CVE-2017-7281: RCE in Unitrends Enterprise Backup Solution tramite upload di file
  • CVE-2017-7280: Esecuzione di comandi in Unitrends Enterprise Backup Solution
  • CVE-2017-7279: Privilege Escalation in Unitrends Enterprise Backup Server.
  • CVE-2017-12861: Attacco brute force al PIN del proiettore Epson EasyMP
  • CVE-2017-12860: PIN hardcoded nel proiettore Epson EasyMP
  • CVE-2016-8972: Exploit locale di root per IBM AIX Bellmail
  • CVE-2016-6079: Exploit locale di root per AIX lquerylv 5.3, 6.1, 7.1, 7.2
  • CVE-2016-3053: Exploit locale di root per AIX lsmcode
Scarica lo strumento