Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
도구/GitHubGitHub/rhinosecuritylabs/cves
Authentication & AuthorizationPrivilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubrhinosecuritylabs/cves

CVEs

Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

저장소 보기
9052501516일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Rhino CVE Proof-of-Concept Exploits

A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs.

  • CVE-2026-46546: Frappe LMS Header Tag Injection Leading to Open Redirect
  • CVE-2026-39405: Frappe LMS Path Traversal in SCORM Package Upload Leading to Remote Code Execution
  • CVE-2026-34606: Frappe LMS Stored XSS in Profile Bio and Other Fields
  • CVE-2025-32815: Infoblox NetMRI Authentication Bypass via Hardcoded Credentials
  • CVE-2025-32814: Infoblox NetMRI Unauthenticated SQL Injection via skipjackUsername
  • CVE-2025-32813: Infoblox NetMRI Unauthenticated Command Injection in get_saml_request
  • CVE-2024-55965: Denial of Service via Broken Access Control allowing “App Viewer” access to ‘Restart’ API request
  • CVE-2024-55963: Unauthenticated Remote Code Execution as postgres user
  • CVE-2024-54188: Infoblox NetMRI Authenticated Arbitrary File Read as Root
  • CVE-2024-52874: Infoblox NetMRI Authenticated SQL Injection in Run.tdf
  • CVE-2024-46507: YETI platform SSTI
  • CVE-2024-2449: Cross-Site Requets Forgery in Progress Kemp LoadMaster
  • CVE-2024-2448: Authenticated Command Injection in Progress Kemp LoadMaster
  • CVE-2024-2389: Progress Software Flowmon Unauthenticated Command Injection
  • CVE-2024-23724: Ghost CMS Stored XSS Leading to Owner Takeover
  • CVE-2024-1212: Unauthenticated Command Injection in Progress Kemp LoadMaster
  • CVE-2023-47327: Silverpeas Core Space Create Function is vulnerable to Broken Access Control
  • CVE-2023-47326: Silverpeas Core Domain Creation is vulnerable to CSRF
  • CVE-2023-47325: Silverpeas Core Broken Access Control on the "Bin" Allows Modification of Deleted Spaces
  • CVE-2023-47324: Silverpeas Core Stored XSS in Messages
  • CVE-2023-47323: Silverpeas Core Broken Access Control Allows Reading All Messages
  • CVE-2023-47322: Silverpeas Core CSRF Leading to Privilege Escalation
  • CVE-2023-47321: Silverpeas Core Portlet Deployer Access via Broken Access Control
  • CVE-2023-47320: Silverpeas Core Denial of Service via Broken Access Control
  • CVE-2023-43121: Extreme Networks EXOS Unauthenticated File Read
  • CVE-2023-43120: Extreme Networks EXOS Privilege Escalation from read-only User to Admin
  • CVE-2023-43119: Extreme Networks EXOS Arbitrary File Write as Root
  • CVE-2023-43118: Extreme Networks EXOS CSRF to RCE
  • CVE-2022-25372: Local Privilege Escalation In Pritunl VPN Client
  • CVE-2022-25237: Authorization Bypass Leading to RCE in Bonitasoft Web
  • CVE-2022-25166: AWS VPN Client Arbitrary File Write as SYSTEM
  • CVE-2022-25165: AWS VPN Client Information Disclosure Via UNC Path
  • CVE-2021-38112: AWS WorkSpaces Remote Code Execution
  • CVE-2020-5377 and CVE-2021-21514: Dell OpenManage Server Administrator Arbitrary File Read
  • CVE-2020-13405: MicroWeber Unauthenticated User Database Disclosure
  • CVE-2019-9926: LabKey Server CSRF
  • CVE-2019-9758: LabKey Server Stored XSS
  • CVE-2019-9757: LabKey Server XXE
  • CVE‑2019‑5678: Command Injection in Nvidia GeForce Experience Web Helper
  • CVE‑2019‑5674: NVIDIA GeForce Experience Arbitrary File Overwrites
  • CVE-2019-3722: Dell EMC OpenManage Server Administrator (OMSA) XXE
  • CVE‑2019‑16864: CompleteFTP Server Authenticated Remote Command Execution
  • CVE‑2019‑16116: CompleteFTP Server Local Privilege Escalation
  • CVE-2019-0227: Apache Axis 1.4 Remote Code Execution
  • CVE-2018-8024: Apache Spark XSS vulnerability in UI
  • CVE-2018-5758: XXE in Jive-n
  • CVE-2018-5757: RCE In AudioCodes 450HD Phone
  • CVE-2018-20621: MEmu Android Emulator Local Privilege Escalation
  • CVE-2018-1335: Command Injection in Apache Tika-server
  • CVE-2018-1000110: User and Node Enumeration Through Jenkins Git Plugin <v3.7
  • CVE-2017-7284: Unitrends Force Password Change Without Current Password
  • CVE-2017-7283: Unitrends Enterprise Backup Solution RCE via Retore File
  • CVE-2017-7282: Unitrends Enterprise Backup Solution LFI
  • CVE-2017-7281: Unitrends Enterprise Backup Solution RCE Via File Upload
  • CVE-2017-7280: Unitrends Enterprise Backup Solution Command Execution
도구 다운로드