Core Certified Exploits
We provide real-time updates including new penetration testing exploits and tests for additional platforms as they become available. We advise you of any new modules by email, after which you can download them directly from within Core Impact. All product updates are free during the license period. You're always on the cutting edge of vulnerability and threat intelligence because Core Impact keeps you there.
Subscribe to receive regular updates by email:
Browse All Exploits
|Title||Description||Date Added||CVE Link||Exploit Platform||Exploit Type|
|Pydio Cells Mailer Configuration Remote OS Command Injection Exploit||The administrative console in Pydio Cells allows a user with administrator role to set the path for the sendmail binary executable, when the "sendmail" option is selected in the mailer configuration.
Due to lack of sanitization in the given parameter, an administrator user can set the path to an arbitrary binary.
|July 3, 2020||CVE-2020-12847||Windows, Linux||Exploits / OS Command Injection / Known Vulnerabilities|
|Microsoft .NET Framework Elevation of Privilege Vulnerability Exploit||An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.||June 23, 2020||CVE-2020-1066||Windows||Exploits / Local|
|Trident Z Lighting Control Driver Local Privilege Escalation Exploit||The ene.sys driver in Trident Z Lighting Control before v1.00.17 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges.||June 19, 2020||CVE-2020-12446||Windows||Exploits / Local|
|Advantech WebAccess SCADA DATACORE IOCTL 0x523e Buffer Overflow Exploit||The specific flaw exists within DATACORE server. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of Administrator.||June 18, 2020||CVE-2020-12002||Windows||Exploits / Remote|
|OpenAudit Remote Code Execution (CVE-2020-12078)||An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called exclude_ip). This exclude_ip value is passed to the exec function in the discoveries_helper.php file (inside the all_ip_list function) without being filtered, which means that the attacker can provide a payload instead of a valid IP address.||June 12, 2020||CVE-2020-12078||Windows, Linux||Exploits / OS Command Injection / Known Vulnerabilities|
|Artica Pandora FMS Events Remote OS Command Injection Exploit||The target parameter in events.php in Pandora FMS 7.0NG 742, 743 and 744 allows remote authenticated users to execute arbitrary OS commands.||June 10, 2020||CVE-2020-13851||Windows, Linux||Exploits / OS Command Injection / Known Vulnerabilities|
|Cisco AnyConnect Secure Mobility Client Uncontrolled Search Path Privilege Escalation Exploit||A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges.||June 5, 2020||CVE-2020-3153||Windows||Exploits / Local|
|Eaton HMiSoft VU3 File Parsing Buffer Overflow Exploit||The specific flaw exists within the parsing of wTextLen information within VU3 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer.||June 4, 2020||CVE-2020-10639||Windows||Exploits / Client Side|
|ATI Technologies Driver atillk64 Kernel Arbitrary Read Write Local Privilege Escalation Exploit||AMD ATI atillk64 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space of the calling process. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages.||June 2, 2020||CVE-2020-12138||Windows||Exploits / Local|
|Advantech WebAccess SCADA DATACORE IOCTL 0x5227 Buffer Overflow Exploit||
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Advantech WebAccess/SCADA. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the implementation of IOCTL 0x00005227 in DATACORE.exe. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of Administrator.
|May 28, 2020||CVE-2020-12002||Windows||Exploits / Remote|
|Microsoft Exchange Validation Key Remote OS Command Injection Exploit Update||.NET deserialization vulnerability in the Microsoft Exchange Control Panel web page allows authenticated attackers to execute OS commands with SYSTEM privileges.
The lack of randomization in the validationKey and decryptionKey values at installation allows an attacker to create a crafted viewstate to execute OS commands via .NET deserialization.
This update adds payload generation error detection and dependencies documentation.
|May 27, 2020||CVE-2020-0688||Windows||Exploits / OS Command Injection / Known Vulnerabilities|
|WECON LeviStudioU MulStatus szFilename Exploit Update||The specific flaw exists within the handling of XML files. When parsing the szFilename attribute of the MulStatus element. This update adds CVE number.||May 22, 2020||CVE-2019-6537||Windows||Exploits / Client Side|
|Liferay Portal JSONWS Java Deserialization Vulnerability Remote Code Execution Exploit||Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).||May 18, 2020||CVE-2020-7961||Windows, Linux||Exploits / Remote|
|Oracle Coherence T3 ReflectionExtractor Deserialization Vulnerability Remote Code Execution||Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 220.127.116.11, 18.104.22.168.0, 22.214.171.124.0 and 126.96.36.199.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence.||May 15, 2020||CVE-2020-2555||Windows, Linux||Exploits / Remote|
|WECON LeviStudioU MulStatus szFilename Exploit||The specific flaw exists within the handling of XML files. When parsing the szFilename attribute of the MulStatus element.||May 11, 2020||NOCVE-9999-127145||Windows||Exploits / Client Side|
|Windows Search Indexer get_RootURL Race Condition Privilege Escalation Exploit||A race condition exists in Windows Search Indexer, when the put_RootURL function wrote a user-controlled data in the memory of CSearchRoot+0x14.AT the same time, the get_RootURL function read the data located in the memory of CSearchRoot+0x14.
The vulnerability was caused by the access to a shared variable between two different methods of the same instance .
|May 5, 2020||CVE-2020-0735||Windows||Exploits / Local|
|Fuji Electric V-Server Lite VPR File Parsing Overflow Exploit||The specific flaw exists within the processing of VPR files.||April 30, 2020||CVE-2020-10646||Windows||Exploits / Client Side|
|Open-AudIT m_devices.php Remote PHP File Upload Vulnerability Exploit||The sub_resource_create function of class M_devices in m_devices.php of Open-AudIT 3.2.2 allows remote authenticated users to upload arbitrary PHP files, allowing the execution of arbitrary php code in the system.||April 29, 2020||CVE-2020-11942||Windows, Linux||Exploits / Remote File Inclusion / Known Vulnerabilities|
|Microsoft Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability Exploit||An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status and take control of an affected system.||April 28, 2020||CVE-2020-0787||Windows||Exploits / Local|
|Kinetica Admin getLogs Function Remote OS Command Injection Exploit||The Kinetica Admin web application did not properly sanitise the input for the function getLogs. This lack of sanitisation could be exploited to allow an authenticated attacker to run remote code on the underlying operating system.||April 20, 2020||CVE-2020-8429||Linux||Exploits / OS Command Injection / Known Vulnerabilities|
|Microsoft Windows SMBv3 SMBGhost Elevation of Privilege Vulnerability Exploit||An unauthenticated attacker can connect to the target system using SMBv3 and sends specially crafted requests to exploit the vulnerability. This module exploits this vulnerability in the local system in order to achieve an elevation of privilege. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.||April 15, 2020||CVE-2020-0796||Windows||Exploits / Local|
|Microsoft Windows SMBv3 CoronaBlue Vulnerability DoS Update||An unauthenticated attacker can connect to the target system using SMBv3 and sends specially crafted requests to exploit the vulnerability.
The module exploits this vulnerability in order to generate a Denial of Service
This update contains minor fixes to it
|April 7, 2020||CVE-2020-0796||Windows||Denial of Service / Remote|
|Microsoft Windows Ws2ifsl UaF Local Privilege Escalation Exploit||An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'||April 1, 2020||CVE-2019-1215||Windows||Exploits / Local|
|Microsoft Windows Installer Elevation of Privilege Vulnerability Exploit||An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links. An attacker who successfully exploited this vulnerability could bypass access restrictions to add or remove files.||March 30, 2020||CVE-2020-0683||Windows||Exploits / Local|
|Delta Industrial Automation CNCSoft ScreenEditor DPB File Parsing Buffer Overflow Exploit||
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation CNCSoft ScreenEditor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
|March 26, 2020||CVE-2020-7002||Windows||Exploits / Client Side|