Exploit catalog results

Showing 25 PoCs on this page

ExploitDB

ProtonVPN v4.4.1 - Unquoted Service Path

ExploitDB exploitPublished 2026-07-07
ScannerUnlinked1 file

EDB-52624

Analysisdeepseek-v4-pro:cloud ·

Technical assessment

The artifact describes an unquoted service path vulnerability in ProtonVPN v4.4.1 and provides a PowerShell command to query the service configuration, which only detects the vulnerability without exploiting it.

Backdoor review

No backdoor observed in reviewed code

The supplied text is a straightforward public disclosure of an unquoted service path vulnerability in ProtonVPN 4.4.1. It contains a description of the vulnerability, a proof-of-concept showing the service configuration, and no hidden commands, obfuscated payloads, or deceptive instructions. No backdoor or trojan behavior is present.

ClassificationScanner
Model confidence95%
AuthenticationNot required
Languagespowershell
Target softwareProtonVPN
Attack typesunquoted service path
Evidence & reasoningClassification basis · observed behavior · safety review
Technical evidence

Classification basis and observed behavior

Classification basis

The artifact provides a PowerShell command (sc.exe qc) that only queries and displays the service configuration, which is a detection technique, not an exploitation. It does not include code to insert or execute a malicious payload.

exploits/windows/local/52624.txt:20

Requirements

  • Local access to a Windows system with ProtonVPN v4.4.1 installedexploits/windows/local/52624.txt:1

Observed behavior

  • Queries the configuration of the 'ProtonVPN WireGuard' service using sc.exe to display its binary path, revealing an unquoted service path vulnerability.exploits/windows/local/52624.txt:20-29
Safety-review evidence

Behaviors behind the backdoor verdict

Observables

Vulnerability Disclosure
Payload withheldThe PoC demonstrates that the service binary path contains spaces and is not quoted, which is a known local privilege escalation technique if an attacker can place a malicious executable in the path.exploits/windows/local/52624.txt:27-29
Review boundaries

What the analysis did not establish

  • The artifact is a single text file with no executable code; it only contains a description and a service query command.
  • Review is limited to the supplied text file; no external tools, libraries, or referenced resources were analyzed.
  • The artifact is a text file describing a vulnerability; no executable code is present to analyze for hidden behavior.
Model interpretation

This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.

ExploitDB

Litespeed Cache WordPress Plugin 6.3.0.1 - Privilege Escalation

ExploitDB exploitPublished 2025-06-15
Not analyzedCVE-2024-280001 file
ExploitDB

Microsoft Windows Server 2016 - Win32k Elevation of Privilege

ExploitDB exploitPublished 2025-05-25
Not analyzedCVE-2023-293361 file
ExploitDB

VirtualBox 7.0.16 - Privilege Escalation

ExploitDB exploitPublished 2025-05-09
Not analyzedCVE-2024-211111 file
ExploitDB

Microsoft Windows 11 Pro 23H2 - Ancillary Function Driver for WinSock Privilege Escalation

ExploitDB exploitPublished 2025-05-09
Not analyzedCVE-2024-381931 file
ExploitDB

Firefox ESR 115.11 - PDF.js Arbitrary JavaScript execution

ExploitDB exploitPublished 2025-04-22
Not analyzedCVE-2024-43671 file
ExploitDB

Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege

ExploitDB exploitPublished 2025-04-22
Not analyzedCVE-2024-491381 file
ExploitDB

Microsoft Windows 11 - Kernel Privilege Escalation

ExploitDB exploitPublished 2025-04-22
Not analyzedCVE-2024-213381 file
ExploitDB

OpenSSH server (sshd) 9.8p1 - Race Condition

ExploitDB exploitPublished 2025-04-22
Not analyzedCVE-2024-63871 file
ExploitDB

WordPress Core 6.2 - Directory Traversal

ExploitDB exploitPublished 2025-04-22
Not analyzedCVE-2023-27451 file
ExploitDB

WonderCMS 3.4.2 - Remote Code Execution (RCE)

ExploitDB exploitPublished 2025-04-22
Not analyzedCVE-2023-414251 file
ExploitDB

Drupal 11.x-dev - Full Path Disclosure

ExploitDB exploitPublished 2025-04-19
Not analyzedCVE-2024-454401 file
ExploitDB

Tatsu 3.3.11 - Unauthenticated RCE

ExploitDB exploitPublished 2025-04-18
Not analyzedCVE-2021-250941 file
ExploitDB

Oracle Database 12c Release 1 - Unquoted Service Path

ExploitDB exploitPublished 2024-08-04
Not analyzedUnlinked1 file
ExploitDB

SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path

ExploitDB exploitPublished 2024-08-04
Not analyzedUnlinked1 file
ExploitDB

Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution

ExploitDB exploitPublished 2024-04-21
Not analyzedCVE-2024-583481 file
ExploitDB

Wordpress Theme Travelscape v1.0.3 - Arbitrary File Upload

ExploitDB exploitPublished 2024-04-08
Not analyzedCVE-2024-583491 file
ExploitDB

AnyDesk 7.0.15 - Unquoted Service Path

ExploitDB exploitPublished 2024-04-08
Not analyzedCVE-2025-344991 file
ExploitDB

ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path

ExploitDB exploitPublished 2024-04-03
Not analyzedCVE-2024-03531 file
ExploitDB

Wordpress Plugin - Membership For WooCommerce < v2.1.7 - Arbitrary File Upload to Shell (Unauthenticated)

ExploitDB exploitPublished 2024-04-02
Not analyzedCVE-2022-43951 file
ExploitDB

Wordpress Seotheme - Remote Code Execution Unauthenticated

ExploitDB exploitPublished 2024-02-09
Not analyzedCVE-2023-543521 file
ExploitDB

Wordpress Augmented-Reality - Remote Code Execution Unauthenticated

ExploitDB exploitPublished 2024-02-09
Not analyzedCVE-2023-543501 file
ExploitDB

ESET Service 16.0.26.0 - 'Service ekrn' Unquoted Service Path

ExploitDB exploitPublished 2023-04-08
Not analyzedCVE-2024-03531 file
ExploitDB

Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquoted Service Path

ExploitDB exploitPublished 2023-04-03
Not analyzedUnlinked1 file
ExploitDB

WooCommerce v7.1.0 - Remote Code Execution(RCE)

ExploitDB exploitPublished 2023-03-31
Not analyzedCVE-2022-509721 file