DarkFunct
67 exploits
Active since Mar 2017
Adobe ColdFusion <2018u16, <2021u6, <2023.0.0.330468 - Code Injection
KubePi < 1.6.3 - Use of Hard-coded Credentials in JWT Authentication
Metabase < 0.46.6.1 and < 1.46.6.1 - Unauthenticated Remote Code Execution
Tongda OA - SQL Injection via DELETE_STR Parameter in delete_log.php
Microsoft Windows SMBv1 - Remote Code Execution via Crafted Packets
Microsoft Office CVE-2017-11882
Internet Information Services 6.0 - Remote Code Execution via WebDAV PROPFIND Request
Adobe Flash Player < 31.0.0.153 - Use-After-Free
University of Washington IMAP Toolkit 2007f - Command Injection
WinRAR <= 5.61 - Path Traversal and Remote Code Execution via ACE Filename Field
iPhone OS < 12.0 - Memory Corruption via ICMP Error Handling
Adobe Flash Player < 28.0.0.161 - Use-After-Free in Primetime SDK Media Player Listener Handling
Windows VBScript Engine - Remote Code Execution via Memory Object Handling
Internet Explorer <11 - Memory Corruption
Microsoft Windows - Remote Code Execution via MSXML Parser
Microsoft Office - Remote Code Execution
CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free
Adobe Acrobat and Reader <2019.021.20056 - Use After Free
sudo 1.7.1-1.8.25 - Stack-based Buffer Overflow via pwfeedback
Android Binder Use-After-Free Exploit
Android 8.0-10 - Unauthenticated Remote Privilege Escalation via Bluetooth Pairing
Android 8.0-10 - Remote Code Execution via Bluetooth Packet Fragment Reassembly
Mediatek Command Queue driver - Privilege Escalation
Android 8.0-9 - Local Privilege Escalation via Confused Deputy in ActivityStartController
Android - Local Privilege Escalation via Uncaught Exception in ServiceRecord