CrashBandicot

13 exploits Active since Oct 2019
CVE-2015-9464 EXPLOITDB HIGH text WORKING POC
S3bubble-amazon-s3-html-5-video-with-adverts - Path Traversal
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
CVSS 7.5
CVE-2015-10087 EXPLOITDB MEDIUM text WORKING POC
UpThemes Theme DesignFolio Plus 1.2 - Unrestricted Upload
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 53f6ae62878076f99718e5feb589928e83c879a9. It is recommended to apply a patch to fix this issue. The identifier VDB-221809 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS 6.3
EIP-2026-113805 EXPLOITDB text WORKING POC
WordPress Plugin HB Audio Gallery Lite 1.0.0 - Arbitrary File Download
EIP-2026-113522 EXPLOITDB text WORKING POC
WordPress Plugin Abtest - Local File Inclusion
EIP-2026-113826 EXPLOITDB text WORKING POC
WordPress Plugin IMDb Profile Widget 1.0.8 - Local File Inclusion
EIP-2026-113835 EXPLOITDB text WORKING POC
WordPress Plugin Insert PHP 3.3.1 - PHP Code Injection
EIP-2026-113952 EXPLOITDB text WORKING POC
WordPress Plugin Photocart Link 1.6 - Local File Inclusion
EIP-2026-114004 EXPLOITDB text WORKING POC
WordPress Plugin Reflex Gallery 3.1.3 - Arbitrary File Upload
EIP-2026-112839 EXPLOITDB text WORKING POC
TYPO3 Extension Restler 1.7.0 - Local File Disclosure
EIP-2026-110592 EXPLOITDB text WORKING POC
Phoenix Exploit Kit - Remote Code Execution
EIP-2026-108540 EXPLOITDB text WORKING POC
Joomla! Component com_simpleimageupload - Arbitrary File Upload
EIP-2026-108356 EXPLOITDB text WORKING POC
Joomla! Component com_gallery_wd - SQL Injection
EIP-2026-108541 EXPLOITDB text WORKING POC
Joomla! Component com_simplephotogallery 1.0 - Arbitrary File Upload