Tulpa

29 exploits Active since Jan 2018
CVE-2016-20094 EXPLOITDB HIGH text WRITEUP
AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.
CVSS 7.8
CVE-2016-20093 EXPLOITDB HIGH text WRITEUP
Wise Care 365 4.27 and Wise Disk Cleaner 9.29 Unquoted Service Path Privilege Escalation
Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that execute during service startup or system reboot with elevated privileges.
CVSS 7.8
CVE-2016-20092 EXPLOITDB HIGH text WRITEUP
NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege
NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.
CVSS 7.8
CVE-2016-20089 EXPLOITDB HIGH text WRITEUP
Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege
Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation path. When installed from directories containing spaces, attackers can place malicious executables in the path to be executed with elevated privileges during service startup or system reboot.
CVSS 7.8
CVE-2016-20087 EXPLOITDB HIGH text WRITEUP
Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the service binary path. Attackers can insert malicious executables in the system root path that execute with SYSTEM privileges during service startup or system reboot.
CVSS 7.8
CVE-2025-34108 EXPLOITDB HIGH python WORKING POC
Disk Pulse Enterprise <9.0.34 - Buffer Overflow
A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. An attacker can send a specially crafted HTTP POST request to the /login endpoint with an overly long username parameter, causing a buffer overflow in the libspp.dll component. Successful exploitation allows arbitrary code execution with SYSTEM privileges.
CVE-2017-18047 EXPLOITDB CRITICAL ruby WORKING POC
LabF nfsAxe 3.7 - Buffer Overflow via Long FTP Reply
Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long reply.
CVSS 9.8
CVE-2017-18047 EXPLOITDB CRITICAL python WORKING POC
LabF nfsAxe 3.7 - Buffer Overflow via Long FTP Reply
Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long reply.
CVSS 9.8
CVE-2017-18047 METASPLOIT CRITICAL ruby WORKING POC
LabF nfsAxe 3.7 - Buffer Overflow via Long FTP Reply
Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long reply.
CVSS 9.8
EIP-2026-119261 EXPLOITDB python WORKING POC
VX Search Enterprise 9.0.26 - 'Login' Remote Buffer Overflow
EIP-2026-119262 EXPLOITDB python WORKING POC
VX Search Enterprise 9.1.12 - 'Login' Remote Buffer Overflow
EIP-2026-119190 EXPLOITDB python WORKING POC
Sync Breeze Enterprise 8.9.24 - 'Login' Remote Buffer Overflow
EIP-2026-119191 EXPLOITDB python WORKING POC
Sync Breeze Enterprise 9.1.16 - 'Login' Remote Buffer Overflow
EIP-2026-118442 EXPLOITDB python WORKING POC
Dup Scout Enterprise 9.1.14 - 'Login' Remote Buffer Overflow
EIP-2026-118410 EXPLOITDB python WORKING POC
Disk Pulse Enterprise 9.1.16 - 'Login' Remote Buffer Overflow
EIP-2026-118419 EXPLOITDB python WORKING POC
Disk Savvy Enterprise 9.0.32 - 'Login' Remote Buffer Overflow
EIP-2026-118421 EXPLOITDB python WORKING POC
Disk Savvy Enterprise 9.1.14 - 'Login' Remote Buffer Overflow
EIP-2026-118423 EXPLOITDB python WORKING POC
Disk Sorter Enterprise 9.0.24 - 'Login' Remote Buffer Overflow
EIP-2026-118424 EXPLOITDB python WORKING POC
Disk Sorter Enterprise 9.1.12 - 'Login' Remote Buffer Overflow
EIP-2026-118439 EXPLOITDB python WORKING POC
Dup Scout Enterprise 10.0.18 - 'online_registration' Remote Buffer Overflow
EIP-2026-118441 EXPLOITDB python WORKING POC
Dup Scout Enterprise 9.0.28 - 'Login' Remote Buffer Overflow
EIP-2026-118449 EXPLOITDB text WORKING POC
DWebPro 8.4.2 - Multiple Vulnerabilities
EIP-2026-118135 EXPLOITDB text WRITEUP
WinSMS 3.43 - Insecure File Permissions Privilege Escalation
EIP-2026-118210 EXPLOITDB text WRITEUP
Zortam Mp3 Media Studio 21.15 - Insecure File Permissions Privilege Escalation
EIP-2026-117681 EXPLOITDB text WRITEUP
Netgear Genie 2.4.32 - Unquoted Service Path Privilege Escalation