Vulnerability-Lab

343 exploits Active since Jan 2008
EIP-2026-118721 EXPLOITDB text WRITEUP
LAN.FS Messenger 2.4 - Command Execution
CVE-2012-4992 EXPLOITDB text WRITEUP
FlashFXP 4.2 - Authenticated Remote Code Execution via Long Unicode String to TListbox or TComboBox
Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.
EIP-2026-118660 EXPLOITDB text WORKING POC
Huawei HedEx Lite 200R006C00SPC005 - Path Traversal
EIP-2026-117918 EXPLOITDB text WORKING POC
Socusoft Photo 2 Video 8.05 - Local Buffer Overflow
EIP-2026-116910 EXPLOITDB text WORKING POC
Blueberry Express 5.9.0.3678 - Local Buffer Overflow (SEH)
EIP-2026-117337 EXPLOITDB text WORKING POC
Internet Download Manager 6.37.11.1 - Stack Buffer Overflow (PoC)
EIP-2026-116892 EXPLOITDB text WORKING POC
Bitsmith PS Knowbase 3.2.3 - Local Buffer Overflow
EIP-2026-116664 EXPLOITDB text WORKING POC
Zoner Photo Studio 15 b3 - Buffer Overflow (PoC)
EIP-2026-116532 EXPLOITDB text WORKING POC
Wickr Desktop 2.2.1 Windows - Denial of Service
EIP-2026-116529 EXPLOITDB text WRITEUP
WebDrive 12.2 (B4172) - Buffer Overflow (PoC)
EIP-2026-116378 EXPLOITDB text WRITEUP
TagScanner 5.1 - Stack Buffer Overflow (PoC)
EIP-2026-116431 EXPLOITDB text WRITEUP
Trend Micro DirectPass 1.5.0.1060 - Multiple Software Vulnerabilities
CVE-2018-5282 EXPLOITDB HIGH text WORKING POC
Kentico Xperience 9.0-11.0 - Stack-based Buffer Overflow via SilentInstall XML Field
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor disputes this issue because neither a buffer overflow nor a crash can be reproduced; also, reading XML documents is implemented exclusively with managed code within the Microsoft .NET Framework
CVSS 7.8
EIP-2026-115007 EXPLOITDB text WORKING POC
Boxoft Wav 1.0 - Buffer Overflow
EIP-2026-115013 EXPLOITDB text WORKING POC
BulletProof FTP Client 2010 - Buffer Overflow (PoC)
EIP-2026-114902 EXPLOITDB text WRITEUP
AnvSoft Any Video Converter 4.3.6 - Multiple Buffer Overflows
CVE-2016-6186 EXPLOITDB MEDIUM text WRITEUP
Django <1.8.14, <1.9.x, <1.10rc1 - XSS
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.
CVSS 6.1
EIP-2026-114627 EXPLOITDB text WRITEUP
Zikula CMS 1.3.5 - Multiple Vulnerabilities
EIP-2026-114411 EXPLOITDB text WRITEUP
Xavier 2.4 - SQL Injection
CVE-2013-5962 EXPLOITDB text WORKING POC
Gallery Manager Plugin < 3.3.4 rev40279 - Unauthenticated Arbitrary File Upload and RCE via upload-images.php
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
EIP-2026-113556 EXPLOITDB text WORKING POC
WordPress Plugin All In One WP Security & Firewall 3.8.3 - Persistent Cross-Site Scripting
EIP-2026-113810 EXPLOITDB text WRITEUP
WordPress Plugin Hotel Listing 3 - 'Multiple' Cross-Site Scripting (XSS)
EIP-2026-113159 EXPLOITDB text WRITEUP
VTiger v7.0 CRM - 'To' Persistent XSS
EIP-2026-113141 EXPLOITDB text WRITEUP
vOlk Botnet Framework 4.0 - Multiple Vulnerabilities
EIP-2026-113312 EXPLOITDB text WORKING POC
Webile v1.0.1 - Multiple Cross Site Scripting