Bash Exploits

462 exploits tracked across all sources.

Sort: Activity Stars
CVE-2026-44596 EXPLOITDB bash
YAMCS yamcs-core 5.12.7 - No Rate Limiting
by Daniel Miranda
CVE-2026-46522 EXPLOITDB bash
ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
by Jose Rivas
CVE-2026-0740 EXPLOITDB CRITICAL bash
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability was partially patched in version 3.3.25 and fully patched in version 3.3.27.
by selim.lanouar
CVSS 9.8
CVE-2025-62360 EXPLOITDB HIGH bash
WeGIA < 3.5.1 - SQL Injection via id_dependente Parameter
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.
by onurdemir
CVSS 8.8
CVE-2025-34506 EXPLOITDB HIGH bash
WBCE CMS < 1.6.3 - Authenticated Remote Code Execution via Malicious Module Upload
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.
by Swammers8
CVSS 8.8
CVE-2022-35914 EXPLOITDB CRITICAL bash
GLPI htmLawed php command injection
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
by Miguel Redondo
CVSS 9.8
EIP-2026-102817 EXPLOITDB bash
Dell Security Management Server <1.9.0 - Local Privilege Escalation
by Amirhossein Bahramizadeh
CVE-2023-37569 EXPLOITDB HIGH bash
ESDS Emagic Data Center Management Suite < 6.0 - Authenticated OS Command Injection via Ping Component
This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.
by thewhiteh4t
CVSS 8.8
CVE-2023-37629 EXPLOITDB CRITICAL bash VERIFIED
Online Piggery Management System 1.0 - Unauthenticated Arbitrary File Upload via add-pig.php
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."
by 1337kid
CVSS 9.8
CVE-2023-53908 EXPLOITDB HIGH bash
HiSecOS 04.0.01 - Privilege Escalation
HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.
by dreizehnutters
CVSS 8.8
CVE-2023-30330 EXPLOITDB CRITICAL bash
SoftExpert Excellence Suite 2.0-2.1.2 - Local File Inclusion via defaultframe_filter.php
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
by Felipe Alcantara
CVSS 9.8
CVE-2023-1671 EXPLOITDB CRITICAL bash
Sophos Web Appliance <4.3.10.4 - Command Injection
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
by Behnam Abasi Vanda
CVSS 9.8
CVE-2023-24709 EXPLOITDB HIGH bash
Paradox Security Systems IPR512 - DoS
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.
by Giorgi Dograshvili
CVSS 7.5
CVE-2023-22809 EXPLOITDB HIGH bash
Sudoedit Extra Arguments Priv Esc
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
by n3m1.sys
CVSS 7.8
EIP-2026-101159 EXPLOITDB bash
ASKEY RTF3505VW-N1 - Privilege Escalation
by Leonardo Nicolas Servalli
CVE-2022-40684 EXPLOITDB CRITICAL bash
Fortinet Fortiproxy < 7.0.7 - Authentication Bypass
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
by Felipe Alcantara
CVSS 9.8
EIP-2026-119275 EXPLOITDB bash
WiFiMouse 1.8.3.4 - Remote Code Execution (RCE)
by FEBIN MON SAJI
CVE-2021-45010 EXPLOITDB HIGH bash
Tiny File Manager < 2.4.7 - Authenticated Path Traversal and Remote Code Execution via File Upload
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
by FEBIN MON SAJI
CVSS 8.8
CVE-2022-0848 EXPLOITDB CRITICAL bash
part-db < 0.5.11 - OS Command Injection
OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.
by Chetanya Sharma
CVSS 9.8
CVE-2022-50927 EXPLOITDB MEDIUM bash
Cyclades Serial Console Server 3.3.0 - Privilege Escalation
Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted sudo permissions.
by ibby
CVSS 6.2
CVE-2021-47936 EXPLOITDB CRITICAL bash
OpenCATS 0.9.4 Remote Code Execution via Resume Upload
OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system commands via POST requests to the uploaded file in the upload directory.
by Nicholas Ferreira
CVSS 9.8
EIP-2026-114218 EXPLOITDB bash
Wordpress Plugin WP Guppy 1.1 - WP-JSON API Sensitive Information Disclosure
by Keyvan Hardani
CVE-2021-42013 EXPLOITDB CRITICAL bash
Apache HTTP Server 2.4.49-2.4.50 - Path Traversal and Remote Code Execution via Alias-like Directives
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
by ThelastVvV
CVSS 9.8
CVE-2021-42013 EXPLOITDB CRITICAL bash VERIFIED
Apache HTTP Server 2.4.49-2.4.50 - Path Traversal and Remote Code Execution via Alias-like Directives
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
by Lucas Souza
CVSS 9.8
CVE-2021-41773 EXPLOITDB CRITICAL bash VERIFIED
Apache 2.4.49/2.4.50 Traversal RCE
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
by Lucas Souza
CVSS 9.8