Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112259 EXPLOITDB php VERIFIED
SN News 1.2 - 'visualiza.php' SQL Injection
by WhiteCollarGroup
CVE-2012-10027 EXPLOITDB CRITICAL php VERIFIED
WP-Property <1.35.0 - RCE
WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
by Sammy FORGIT
CVE-2012-10026 EXPLOITDB CRITICAL php VERIFIED
Asset-Manager <2.0 - RCE
The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious PHP scripts to a predictable temporary directory. Once uploaded, the attacker can execute the file via a direct HTTP GET request, resulting in remote code execution under the web server’s context.
by Sammy FORGIT
EIP-2026-113881 EXPLOITDB php VERIFIED
WordPress Plugin Marketplace Plugin 1.5.0 < 1.6.1 - Arbitrary File Upload
by Sammy FORGIT
EIP-2026-113812 EXPLOITDB php VERIFIED
WordPress Plugin HTML5 AV Manager 0.2.7 - Arbitrary File Upload
by Sammy FORGIT
EIP-2026-113796 EXPLOITDB php VERIFIED
WordPress Plugin Google Maps via Store Locator 2.7.1 < 3.0.1 - Multiple Vulnerabilities
by Sammy FORGIT
EIP-2026-113768 EXPLOITDB php VERIFIED
WordPress Plugin Foxypress 0.4.1.1 < 0.4.2.1 - Arbitrary File Upload
by Sammy FORGIT
EIP-2026-109520 EXPLOITDB php VERIFIED
Mnews 1.1 - 'view.php' SQL Injection
by WhiteCollarGroup
EIP-2026-113964 EXPLOITDB php VERIFIED
WordPress Plugin Picturesurf Gallery - 'upload.php' Arbitrary File Upload
by Sammy FORGIT
EIP-2026-104659 EXPLOITDB php
PHP 5.3.10 - 'spl_autoload_register()' Local Denial of Service
by Yakir Wizman
EIP-2026-104658 EXPLOITDB php
PHP 5.3.10 - 'spl_autoload_call()' Local Denial of Service
by Yakir Wizman
EIP-2026-104657 EXPLOITDB php
PHP 5.3.10 - 'spl_autoload()' Local Denial of Service
by Yakir Wizman
EIP-2026-115552 EXPLOITDB php VERIFIED
LibreOffice 3.5.3 - '.rtf' FileOpen Crash
by shinnai
EIP-2026-112224 EXPLOITDB php VERIFIED
Small-Cms - 'hostname' Remote PHP Code Injection
by L3b-r1'z
EIP-2026-115012 EXPLOITDB php VERIFIED
bsnes 0.87 - Local Denial of Service
by Yakir Wizman
EIP-2026-112491 EXPLOITDB php VERIFIED
Supernews 2.6.1 - SQL Injection
by WhiteCollarGroup
EIP-2026-104663 EXPLOITDB php VERIFIED
PHP 5.4.3 - wddx_serialize_* / stream_bucket_* Variant Object Null Ptr Dereference
by condis
EIP-2026-104662 EXPLOITDB php VERIFIED
PHP 5.4.3 - 'com_event_sink' Denial of Service
by condis
CVE-2012-2376 EXPLOITDB php VERIFIED
PHP <5.4.3 - RCE
Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.
by 0in
CVE-2012-2052 EXPLOITDB php VERIFIED
Adobe Photoshop Cs5 - Memory Corruption
Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the cameraYFov value in the contributor comments element.
by rgod
CVE-2012-1002 EXPLOITDB php VERIFIED
OpenConf <4.12 - SQL Injection
SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
by EgiX
EIP-2026-109805 EXPLOITDB php VERIFIED
MySQLDumper 1.24.4 - 'menu.php' PHP Remote Code Execution
by AkaStep
CVE-2012-1495 EXPLOITDB CRITICAL php VERIFIED
Webcalendar < 1.2.5 - Injection
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
by EgiX
CVSS 9.8
CVE-2012-1496 EXPLOITDB HIGH php VERIFIED
Webcalendar < 1.2.5 - Injection
Local file inclusion in WebCalendar before 1.2.5.
by EgiX
CVSS 8.8
EIP-2026-103534 EXPLOITDB php
LibreOffice 3.5.2.2 - Memory Corruption
by shinnai