Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-109242 EXPLOITDB php
Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
by GeekHack
EIP-2026-106757 EXPLOITDB php
Ecommerce Systempay 1.0 - Production KEY Brute Force
by live3
CVE-2020-8547 EXPLOITDB CRITICAL php
phpList 3.5.0 - Auth Bypass
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
by Suvadip Kar
CVSS 9.8
EIP-2026-104705 EXPLOITDB php
PHP 7.0 < 7.4 (Unix) - 'debug_backtrace' disable_functions Bypass
by mm0r1
CVE-2019-19576 EXPLOITDB CRITICAL php
verot.net class.upload <2.0.4 - Info Disclosure
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
by Jinny Ramsmark
CVSS 9.8
CVE-2019-5434 EXPLOITDB CRITICAL php
XML-RPC - Code Injection
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0.
by crlf
CVSS 9.8
CVE-2019-17132 EXPLOITDB CRITICAL php
Vbulletin < 5.5.4 - Code Injection
vBulletin through 5.5.4 mishandles custom avatars.
by EgiX
CVSS 9.8
EIP-2026-110631 EXPLOITDB php
PHP 7.0 < 7.3 (Unix) - 'gc' disable_functions Bypass
by mm0r1
EIP-2026-106426 EXPLOITDB php
Detrix EDMS 1.2.3.1505 - SQL Injection
by Burov Konstantin
EIP-2026-104393 EXPLOITDB php
PHP 7.1 < 7.3 - 'json serializer' disable_functions Bypass
by mm0r1
EIP-2026-109825 EXPLOITDB php
Nagios XI 5.6.5 - Remote Code Execution / Root Privilege Escalation
by Jak Gibb
EIP-2026-109703 EXPLOITDB php
MyBB < 1.8.21 - Remote Code Execution
by Giovanni Chhatta
CVE-2019-0211 EXPLOITDB HIGH php
Apache HTTP Server < 2.4.38 - Use After Free
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
by cfreal
CVSS 7.8
CVE-2019-9768 EXPLOITDB HIGH php
Thinkst Canarytokens <4e89ee0 - Info Disclosure
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token.
by Benjamin Zink Loft_ Gionathan Reale
CVSS 7.5
CVE-2018-1133 EXPLOITDB HIGH php
Moodle 3.x - RCE
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
by Darryn Ten
CVSS 8.8
CVE-2019-6977 EXPLOITDB HIGH php
GD Graphics Library <2.2.5 - Buffer Overflow
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.
by cfreal
CVSS 8.8
CVE-2018-20782 EXPLOITDB HIGH php
Globee Woocommerce < 1.1.2 - Improper Input Validation
The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.
by GeekHack
CVSS 7.5
CVE-2018-19125 EXPLOITDB HIGH php
PrestaShop <1.6.1.23, <1.7.4.4 - Path Traversal
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.
by Fariskhi Vidyan
CVSS 7.5
CVE-2018-19126 EXPLOITDB CRITICAL php
Prestashop < 1.6.1.23 - Unrestricted File Upload
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
by Fariskhi Vidyan
CVSS 9.8
EIP-2026-102947 EXPLOITDB php VERIFIED
PHP 5.2.3 imap (Debian Based) - 'imap_open' disable_functions Bypass
by Anton Lopanitsyn
EIP-2026-101119 EXPLOITDB php
ZyXEL VMG3312-B10B < 1.00(AAPP.7) - Credential Disclosure
by numan türle
EIP-2026-104895 EXPLOITDB php
Academic Timetable Final Build 7.0 - Information Disclosure
by Ihsan Sencan
EIP-2026-109013 EXPLOITDB php VERIFIED
KingMedia 4.1 - File Upload
by Efrén Díaz
CVE-2018-15576 EXPLOITDB HIGH php VERIFIED
Hazzardweb Easylogin Pro < 1.3.0 - Insecure Deserialization
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.
by mr_me
CVSS 8.1
CVE-2018-12254 EXPLOITDB HIGH php
Harmis Ek Rishta <2.10 - SQL Injection
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.
by Guilherme Assmann
CVSS 8.8