Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-104712 EXPLOITDB php
Apache 2.4.7 + PHP 7.0.2 - 'openssl_seal()' Uninitialized Memory Code Execution
by akat1
EIP-2026-114045 EXPLOITDB php
WordPress Plugin Simple Ads Manager 2.9.4.116 - SQL Injection
by Kacper Szurek
EIP-2026-114912 EXPLOITDB php VERIFIED
Apache 2.4.17 - Denial of Service
by rUnViRuS
EIP-2026-108183 EXPLOITDB php VERIFIED
Joomla! 3.2.x < 3.4.4 - SQL Injection
by Manish Tanwar
CVE-2014-6332 EXPLOITDB HIGH php VERIFIED
Microsoft Windows - RCE
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
by Ehsan Noreddini
CVSS 8.8
CVE-2014-6332 EXPLOITDB HIGH php VERIFIED
Microsoft Windows - RCE
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
by Ehsan Noreddini
CVSS 8.8
CVE-2015-7603 EXPLOITDB php
Konica Minolta FTP Utility 1.0 - Path Traversal
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in a RETR command.
by shinnai
EIP-2026-110630 EXPLOITDB php
PHP 5.5.9 - 'zend_executor_globals' 'CGIMode FPM WriteProcMemFile' disable_functions Bypass / Load Dynamic Library
by ylbhz
EIP-2026-106817 EXPLOITDB php
Elastix < 2.5 - PHP Code Injection
by i-Hmx
CVE-2012-3448 EXPLOITDB php
Ganglia Web <3.5.1 - RCE
Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors.
by Andrei Costin
CVE-2014-6332 EXPLOITDB HIGH php VERIFIED
Microsoft Windows - RCE
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
by Mohammad Reza Espargham
CVSS 8.8
EIP-2026-109995 EXPLOITDB php
Nuts CMS - PHP Remote Code Injection / Execution
by Yakir Wizman
CVE-2014-6332 EXPLOITDB HIGH php
Microsoft Windows - RCE
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
by Mohammad Reza Espargham
CVSS 8.8
EIP-2026-118680 EXPLOITDB php
Impero Education Pro - System Remote Command Execution
by slipstream
CVE-2015-6512 EXPLOITDB php
Codelogic Freichat - SQL Injection
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php.
by Kacper Szurek
CVE-2014-6332 EXPLOITDB HIGH php VERIFIED
Microsoft Windows - RCE
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
by Mohammad Reza Espargham
CVSS 8.8
EIP-2026-104555 EXPLOITDB php VERIFIED
Apple Mac OSX 10.10.3 (Yosemite) Safari 8.0.x - Crash (PoC)
by Mohammad Reza Espargham
CVE-2012-3577 EXPLOITDB php VERIFIED
Nmedia Member Conversation < 1.3 - Access Control
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.
by Sammy FORGIT
EIP-2026-113702 EXPLOITDB php VERIFIED
WordPress Plugin dzs-zoomsounds 2.0 - Arbitrary File Upload
by nabil chris
EIP-2026-101118 EXPLOITDB php
ZYXEL P-660HN-T1H_IPv6 - Remote Configuration Editor / Web Server Denial of Service
by Koorosh Ghorbani
EIP-2026-113453 EXPLOITDB php
Wolf CMS 0.8.2 - Arbitrary File Upload
by CWH Underground
EIP-2026-110242 EXPLOITDB php
Open-Letters - Remote PHP Code Injection
by TUNISIAN CYBER
EIP-2026-113828 EXPLOITDB php
WordPress Plugin InBoundio Marketing 1.0 - Arbitrary File Upload
by KedAns-Dz
EIP-2026-113302 EXPLOITDB php
WeBid 1.1.1 - Unrestricted Arbitrary File Upload
by CWH Underground
CVE-2015-2196 EXPLOITDB php VERIFIED
Web-dorado Spider Calendar - SQL Injection
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.
by Mateusz Lach