Python Exploits

6,615 exploits tracked across all sources.

Sort: Activity Stars
CVE-2020-13927 EXPLOITDB CRITICAL python
Apache Airflow < 1.10.11 - Unauthenticated Remote Code Execution via Experimental API
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default
by Pepe Berba
CVSS 9.8
CVE-2021-47818 EXPLOITDB HIGH python
DupTerminator <1.4.5639.37199 - DoS
DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application by inputting a long character string in the Excluded text box. Attackers can generate a payload of 8000 repeated characters to trigger the application to stop working on Windows 10.
by Brian Rodriguez
CVSS 7.5
CVE-2018-16167 EXPLOITDB CRITICAL python
LogonTracer < 1.2.0 - OS Command Injection
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
by g0ldm45k
CVSS 9.8
EIP-2026-104176 EXPLOITDB python
Atlassian Jira 8.15.0 - Information Disclosure (Username Enumeration)
by Mohammed Aloraimi
CVE-2017-14535 EXPLOITDB HIGH python
Trixbox - 2.8.0.4 OS Command Injection
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
by Ron Jost
CVSS 8.8
CVE-2017-14537 EXPLOITDB MEDIUM python
Trixbox 2.8.0 - Path Traversal
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
by Ron Jost
CVSS 6.5
CVE-2020-24949 EXPLOITDB HIGH python VERIFIED
php-fusion 9.03.50 - Authenticated Remote Code Execution via Downloads Endpoint
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).
by g0ldm45k
CVSS 8.8
CVE-2021-33570 EXPLOITDB MEDIUM python
Postbird 0.8.4 - Stored Cross-Site Scripting via IMG onerror Attribute
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
by Debshubra Chakraborty
CVSS 5.4
CVE-2021-47821 EXPLOITDB HIGH python
RarmaRadio 2.72.8 - Denial of Service via Network Configuration Field Buffer Overflow
RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffers. Attackers can generate a 100,000 character buffer and paste it into multiple network settings fields to trigger application instability and potential crash.
by Ismael Nava
CVSS 7.5
CVE-2020-29607 EXPLOITDB HIGH python VERIFIED
Pluck CMS < 4.7.13 - Authenticated Remote Code Execution via File Upload Restriction Bypass
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
by Ron Jost
CVSS 7.2
CVE-2018-19423 EXPLOITDB HIGH python
Codiad 2.8.4 - Authenticated Remote Code Execution via File Upload
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
by Ron Jost
CVSS 7.2
CVE-2015-3306 EXPLOITDB python VERIFIED
ProFTPD 1.3.5 - Unauthenticated Arbitrary File Read and Write via mod_copy Site Commands
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
by Shellbr3ak
CVE-2019-19208 EXPLOITDB CRITICAL python
Codiad Web IDE <2.8.4 - Code Injection
Codiad Web IDE through 2.8.4 allows PHP Code injection.
by Ron Jost
CVSS 9.8
EIP-2026-117635 EXPLOITDB python VERIFIED
Mozilla Firefox 88.0.1 - File Extension Execution of Arbitrary Code
by BestEffort Team
CVE-2020-14871 EXPLOITDB CRITICAL python
Oracle Solaris 10-11 - Privilege Escalation
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
by legend
CVSS 10.0
CVE-2021-47827 EXPLOITDB HIGH python
WebSSH for iOS 14.16.10 - Denial of Service via MashREPL Input Buffer Overflow
WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash the application by pasting malformed input. Attackers can trigger the vulnerability by copying a 300-character buffer of repeated 'A' characters into the mashREPL input field, causing the application to crash.
by Luis Martínez
CVSS 7.5
EIP-2026-104321 EXPLOITDB python
ManageEngine ADSelfService Plus 6.1 - CSV Injection
by Metin Yunus Kandemir
CVE-2021-26855 EXPLOITDB CRITICAL python
Microsoft Exchange ProxyLogon RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
by Gonzalo Villegas
CVSS 9.1
CVE-2018-19422 EXPLOITDB HIGH python
Subrion CMS < 4.2.2 - Remote Code Execution via .pht or .phar File Upload
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
by Fellipe Oliveira
CVSS 7.2
CVE-2021-33393 EXPLOITDB HIGH python
IPFire 2.25-core155 - Privilege Escalation
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. Similar problems with the ownership/permissions of other files may be present as well.
by Mücahit Saratar
CVSS 8.8
CVE-2021-31933 EXPLOITDB HIGH python VERIFIED
Chamilo <= 1.11.14 - Authenticated Remote Code Execution via File Upload Parameter
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.
by M. Cory Billington
CVSS 7.2
CVE-2019-12725 EXPLOITDB CRITICAL python
ZeroShell 3.9.0 - Unauthenticated Remote Command Execution via HTTP Parameter Injection
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
by Fellipe Oliveira
CVSS 9.8
CVE-2020-28337 EXPLOITDB HIGH python
Microweber < 1.1.20 - Authenticated Remote Code Execution via Backup Restore Path Traversal
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
by sl1nki
CVSS 7.2
CVE-2021-47831 EXPLOITDB HIGH python
Sandboxie 5.49.7 - Denial of Service via Container Folder Input Overflow
Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the container folder input field. Attackers can paste a large buffer of repeated characters into the Sandbox container folder setting to trigger an application crash.
by Erick Galindo
CVSS 7.5
EIP-2026-107674 EXPLOITDB python
Human Resource Information System 0.1 - Remote Code Execution (Unauthenticated)
by Reza Afsahi