Exploitdb Exploits

4,759 exploits tracked across all sources.

Sort: Activity Stars
CVE-2015-5082 EXPLOITDB python
Endian Firewall < 2.5.1 - Remote Command Execution via Password Change Parameters
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.
by Ben Lincoln
EIP-2026-117391 EXPLOITDB python
KMPlayer 3.9.1.136 - Capture Unicode Buffer Overflow (ASLR Bypass)
by Naser Farhadi
EIP-2026-116226 EXPLOITDB python VERIFIED
Seagate Dashboard 4.0.21.0 - Crash (PoC)
by HexTitan
EIP-2026-116566 EXPLOITDB python VERIFIED
WinylPlayer 3.0.3 - Memory Corruption (PoC)
by Rajganesh Pandurangan
EIP-2026-115383 EXPLOITDB python VERIFIED
HansoPlayer 3.4.0 - Memory Corruption (PoC)
by Rajganesh Pandurangan
EIP-2026-116627 EXPLOITDB python VERIFIED
XtMediaPlayer 0.93 - '.wav' Crash (PoC)
by SATHISH ARTHAR
EIP-2026-115249 EXPLOITDB python VERIFIED
FinePlayer 2.20 - '.mp4' Crash (PoC)
by SATHISH ARTHAR
EIP-2026-116108 EXPLOITDB python VERIFIED
Putty 0.64 - Denial of Service
by 3unnym00n
EIP-2026-115248 EXPLOITDB python VERIFIED
FileZilla 3.11.0.2 SFTP Module - Denial of Service
by 3unnym00n
EIP-2026-115336 EXPLOITDB python VERIFIED
GoldWave 6.1.2 - Local Crash (PoC)
by 0neb1n
EIP-2026-115267 EXPLOITDB python VERIFIED
foobar2000 1.3.8 - '.m3u' Local Crash (PoC)
by 0neb1n
CVE-2015-3205 EXPLOITDB python
libmimedir - Remote Code Execution via Malformed VCF File
libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, related to "free" function calls in the "lexer's memory clean-up procedure."
by Jeremy Brown
EIP-2026-101755 EXPLOITDB python
GeoVision (GeoHttpServer) Webcams - Remote File Disclosure
by Viktor Minin
EIP-2026-117370 EXPLOITDB python VERIFIED
Jildi FTP Client 1.5.6 - Local Buffer Overflow (SEH)
by Zahid Adeel
EIP-2026-115492 EXPLOITDB python VERIFIED
Jildi FTP Client - Buffer Overflow (PoC)
by metacom
EIP-2026-101973 EXPLOITDB python
Seagate Central 2014.0410.0026-F - Remote Facebook Access Token
by Jeremy Brown
EIP-2026-101442 EXPLOITDB python
Seagate Central 2014.0410.0026-F - Remote Command Execution
by Jeremy Brown
EIP-2026-119268 EXPLOITDB python VERIFIED
WebDrive 12.2 (Build #4172) - Remote Buffer Overflow
by metacom
EIP-2026-118668 EXPLOITDB python VERIFIED
IBM Security AppScan Standard 9.0.2 - OLE Automation Array Remote Code Execution
by Naser Farhadi
EIP-2026-116094 EXPLOITDB python VERIFIED
Private Shell SSH Client 3.3 - Crash (PoC)
by 3unnym00n
CVE-2015-1833 EXPLOITDB python
Apache Jackrabbit XML External Entity Injection via WebDAV Request
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.
by Mikhail Egorov
EIP-2026-102199 EXPLOITDB python VERIFIED
FTP Media Server 3.0 - Authentication Bypass / Denial of Service
by Wh1t3Rh1n0 (Michael Allen)
EIP-2026-116651 EXPLOITDB python
ZOC SSH Client - Buffer Overflow (SEH) (PoC)
by Dolev Farhi
CVE-2014-9195 EXPLOITDB python VERIFIED
Phoenix Contact ProConOs & MultiProg - RCE
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.
by Photubias
CVE-2014-4113 EXPLOITDB HIGH python VERIFIED
Microsoft Windows - Privilege Escalation
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."
by ryujin
CVSS 7.8