Python Exploits

6,637 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113009 EXPLOITDB python
vBulletin 5.6.1 - 'nodeId' SQL Injection
by Photubias
EIP-2026-117019 EXPLOITDB python
Dameware Remote Support 12.1.1.273 - Buffer Overflow (SEH)
by gurbanli
EIP-2026-106104 EXPLOITDB python
Complaint Management System 1.0 - 'username' SQL Injection
by Daniel Ortiz
CVE-2020-37074 EXPLOITDB CRITICAL python
Remote Desktop Audit 2.3.0.157 - RCE
Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer lists.
by gurbanli
CVSS 9.8
CVE-2020-37075 EXPLOITDB CRITICAL python
LanSend 3.2 - Remote Code Execution via Add Computers Wizard File Import
LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) overwrite and execute shellcode when importing computers from a file.
by gurbanli
CVSS 9.8
EIP-2026-103377 EXPLOITDB python
MacOS 320.whatis Script - Privilege Escalation
by Csaba Fitzl
CVE-2019-16112 EXPLOITDB HIGH python
TylerTech Eagle 2018.3.11 - Remote Code Execution via Untrusted Java Deserialization
TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.
by Anthony Cole
CVSS 8.8
EIP-2026-114050 EXPLOITDB python
WordPress Plugin Simple File List 4.2.2 - Remote Code Execution
by coiffeur
CVE-2020-11108 EXPLOITDB HIGH python
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.
by Nick Frichette
CVSS 8.8
CVE-2020-11108 EXPLOITDB HIGH python
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.
by Nick Frichette
CVSS 8.8
EIP-2026-115257 EXPLOITDB python
FlashGet 1.9.6 - Denial of Service (PoC)
by Milad karimi
EIP-2026-117206 EXPLOITDB python
Frigate 3.36 - Buffer Overflow (SEH)
by Xenofon Vassilakopoulos
CVE-2020-37085 EXPLOITDB HIGH python
VirtualTablet Server 3.0.2 - Denial of Service via Oversized Thrift Payload
VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by sending oversized string payloads through the Thrift protocol. Attackers can exploit the vulnerability by sending a long string to the send_say() method, causing the server to become unresponsive.
by Dolev Farhi
CVSS 7.5
EIP-2026-110241 EXPLOITDB python VERIFIED
Open-AudIT Professional 3.3.1 - Remote Code Execution
by Askar
EIP-2026-118370 EXPLOITDB python
CloudMe 1.11.2 - Buffer Overflow (PoC)
by Andy Bowden
EIP-2026-117873 EXPLOITDB python
RM Downloader 3.1.3.2.2010.06.13 - 'Load' Buffer Overflow (SEH)
by Felipe Winsnes
CVE-2020-6857 EXPLOITDB MEDIUM python
CarbonFTP 1.4 - Use of a Broken or Risky Cryptographic Algorithm
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.
by hyp3rlinx
CVSS 5.5
EIP-2026-101814 EXPLOITDB python
IQrouter 3.3.1 Firmware - Remote Code Execution
by drakylar
CVE-2020-37221 EXPLOITDB HIGH python
Atomic Alarm Clock 6.3 Stack Overflow via SEH Unicode
Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encoded shellcode to bypass SafeSEH protections and execute arbitrary commands with application privileges.
by boku
CVSS 8.4
CVE-2020-37120 EXPLOITDB CRITICAL python
Rubo DICOM Viewer 2.0 - Buffer Overflow
Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious text file with carefully constructed payload to execute arbitrary code by overwriting SEH and triggering remote code execution.
by bzyo
CVSS 9.8
CVE-2020-37119 EXPLOITDB CRITICAL python
Nsasoft Nsauditor 3.0.28 and 3.2.1.0 - Stack-based Buffer Overflow via DNS Lookup Tool
Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a carefully constructed exploit.
by Cervoise
CVSS 9.8
CVE-2020-37121 EXPLOITDB MEDIUM python
CODE::BLOCKS 16.01 - Buffer Overflow
CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist file with 536 bytes of buffer and shellcode to trigger remote code execution.
by T3jv1l
CVSS 5.5
EIP-2026-117097 EXPLOITDB python
Easy MPEG to DVD Burner 1.7.11 - Buffer Overflow (SEH + DEP)
by Bailey Belisario
EIP-2026-116901 EXPLOITDB python
BlazeDVD 7.0.2 - Buffer Overflow (SEH)
by areyou1or0
CVE-2020-37124 EXPLOITDB CRITICAL python
B64dec 1.1.2 - Stack-based Buffer Overflow via Crafted Base64 Input
B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) with crafted input. Attackers can leverage an egg hunter technique and carefully constructed payload to inject and execute malicious code during base64 decoding process.
by Andy Bowden
CVSS 9.8