Python Exploits

5,914 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-1010163 EXPLOITDB HIGH python
Socusoft Co Photo 2 Video Converter 8.0.0 - Buffer Overflow
Socusoft Co Photo 2 Video Converter 8.0.0 is affected by: Buffer Overflow - Local shell-code execution and Denial of Service. The impact is: Local privilege escalation (dependant upon conditions), shell code execution and denial-of-service. The component is: pdmlog.dll library. The attack vector is: The attacker must have access to local system (either directly, or remotley).
by ret2eax
CVSS 7.8
CVE-2017-5816 EXPLOITDB CRITICAL python VERIFIED
HP Intelligent Management Center < 7.3 - Improper Input Validation
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
by Chris Lyne
CVSS 9.8
EIP-2026-118437 EXPLOITDB python
Dup Scout Enterprise 10.0.18 - 'Input Directory' Local Buffer Overflow (SEH)
by Miguel Mendez Z
CVE-2017-5817 EXPLOITDB CRITICAL python VERIFIED
HP Intelligent Management Center < 7.3 - Improper Input Validation
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
by Chris Lyne
CVSS 9.8
EIP-2026-100907 EXPLOITDB python
Synology StorageManager 5.2 - Root Remote Command Execution
by SecuriTeam
EIP-2026-100020 EXPLOITDB python VERIFIED
Android Gmail < 7.11.5.176568039 - Directory Traversal in Attachment Download
by Google Security Research
EIP-2026-114888 EXPLOITDB python
ALLPlayer 7.5 - Denial of-Service (PoC)
by Kiefer Bauer
EIP-2026-116771 EXPLOITDB python VERIFIED
ALLPlayer 7.5 - Local Buffer Overflow (SEH Unicode)
by sickness
CVE-2017-16902 EXPLOITDB HIGH python
Vonage VDV-23 115 <3.2.11-0.9.40 - DoS
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.
by Nu11By73
CVSS 7.5
CVE-2017-13849 EXPLOITDB MEDIUM python VERIFIED
Apple <11.1 - DoS
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.
by Russian Otter
CVSS 5.5
EIP-2026-118085 EXPLOITDB python VERIFIED
VX Search 10.2.14 - 'Proxy' Local Buffer Overflow (SEH)
by wetw0rk
EIP-2026-118438 EXPLOITDB python VERIFIED
Dup Scout Enterprise 10.0.18 - 'Login' Remote Buffer Overflow
by sickness
CVE-2017-16806 EXPLOITDB HIGH python
Ulterius Server < 1.9.5.0 - Directory Traversal
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal.
by Rick Osgood
CVSS 7.5
EIP-2026-110378 EXPLOITDB python
osCommerce 2.3.4.1 - Arbitrary File Upload
by Simon Scannell
EIP-2026-116605 EXPLOITDB python VERIFIED
Xlight FTP Server 3.8.8.5 - Buffer Overflow (PoC)
by bzyo
EIP-2026-116256 EXPLOITDB python
SMPlayer 17.11.0 - '.m3u' Buffer Overflow (PoC)
by bzyo
CVE-2017-16352 EXPLOITDB HIGH python
GraphicsMagick 1.3.26 - Buffer Overflow
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. One possible way to trigger the vulnerability is to run the identify command on a specially crafted MIFF format file with the verbose flag.
by SecuriTeam
CVSS 8.8
EIP-2026-115493 EXPLOITDB python
Jnes 1.0.2 - Stack Buffer Overflow
by crash_manucoot
CVE-2017-16513 EXPLOITDB HIGH python VERIFIED
Ipswitch WS_FTP Pro <12.6.0.3 - Buffer Overflow
Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729.
by Kevin McGuigan
CVSS 7.8
CVE-2017-16353 EXPLOITDB MEDIUM python
GraphicsMagick 1.3.26 - Info Disclosure
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can be triggered with a specially crafted MIFF file. There is an out-of-bounds buffer dereference because certain increments are never checked.
by SecuriTeam
CVSS 6.5
CVE-2017-16249 EXPLOITDB HIGH python
Debut embedded http server - DoS
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
by z00n
CVSS 7.5
EIP-2026-102192 EXPLOITDB python
WhatsApp 2.17.52 - Memory Corruption
by Juan Sacco
CVE-2017-10309 EXPLOITDB HIGH python VERIFIED
Oracle Jdk < 11.70.1 - Denial of Service
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u144 and 9. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
by mr_me
CVSS 7.1
EIP-2026-114139 EXPLOITDB python
WordPress Plugin Ultimate Product Catalog 4.2.24 - PHP Object Injection
by tomplixsee
EIP-2026-116413 EXPLOITDB python
Tizen Studio 1.3 Smart Development Bridge < 2.3.2 - Buffer Overflow (PoC)
by Marcin Kopec