Python Exploits

5,917 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-117707 EXPLOITDB python
NScan 0.9.1 - 'Target' Local Buffer Overflow
by hyp3rlinx
EIP-2026-115360 EXPLOITDB python
Goron WebServer 2.0 - Multiple Vulnerabilities
by Guillaume Kaddouch
EIP-2026-107579 EXPLOITDB python
HelpDeskZ 1.0.2 - Arbitrary File Upload
by Lars Morgenroth
EIP-2026-101431 EXPLOITDB python
Samsung Smart Home Camera SNH-P-6410 - Command Injection
by PentestPartners
EIP-2026-103111 EXPLOITDB python
FreePBX 13/14 - Remote Command Execution / Privilege Escalation
by pgt
CVE-2016-6483 EXPLOITDB HIGH python
vBulletin <4.2.2 PL6-5.2.2 PL1 - SSRF
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Level 1 allows remote attackers to conduct SSRF attacks via a crafted URL that results in a Redirection HTTP status code.
by Dawid Golunski
CVSS 8.6
EIP-2026-106987 EXPLOITDB python
EyeLock nano NXT 3.5 - Remote Code Execution
by LiquidWorm
EIP-2026-110001 EXPLOITDB python
NUUO NVRmini 2 3.0.8 - Remote Code Execution
by LiquidWorm
CVE-2016-20046 EXPLOITDB HIGH python
zFTP Client 20061220+dfsg3-4.1 Local Buffer Overflow
zFTP Client 20061220+dfsg3-4.1 contains a buffer overflow vulnerability in the NAME parameter handling of FTP connections that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized NAME value exceeding the 80-byte buffer allocated in strcpy_chk to overwrite the instruction pointer and execute shellcode with user privileges.
by Juan Sacco
CVSS 8.4
EIP-2026-115523 EXPLOITDB python
Kodi Web Server 16.1 - Denial of Service
by Guillaume Kaddouch
EIP-2026-104364 EXPLOITDB python
ntop-ng 2.5.160805 - Username Enumeration
by Dolev Farhi
EIP-2026-115374 EXPLOITDB python
Halliburton LogView Pro 9.7.5 - '.cgm' / '.tif' / '.tiff' / '.tifh' Crash (PoC)
by Karn Ganeshen
EIP-2026-118472 EXPLOITDB python
Easy File Sharing Web Server 7.2 - Remote Overflow (Egghunter) (SEH)
by ch3rn0byl
EIP-2026-118082 EXPLOITDB python
VUPlayer 2.49 - '.pls' File Stack Buffer Overflow (DEP Bypass)
by vportal
CVE-2016-5734 EXPLOITDB CRITICAL python
phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - RCE
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated by the table search-and-replace implementation.
by @iamsecurity
CVSS 9.8
CVE-2016-15056 EXPLOITDB HIGH python
Ubee EVW3226 <1.0.20 - Info Disclosure
Ubee EVW3226 cable modem/routers firmware versions up to and including 1.0.20 store configuration backup files in the web root after they are generated for download. These backup files remain accessible without authentication until the next reboot. A remote attacker on the local network can request 'Configuration_file.cfg' directly to obtain the backup archive. Because backup files are not encrypted, they expose sensitive information including the plaintext admin password, allowing full compromise of the device.
by Gergely Eberhardt
EIP-2026-117468 EXPLOITDB python
Mediacoder 0.8.43.5852 - '.m3u' (SEH)
by Karn Ganeshen
EIP-2026-116999 EXPLOITDB python
CoolPlayer+ Portable 2.19.6 - '.m3u' File Stack Overflow (Egghunter + ASLR Bypass)
by Karn Ganeshen
CVE-2016-5399 EXPLOITDB HIGH python VERIFIED
Php < 5.5.37 - Out-of-Bounds Write
The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.
by Hans Jerry Illikainen
CVSS 7.8
EIP-2026-101559 EXPLOITDB python
Bellini/Supercook Wi-Fi Yumi SC200 - Multiple Vulnerabilities
by James McLean
EIP-2026-100908 EXPLOITDB python
Technicolor TC7200 Modem/Router STD6.02.11 - Multiple Vulnerabilities
by Gergely Eberhardt
EIP-2026-119214 EXPLOITDB python
TFTP Server 1.4 - 'WRQ' Remote Buffer Overflow (Egghunter)
by Karn Ganeshen
CVE-2016-6210 EXPLOITDB MEDIUM python
OpenSSH <7.3 - Info Disclosure
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
by 0_o
CVSS 5.9
EIP-2026-103869 EXPLOITDB python
Axis Communications MPQT/PACS 5.20.x - Server-Side Include Daemon Remote Format String
by bashis
CVE-2016-3962 EXPLOITDB HIGH python
Meinberg IMS-LANTIME - Buffer Overflow
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via a crafted parameter in a POST request.
by b0yd
CVSS 7.3