Python Exploits

5,917 exploits tracked across all sources.

Sort: Activity Stars
CVE-2016-20038 EXPLOITDB HIGH python
yTree 1.94-1.1 Stack-Based Buffer Overflow
yTree 1.94-1.1 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an excessively long argument to the application. Attackers can craft a malicious command-line argument containing shellcode and a return address to overwrite the stack and execute code in the application context.
by Juan Sacco
CVSS 8.4
EIP-2026-114985 EXPLOITDB python
Baumer VeriSens Application Suite 2.6.2 - Buffer Overflow (PoC)
by LiquidWorm
CVE-2016-2534 EXPLOITDB python VERIFIED
Jive Forums 5.5.25 - Directory Traversal
by ZhaoHuAn
EIP-2026-107960 EXPLOITDB python
iScripts EasyCreate 3.0 - Remote Code Execution
by Bikramaditya Guha
EIP-2026-101881 EXPLOITDB python
Netgear WNR1000v4 - Authentication Bypass
by Daniel Haake
CVE-2016-1879 EXPLOITDB HIGH python
FreeBSD <9.3p33, 10.1p26, 10.2p9 - DoS
The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer dereference and kernel panic) via a crafted ICMPv6 packet.
by ptsecurity
CVSS 7.5
CVE-2016-20037 EXPLOITDB HIGH python
xwpe 1.5.30a-2.1 Stack-based Buffer Overflow
xwpe 1.5.30a-2.1 and prior contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying overly long input strings that exceed buffer boundaries. Attackers can craft malicious command-line arguments with 262 bytes of junk data followed by shellcode to overwrite the instruction pointer and achieve code execution or denial of service.
by Juan Sacco
CVSS 8.4
CVE-2006-2961 EXPLOITDB python VERIFIED
CesarFTP <0.99g - Buffer Overflow
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MKD command. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Irving Aguilar
CVE-2016-20050 EXPLOITDB MEDIUM python VERIFIED
NetSchedScan 1.0 Buffer Overflow Denial of Service
NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a crafted payload containing 388 bytes of data followed by 4 bytes of EIP overwrite into the Hostname/IP field to trigger a denial of service condition.
by Abraham Espinosa
CVSS 6.2
EIP-2026-102370 EXPLOITDB python VERIFIED
GlassFish Server - Arbitrary File Read
by bingbing
EIP-2026-112006 EXPLOITDB python
SevOne NMS 5.3.6.0 - Remote Command Execution
by @iamsecurity
EIP-2026-104317 EXPLOITDB python
Manage Engine Application Manager 12.5 - Arbitrary Command Execution
by Bikramaditya Guha
CVE-2015-8261 EXPLOITDB CRITICAL python
Ipswitch WhatsUp Gold <16.4 - SQL Injection
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.
by Matt Buzanowski
CVSS 9.8
EIP-2026-116259 EXPLOITDB python VERIFIED
SNScan 1.05 - Scan Hostname/IP Field Buffer Overflow Crash (PoC)
by Daniel Velazquez
CVE-2015-7768 EXPLOITDB python VERIFIED
Konica Minolta FTP Utility 1.0 - RCE
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command.
by TOMIWA
EIP-2026-115515 EXPLOITDB python
KeePass Password Safe Classic 1.29 - Crash (PoC)
by Mohammad Reza Espargham
CVE-2016-1909 EXPLOITDB CRITICAL python
Fortinet <5.0.12 - Hardcoded Passphrase
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.
by operator8203
CVSS 9.8
CVE-2014-6287 EXPLOITDB CRITICAL python VERIFIED
Rejetto HTTP File Server <2.3c - RCE
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
by Avinash Thapa
CVSS 9.8
EIP-2026-117215 EXPLOITDB python VERIFIED
FTPShell Client 5.24 - 'Add to Favorites' Buffer Overflow
by INSECT.B
EIP-2026-117217 EXPLOITDB python
FTPShell Client 5.24 - Local Buffer Overflow
by hyp3rlinx
CVE-2015-7874 EXPLOITDB CRITICAL python
KiTTY Portable <0.65.0.2p - RCE
Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname.
by Guillaume Kaddouch
CVSS 9.8
EIP-2026-117389 EXPLOITDB python
KiTTY Portable 0.65.1.1p - Local Saved Session Overflow (Egghunter XP / Denial of Service 7/8.1/10)
by Guillaume Kaddouch
EIP-2026-117388 EXPLOITDB python VERIFIED
KiTTY Portable 0.65.0.2p (Windows 8.1/10) - Local kitty.ini Overflow
by Guillaume Kaddouch
EIP-2026-117387 EXPLOITDB python VERIFIED
KiTTY Portable 0.65.0.2p (Windows 7) - Local kitty.ini Overflow (Wow64 Egghunter)
by Guillaume Kaddouch
CVE-2025-34119 EXPLOITDB HIGH python VERIFIED
EasyCafe Server <2.2.14 - Info Disclosure
A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. If the file exists and is accessible, its content is returned without authentication. This flaw allows attackers to retrieve sensitive files such as system configuration, password files, or application data.
by R-73eN