Python Exploits

5,951 exploits tracked across all sources.

Sort: Activity Stars
CVE-2013-0230 EXPLOITDB python
Miniupnpd - Memory Corruption
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
by Onur Alanbel (BGA)
EIP-2026-103964 EXPLOITDB python VERIFIED
Legend Perl IRC Bot - Remote Code Execution
by Jay Turla
EIP-2026-103751 EXPLOITDB python VERIFIED
Wireshark 1.12.4 - Memory Corruption and Access Violation (PoC)
by Avinash Thapa
CVE-2011-5165 EXPLOITDB python VERIFIED
Cleanersoft Free Mp3 CD Ripper < 2.6 - Memory Corruption
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file.
by naxxo
CVE-2015-3306 EXPLOITDB python
ProFTPD 1.3.5 - RCE
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
by R-73eN
CVE-2015-1635 EXPLOITDB CRITICAL python
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
by laurent gaffie
CVSS 9.8
CVE-2015-0240 EXPLOITDB python
Samba _netr_ServerPasswordSet Uninitialized Credential State
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
by sleepya
CVE-2015-1130 EXPLOITDB HIGH python VERIFIED
Apple OS X Rootpipe Privilege Escalation
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
by Emil Kvarnhammar
CVSS 7.8
EIP-2026-104124 EXPLOITDB python VERIFIED
w3tw0rk / Pitbull Perl IRC Bot - Remote Code Execution
by Jay Turla
EIP-2026-104289 EXPLOITDB python
JBoss AS 3/4/5/6 - Remote Command Execution
by João Filho Matos Figueiredo
CVE-2015-2797 EXPLOITDB python
Airties Air Firmware < 1.0.2.0 - Memory Corruption
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the redirect parameter to cgi-bin/login.
by Batuhan Burakcin
EIP-2026-117311 EXPLOITDB python
IDM 6.20 - Local Buffer Overflow
by TUNISIAN CYBER
CVE-2014-6332 EXPLOITDB HIGH python VERIFIED
Microsoft Windows - RCE
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
by Naser Farhadi
CVSS 8.8
CVE-2009-1646 EXPLOITDB python
Mini-stream RM Downloader - Memory Corruption
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file.
by TUNISIAN CYBER
EIP-2026-117605 EXPLOITDB python VERIFIED
Mini-stream Ripper 2.7.7.100 - Local Buffer Overflow
by TUNISIAN CYBER
CVE-2014-9013 EXPLOITDB HIGH python
WP Marketplace <2.4.0 - Privilege Escalation
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
by Claudio Viviani
CVSS 8.8
CVE-2014-9014 EXPLOITDB MEDIUM python
WP Marketplace <2.4.1 - Path Traversal
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.
by Claudio Viviani
CVSS 4.3
EIP-2026-118333 EXPLOITDB python VERIFIED
Bsplayer 2.68 - HTTP Response Universal
by Fady Mohammed Osman
CVE-2011-5165 EXPLOITDB python VERIFIED
Cleanersoft Free Mp3 CD Ripper < 2.6 - Memory Corruption
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file.
by TUNISIAN CYBER
EIP-2026-102568 EXPLOITDB python VERIFIED
Brasero CD/DVD Burner 3.4.1 - '.m3u' Buffer Overflow Crash (PoC)
by Avinash Thapa
CVE-2015-1427 EXPLOITDB CRITICAL python VERIFIED
Elasticsearch <1.3.8, <1.4.3 - Command Injection
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
by Xiphos Research Ltd
CVSS 9.8
EIP-2026-101073 EXPLOITDB python
Sagem F@st 3304-V2 - Telnet Crash (PoC)
by Loudiyi Mohamed
CVE-2014-8687 EXPLOITDB CRITICAL python VERIFIED
Seagate Business NAS <2015.00322 - RCE
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.
by OJ Reeves
CVSS 9.8
EIP-2026-117590 EXPLOITDB python VERIFIED
Microsoft Word 2007 - RTF Object Confusion (ASLR + DEP Bypass)
by R-73eN
EIP-2026-107447 EXPLOITDB python
GoAutoDial CE 2.0 - Arbitrary File Upload
by R-73eN