Python Exploits

5,951 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105068 EXPLOITDB python
ALCASAR 2.8.1 - Remote Code Execution
by eF
EIP-2026-108868 EXPLOITDB python
Joomla! Component Spider Contacts 1.3.6 - 'contacts_id' SQL Injection
by Claudio Viviani
EIP-2026-103058 EXPLOITDB python
ALCASAR 2.8 - Remote Code Execution
by eF
EIP-2026-108864 EXPLOITDB python
Joomla! Component Spider Calendar 3.2.6 - SQL Injection
by Claudio Viviani
CVE-2014-2973 EXPLOITDB python VERIFIED
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-5753. Reason: This candidate is a duplicate of CVE-2008-5753. Notes: All CVE users should reference CVE-2008-5753 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
by Robert Kugler
EIP-2026-117410 EXPLOITDB python VERIFIED
LeapFTP 3.1.0 - URL Handling Buffer Overflow (SEH)
by k3170makan
EIP-2026-117288 EXPLOITDB python VERIFIED
HTML Help Workshop 1.4 - Local Buffer Overflow (SEH)
by mr.pr0n
EIP-2026-115399 EXPLOITDB python VERIFIED
HTML Help Workshop 1.4 - Buffer Overflow (SEH) (PoC)
by Moroccan Kingdom (MKD)
CVE-2014-2913 EXPLOITDB python
Nagios Remote Plugin Executor <2.15 - RCE
Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments
by Claudio Viviani
CVE-2014-5520 EXPLOITDB python
Xrms Crm - SQL Injection
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php.
by Benjamin Harris
CVE-2014-5521 EXPLOITDB python
Xrms Crm - SQL Injection
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.
by Benjamin Harris
CVE-2014-2223 EXPLOITDB python
Plogger <1.0 RC1 - RCE
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in plog-content/uploads/archive/.
by b0z
CVE-2014-5519 EXPLOITDB python
Phpwiki - Code Injection
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.
by Benjamin Harris
EIP-2026-104927 EXPLOITDB python
ActualAnalyzer Lite 2.81 - Command Execution
by Benjamin Harris
EIP-2026-116904 EXPLOITDB python VERIFIED
BlazeDVD Pro Player 7.0 - '.plf' Local Buffer Overflow (SEH)
by metacom
EIP-2026-116903 EXPLOITDB python VERIFIED
BlazeDVD Pro Player 7.0 - '.plf' Direct RET Local Stack Buffer Overflow
by Giovanni Bartolomucci
CVE-2014-3434 EXPLOITDB python VERIFIED
Symantec Endpoint Protection - Memory Corruption
Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL call.
by ryujin & sickness
EIP-2026-112202 EXPLOITDB python
SkaDate Lite 2.0 - Remote Code Execution
by LiquidWorm
EIP-2026-104746 EXPLOITDB python
Oxwall 1.7.0 - Remote Code Execution
by LiquidWorm
CVE-2014-9096 EXPLOITDB python
Pligg CMS <2.0.1 - SQL Injection
Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter.
by BlackHawk
CVE-2014-2973 EXPLOITDB python VERIFIED
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-5753. Reason: This candidate is a duplicate of CVE-2008-5753. Notes: All CVE users should reference CVE-2008-5753 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
by Gabor Seljan
EIP-2026-104744 EXPLOITDB python VERIFIED
Omeka 2.2.1 - Remote Code Execution
by LiquidWorm
EIP-2026-115156 EXPLOITDB python
DjVuLibre 3.5.25.3 - Out of Bounds Access Violation
by drone
CVE-2014-4971 EXPLOITDB python
Microsoft Windows XP SP3 - Privilege Escalation
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.
by KoreLogic
EIP-2026-101851 EXPLOITDB python
MTS MBlaze Ultra Wi-Fi / ZTE AC3633 - Multiple Vulnerabilities
by Ajin Abraham