Python Exploits

5,949 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-101488 EXPLOITDB python
Ubiquiti AirOS 5.5.2 - (Authenticated) Remote Command Execution
by xistence
CVE-2012-5967 EXPLOITDB python
Merethis Centreon - SQL Injection
SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execute arbitrary SQL commands via the menu parameter.
by modpr0be
CVE-2012-5375 EXPLOITDB python VERIFIED
Linux kernel <3.8-rc1 - DoS
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (prevention of file creation) by leveraging the ability to write to a directory important to the victim, and creating a file with a crafted name that is associated with a specific CRC32C hash value.
by Pascal Junod
CVE-2012-4959 EXPLOITDB python VERIFIED
Novell File Reporter <1.0.2 - Path Traversal
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
by Abysssec
EIP-2026-115304 EXPLOITDB python VERIFIED
FreeVimager 4.1.0 - Crash (PoC)
by Jean Pascal Pereira
EIP-2026-115146 EXPLOITDB python VERIFIED
DIMIN Viewer 5.4.0 - Crash (PoC)
by Jean Pascal Pereira
CVE-2012-10023 EXPLOITDB CRITICAL python VERIFIED
FreeFloat FTP Server 1.0.0 - Buffer Overflow
A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The flaw is triggered by sending an overly long username string, which overflows the buffer allocated for user authentication.
by D35m0nd142
CVSS 9.8
CVE-2013-1627 EXPLOITDB python VERIFIED
Advantech Studio - Path Traversal
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function.
by Nin3
EIP-2026-116457 EXPLOITDB python VERIFIED
UMPlayer Portable 0.95 - Crash (PoC)
by p3kok
CVE-2012-6608 EXPLOITDB python VERIFIED
Elastix - XSS
Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the Page parameter.
by cheki
CVE-2012-10031 EXPLOITDB HIGH python VERIFIED
BlazeVideo HDTV Player Pro v6.6.0.3 - Buffer Overflow
BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supplied input embedded in .plf playlist files. When parsing a crafted .plf file, the MediaPlayerCtrl.dll component invokes PathFindFileNameA() to extract a filename from a URL-like string. The returned value is then copied to a fixed-size stack buffer using an inline strcpy call without bounds checking. If the input exceeds the buffer size, this leads to a stack overflow and potential arbitrary code execution under the context of the user.
by Nezim
EIP-2026-116860 EXPLOITDB python VERIFIED
Aviosoft Digital TV Player Professional 1.x - '.PLF' Direct Retn
by Nezim
CVE-2012-4409 EXPLOITDB python VERIFIED
Mcrypt < 2.6.8 - Memory Corruption
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted file with a crafted header containing long salt data that is not properly handled during decryption.
by _ishikawa
CVE-2012-0698 EXPLOITDB python
TrouSerS <0.3.10 - DoS
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.
by Andy Lutomirski
EIP-2026-102210 EXPLOITDB python VERIFIED
Twitter for iPhone - Man in the Middle Security
by Carlos Reventlov
EIP-2026-117175 EXPLOITDB python
FormatFactory 3.0.1 - Profile File Handling Buffer Overflow
by Julien Ahrens
CVE-2012-2619 EXPLOITDB python
BCM4325/9 - DoS
The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung, and Sony products, allow remote attackers to cause a denial of service (out-of-bounds read and Wi-Fi outage) via an RSN 802.11i information element.
by CoreLabs
CVE-2012-4960 EXPLOITDB python VERIFIED
Huawei Various - Path Traversal
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500, Eudemon1000, Eudemon1000E-U/USG5300, Eudemon1000E-X/USG5500, Eudemon8080E/USG9300, Eudemon8160E/USG9300, Eudemon8000E-X/USG9500, E200E-C/USG2200, E200E-X3/USG2200, E200E-X5/USG2200, E200E-X7/USG2200, E200E-C/USG5100, E200E-X3/USG5100, E200E-X5/USG5100, E200E-X7/USG5100, E200E-B/USG2100, E200E-X1/USG2100, E200E-X2/USG2100, SVN5300, SVN2000, SVN5000, SVN3000, NIP100, NIP200, NIP1000, NIP2100, NIP2200, and NIP5100 use the DES algorithm for stored passwords, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
by Roberto Paleari
EIP-2026-118208 EXPLOITDB python VERIFIED
Zoner Photo Studio 15 Build 3 - 'Zps.exe' Registry Value Parsing
by Julien Ahrens
EIP-2026-116245 EXPLOITDB python VERIFIED
Smadav Anti Virus 9.1 - Crash (PoC)
by Mada R Perdhana
EIP-2026-113024 EXPLOITDB python VERIFIED
vBulletin vBay 1.1.9 - Error-Based SQL Injection
by Dan UK
EIP-2026-118319 EXPLOITDB python
BigAnt Server 2.52 SP5 - Remote Stack Overflow ROP-Based (SEH) (ASLR + DEP Bypass)
by Lorenzo Cantoni
CVE-2012-5106 EXPLOITDB python VERIFIED
FreeFloat FTP Server 1.0 - Buffer Overflow
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command.
by Jacob Holcomb
EIP-2026-104327 EXPLOITDB python VERIFIED
ManageEngine Security Manager Plus 5.5 build 5505 - Directory Traversal
by xistence
EIP-2026-103978 EXPLOITDB python VERIFIED
ManageEngine Security Manager Plus 5.5 build 5505 - Remote Root/SYSTEM SQL Injection
by xistence