Exploitdb Exploits

4,724 exploits tracked across all sources.

Sort: Activity Stars
CVE-2021-26236 EXPLOITDB HIGH python
Faststone Image Viewer < 7.5 - Out-of-Bounds Write
FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handler (SEH). Attackers could exploit this issue to achieve code execution when a user opens or views a malformed/specially crafted CUR file.
by Paolo Stagno
CVSS 7.8
CVE-2021-47877 EXPLOITDB HIGH python
GeoGebra Graphing Calculator <6.0.631.0 - DoS
GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer. Attackers can generate a payload of 8000 repeated characters to overwhelm the input field and cause the application to become unresponsive.
by Brian Rodriguez
CVSS 7.5
CVE-2021-47876 EXPLOITDB HIGH python
GeoGebra Classic <5.0.631.0-d - DoS
GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability in the input field that allows attackers to crash the application by sending oversized buffer content. Attackers can generate a large buffer of 800,000 repeated characters and paste it into the 'Entrada:' input field to trigger an application crash.
by Brian Rodriguez
CVSS 7.5
CVE-2021-47875 EXPLOITDB CRITICAL python
GeoGebra CAS Calculator <6.0.631.0 - DoS
GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a payload with 8000 repeated characters and paste it into the calculator's input field to trigger an application crash.
by Brian Rodriguez
CVSS 9.8
EIP-2026-105119 EXPLOITDB python
Alphaware E-Commerce System 1.0 - Unauthenicated Remote Code Execution (File Upload + SQL injection)
by Christian Vierschilling
EIP-2026-104446 EXPLOITDB python VERIFIED
Sonlogger 4.2.3.3 - SuperAdmin Account Creation / Information Disclosure
by Berkan Er
CVE-2021-26855 EXPLOITDB CRITICAL python
Microsoft Exchange ProxyLogon RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
by F5
CVSS 9.1
EIP-2026-109557 EXPLOITDB python
Monitoring System (Dashboard) 1.0 - File Upload RCE (Authenticated)
by Richard Jones
CVE-2021-27722 EXPLOITDB HIGH python
Nsasoft US LLC SpotAuditor <5.3.5 - Buffer Overflow
An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering.
by Enes Özeser
CVSS 7.5
CVE-2021-27065 EXPLOITDB HIGH python
Microsoft Exchange Server - Path Traversal
Microsoft Exchange Server Remote Code Execution Vulnerability
by testanull
CVSS 7.8
CVE-2020-14181 EXPLOITDB MEDIUM python
Atlassian Data Center < 7.13.6 - Information Disclosure
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.
by Dolev Farhi
CVSS 5.3
CVE-2006-6576 EXPLOITDB python VERIFIED
Golden FTP Server <1.92 - Buffer Overflow
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.
by 1F98D
EIP-2026-107645 EXPLOITDB python
Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated)
by Christian Vierschilling
CVE-2021-47888 EXPLOITDB HIGH python
Textpattern <4.8.3 - Authenticated RCE
Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL parameter.
by Ricardo Ruiz
CVSS 8.8
CVE-2020-13160 EXPLOITDB CRITICAL python VERIFIED
AnyDesk <5.5.3 - RCE
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
by scryh
CVSS 9.8
CVE-2020-25787 EXPLOITDB CRITICAL python
Tt-rss Tiny Tiny Rss < 2020-09-16 - Improper Input Validation
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
by Daniel Neagaru
CVSS 9.8
CVE-2022-3218 EXPLOITDB CRITICAL python VERIFIED
WiFi Mouse - RCE
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.
by H4rk3nz0
CVSS 9.8
EIP-2026-110066 EXPLOITDB python
Online Catering Reservation System 1.0 - Remote Code Execution (Unauthenticated)
by Christian Vierschilling
EIP-2026-106196 EXPLOITDB python
Covid-19 Contact Tracing System 1.0 - Remote Code Execution (Unauthenticated)
by Christian Vierschilling
CVE-2021-21972 EXPLOITDB CRITICAL python
Vmware Cloud Foundation < 3.10.1.2 - Path Traversal
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
by Photubias
CVSS 9.8
EIP-2026-119088 EXPLOITDB python
Remote Desktop Web Access - Authentication Timing Attack (Metasploit Module)
by Matthew Dunn
EIP-2026-118284 EXPLOITDB python
ASUS Remote Link 1.1.2.13 - Remote Code Execution
by H4rk3nz0
CVE-2021-47891 EXPLOITDB CRITICAL python VERIFIED
Unified Remote 3.9.0.2463 - RCE
Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending specially crafted packets to open a command prompt and download and execute malicious payloads.
by H4rk3nz0
CVSS 9.8
CVE-2021-27722 EXPLOITDB HIGH python VERIFIED
Nsasoft US LLC SpotAuditor <5.3.5 - Buffer Overflow
An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering.
by Sinem Şahin
CVSS 7.5
EIP-2026-116303 EXPLOITDB python VERIFIED
SpotAuditor 5.3.5 - 'multiple' Denial Of Service (PoC)
by Sinem Şahin