Python Exploits

6,597 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-12132 GITHUB MEDIUM python
WP Job Portal < 2.2.4 - Authenticated Insecure Direct Object Reference via User-Controlled Key
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create jobs for companies that are unaffiliated with the attacker.
by certuscyber
3 stars
CVSS 4.3
CVE-2024-12131 GITHUB MEDIUM python
WP Job Portal < 2.2.5 - Authenticated Insecure Direct Object Reference via User-Controlled Key
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit resumes for other applicants when applying for jobs.
by certuscyber
3 stars
CVSS 4.3
CVE-2024-11270 GITHUB HIGH python
WebinarPress < 1.33.24 - Authenticated Arbitrary File Creation via sync-import-imgs Function
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files that can lead to remote code execution.
by certuscyber
3 stars
CVSS 8.8
CVE-2023-47873 GITHUB CRITICAL python
WEN Solutions WP Child Theme Generator <= 1.0.9 - Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.
by certuscyber
3 stars
CVSS 9.1
CVE-2023-4490 GITHUB CRITICAL python
WP Job Portal < 2.0.6 - Unauthenticated SQL Injection
The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
by certuscyber
3 stars
CVSS 9.8
CVE-2023-3460 GITHUB CRITICAL python
Ultimate Member <2.6.7 - Privilege Escalation
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.
by certuscyber
3 stars
CVSS 9.8
CVE-2023-1425 GITHUB HIGH python
WordPress CRM <2.7.9.4 - SQL Injection
The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins
by certuscyber
3 stars
CVSS 7.2
CVE-2022-29434 GITHUB MEDIUM python
Spiffy Calendar <= 4.9.0 - Insecure Direct Object Reference in Event Editing
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.
by certuscyber
3 stars
CVSS 6.3
CVE-2020-29045 GITHUB CRITICAL python
Five Star Restaurant Menu < 2.2.0 - Remote Code Execution via Unserialize in fdm_cart Cookie
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
by certuscyber
3 stars
CVSS 9.8
CVE-2014-5185 GITHUB python
quartz_plugin 1.01.1 - Authenticated SQL Injection via Quote Parameter
SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor privileges to execute arbitrary SQL commands via the quote parameter in an edit action in the quartz/quote_form.php page to wp-admin/edit.php.
by certuscyber
3 stars
CVE-2014-5182 GITHUB python
yawpp 1.2 - Authenticated SQL Injection via id Parameter
Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin.php.
by certuscyber
3 stars
CVE-2025-24054 EXPLOITDB MEDIUM python
Windows 10 1507-22H2 and Windows 11 22H2 - Unauthenticated Spoofing via NTLM File Path Control
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
by beatrizfn
CVSS 6.5
CVE-2025-32023 EXPLOITDB HIGH python
Redis 2.8.0-6.2.18 - Authenticated Remote Code Execution via HyperLogLog String Parsing
Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. The bug likely affects all Redis versions with hyperloglog operations implemented. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing hyperloglog operations. This can be done using ACL to restrict HLL commands.
by Beatriz Fresno Naumova
CVSS 7.0
CVE-2025-67779 GITHUB HIGH python
React Server Components 19.0.2, 19.1.3, 19.2.2 - Denial of Service via Unsafe Deserialization
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
by JSH-data
CVSS 7.5
CVE-2025-10370 EXPLOITDB LOW python
sourcefabric rpi-jukebox-rfid < 2.8.0 - Cross-Site Scripting via Custom Script Parameter
A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
by Beatriz Fresno Naumova
CVSS 3.5
CVE-2025-10666 EXPLOITDB HIGH python
D-Link DIR-825 Firmware < 2.10 - Buffer Overflow via apply.cgi countdown_time Argument
A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This vulnerability only affects products that are no longer supported by the maintainer.
by Beatriz Fresno Naumova
CVSS 8.8
CVE-2026-7731 GITHUB MEDIUM python
code-projects BloodBank Managing System get_state.php sql injection
A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file get_state.php. The manipulation of the argument G_STATE_ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
by SimoesCTT
CVSS 6.3
CVE-2026-24061 GITHUB CRITICAL python
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
by ridpath
1 stars
CVSS 9.8
CVE-2026-23626 GITHUB MEDIUM python
Kimai < 2.46.0 - Authenticated Information Disclosure via Twig Template Injection
Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`DefaultPolicy`) that allows arbitrary method calls on objects available in the template context. An authenticated user with export permissions can deploy a malicious Twig template that extracts sensitive information including environment variables, all user password hashes, serialized session tokens, and CSRF tokens. Version 2.46.0 patches this issue.
by HUSEYNKHANLI
1 stars
CVSS 6.8
CVE-2026-21881 GITHUB CRITICAL python
Kanboard < 1.2.49 - Unauthenticated Authentication Bypass via Spoofed HTTP Header
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a trusted reverse proxy. An attacker can impersonate any user, including administrators, by simply sending a spoofed HTTP header. This issue is fixed in version 1.2.49.
by HUSEYNKHANLI
1 stars
CVSS 9.1
CVE-2026-21880 GITHUB MEDIUM python
kanboard < 1.2.49 - LDAP Injection in Authentication Mechanism
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific accounts. This issue is fixed in version 1.2.49.
by HUSEYNKHANLI
1 stars
CVSS 5.3
CVE-2026-21879 GITHUB MEDIUM python
kanboard < 1.2.49 - Open Redirect via URL Validation Bypass
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs such as //evil.com, attackers can bypass the filter_var($url, FILTER_VALIDATE_URL) validation check. This vulnerability could be exploited to conduct phishing attacks, steal user credentials, or distribute malware. The issue is fixed in version 1.2.49.
by HUSEYNKHANLI
1 stars
CVSS 4.7
CVE-2026-22794 GITHUB CRITICAL python
Appsmith < 1.93 - Origin Validation Error in Email Link Generation
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.
by exploitChains
2 stars
CVSS 9.6
CVE-2026-21858 GITHUB CRITICAL python
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.
by exploitChains
2 stars
CVSS 10.0
CVE-2025-64155 GITHUB CRITICAL python
FortiSIEM 6.7.0-6.7.10, 7.0.0-7.0.4, 7.1.0-7.1.8, 7.3.0-7.3.4, 7.4.0 - OS Command Injection via TCP Requests
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
by exploitChains
2 stars
CVSS 9.8