Exploitdb Exploits

4,759 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-25240 EXPLOITDB MEDIUM python
Watchr 1.1.0.0 Denial of Service via Search
Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 8145 characters into the search bar and trigger a search operation to cause the application to crash.
by 0xB9
CVSS 6.2
CVE-2019-6110 EXPLOITDB MEDIUM python
OpenSSH < 7.9 - Terminal Output Manipulation via ANSI Control Codes
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
by Mark E. Haase
CVSS 6.8
CVE-2019-6111 EXPLOITDB MEDIUM python
OpenSSH < 7.9 - Arbitrary File Write via Malicious SCP Server
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
by Mark E. Haase
CVSS 5.9
EIP-2026-116314 EXPLOITDB python
Spotify 1.0.96.181 - 'Proxy configuration' Denial of Service (PoC)
by Aaron V. Hernandez
CVE-2018-9206 EXPLOITDB CRITICAL python
Blueimp jQuery-File-Upload <=9.22.0 - File Upload
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
by Larry W. Cashdollar
CVSS 9.8
CVE-2019-6444 EXPLOITDB CRITICAL python VERIFIED
ntpsec < 1.1.3 - Stack-based Buffer Over-read via process_control
An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.
by Magnus Klaaborg Stubman
CVSS 9.1
CVE-2019-6445 EXPLOITDB MEDIUM python VERIFIED
ntpsec < 1.1.3 - Authenticated Denial of Service via NULL Pointer Dereference in ntp_control.c
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.
by Magnus Klaaborg Stubman
CVSS 6.5
CVE-2019-6443 EXPLOITDB CRITICAL python VERIFIED
ntpsec < 1.1.3 - Stack-based Buffer Over-read in ntp_control.c
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.
by Magnus Klaaborg Stubman
CVSS 9.1
CVE-2019-6442 EXPLOITDB MEDIUM python VERIFIED
ntpsec < 1.1.3 - Authenticated Out-of-bounds Write via Malformed Config Request
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.
by Magnus Klaaborg Stubman
CVSS 6.5
CVE-2018-13374 EXPLOITDB MEDIUM python VERIFIED
FortiOS < 6.0.3 and FortiADC 5.4.0-5.4.4 - LDAP Server Credential Exposure via Connectivity Test Request
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
by Julio Ureña
CVSS 4.3
CVE-2019-25137 EXPLOITDB HIGH python
Umbraco CMS <7.15.10 - Authenticated RCE
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.
by Gregory Draperi
CVSS 7.2
EIP-2026-107616 EXPLOITDB python
Horde Imp - 'imap_open' Remote Command Execution
by Paolo Serracino_ Pietro Minniti_ Damiano Proietti
EIP-2026-101828 EXPLOITDB python
Lenovo R2105 - Cross-Site Request Forgery (Command Execution)
by Nathu Nandwani
CVE-2019-25625 EXPLOITDB MEDIUM python
Blob Studio 2.17 Denial of Service via Malformed Input
Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of repeated characters and trigger the application to read it, causing the application to crash or become unresponsive.
by Ihsan Sencan
CVSS 6.2
CVE-2019-25624 EXPLOITDB MEDIUM python
Liquid Studio 2.17 Denial of Service via Malformed Input
Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.
by Ihsan Sencan
CVSS 6.2
CVE-2019-25623 EXPLOITDB MEDIUM python
Luminance Studio 2.17 Denial of Service via Malformed Input
Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to process the input, causing the application to become unresponsive or terminate abnormally.
by Ihsan Sencan
CVSS 6.2
CVE-2019-25622 EXPLOITDB MEDIUM python
Paint Studio 2.17 Denial of Service via Malformed Input
Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of characters and trigger the application to read it, causing the application to crash and become unavailable.
by Ihsan Sencan
CVSS 6.2
CVE-2019-25621 EXPLOITDB MEDIUM python
Pixel Studio 2.17 Denial of Service via Malformed Input
Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters, causing the application to become unresponsive or terminate abnormally.
by Ihsan Sencan
CVSS 6.2
CVE-2019-25620 EXPLOITDB MEDIUM python
Tree Studio 2.17 Denial of Service via Malformed Input
Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.
by Ihsan Sencan
CVSS 6.2
EIP-2026-116976 EXPLOITDB python
Code Blocks 17.12 - Local Buffer Overflow (SEH) (Unicode)
by bzyo
EIP-2026-116975 EXPLOITDB python
Code Blocks 17.12 - Local Buffer Overflow (SEH) (Unicode)
by bzyo
EIP-2026-116232 EXPLOITDB python
Selfie Studio 2.17 - Denial of Service (PoC)
by Ihsan Sencan
EIP-2026-116231 EXPLOITDB python
Selfie Studio 2.17 - Denial of Service (PoC)
by Ihsan Sencan
CVE-2019-6111 EXPLOITDB MEDIUM python
OpenSSH < 7.9 - Arbitrary File Write via Malicious SCP Server
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
by Harry Sintonen
CVSS 5.9
CVE-2018-25258 EXPLOITDB HIGH python
RGui 3.5.0 Local Buffer Overflow SEH DEP Bypass
RGui 3.5.0 contains a local buffer overflow vulnerability in the GUI preferences dialog that allows attackers to bypass DEP protections through structured exception handling exploitation. Attackers can craft malicious input in the Language for menus and messages field to trigger a stack-based buffer overflow, execute a ROP chain for VirtualAlloc allocation, and achieve arbitrary code execution.
by bzyo
CVSS 8.4