Exploitdb Exploits

4,759 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-16671 EXPLOITDB MEDIUM python
CIRCONTROL CirCarLife <4.3 - Info Disclosure
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.
by SadFud
CVSS 5.3
CVE-2018-16670 EXPLOITDB MEDIUM python
CIRCONTROL CirCarLife <4.3 - Info Disclosure
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
by SadFud
CVSS 5.3
CVE-2018-16669 EXPLOITDB CRITICAL python
CIRCONTROL OCPP <1.5.0 - Info Disclosure
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.
by SadFud
CVSS 9.8
CVE-2018-16668 EXPLOITDB MEDIUM python
CIRCONTROL CirCarLife <4.3 - Info Disclosure
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.
by SadFud
CVSS 5.3
EIP-2026-116048 EXPLOITDB python VERIFIED
PDF Explorer 1.5.66.2 - Denial of Service (PoC)
by Gionathan Reale
CVE-2018-4240 EXPLOITDB MEDIUM python
iPhone OS < 11.4, macOS < 10.13.5, tvOS < 11.4, watchOS < 4.3.1 - Denial of Service via Crafted Message
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service via a crafted message.
by Sriram
CVSS 6.5
CVE-2018-16946 EXPLOITDB HIGH python
LG Smart Network Camera Firmware 1310250-1508190 - Unauthenticated Sensitive Information Exposure
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.
by Ege Balci
CVSS 7.5
CVE-2018-12634 EXPLOITDB CRITICAL python
CirCarLife Scada <4.3 - Info Disclosure
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.
by SadFud
CVSS 9.8
EIP-2026-119635 EXPLOITDB python
InTouch Machine Edition 8.1 SP1 - 'Nombre del Tag' Buffer Overflow (SEH)
by Luis Martínez
EIP-2026-119473 EXPLOITDB python
HTML5 Video Player 1.2.5 - Denial of Service (PoC)
by T3jv1l
CVE-2018-25377 EXPLOITDB HIGH python
Flash Slideshow Maker Professional 5.20 Buffer Overflow SEH
Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog to trigger a reverse shell with system privileges.
by Shubham Singh
CVSS 8.4
CVE-2018-25376 EXPLOITDB HIGH python
Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH
Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft malicious input in the Registration Name and Registration Key fields to overwrite the SEH chain and execute shellcode for reverse shell access.
by Shubham Singh
CVSS 8.4
CVE-2018-25375 EXPLOITDB HIGH python
SocuSoft iPod Photo Slideshow 8.05 Buffer Overflow SEH
SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft malicious input in the Registration Name and Registration Key fields to trigger a stack-based buffer overflow and execute a reverse shell payload.
by Shubham Singh
CVSS 8.4
CVE-2018-16752 EXPLOITDB HIGH python
LINK-NET LW-N605R Firmware 12.20.2.1486 - Authenticated Remote Code Execution via Ping HOST Field
LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.
by Nassim Asrir
CVSS 8.8
EIP-2026-119550 EXPLOITDB python
Photo To Video Converter Professional 8.07 - Buffer Overflow (SEH)
by Shubham Singh
EIP-2026-119457 EXPLOITDB python
Any Sound Recorder 2.93 - Denial of Service (PoC)
by T3jv1l
CVE-2018-25373 EXPLOITDB HIGH python
DVD Photo Slideshow Professional 8.07 Buffer Overflow SEH
SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious text file with carefully constructed payload containing junk bytes, SEH chain overwrite, and shellcode, then paste the contents into the Registration Name field via Help > Register to trigger code execution.
by T3jv1l
CVSS 8.4
CVE-2018-25283 EXPLOITDB HIGH python
iSmartViewPro 1.5 Buffer Overflow via SavePath Parameter
iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary code. Attackers can input a crafted payload exceeding 260 bytes through the System Setup interface to overwrite SEH records and execute shellcode with application privileges.
by Gionathan Reale
CVSS 8.4
CVE-2014-0030 EXPLOITDB CRITICAL python
Apache Roller - XML External Entity Injection
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
by Marko Jokic
CVSS 9.8
CVE-2018-16709 EXPLOITDB CRITICAL python
Fuji Xerox Devices - Info Disclosure
Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V C5576, DocuCentre-IV C2263, DocuCentre-V C2263, and ApeosPort-V 5070 devices allow remote attackers to read or write to files via crafted PJL commands.
by vr_system
CVSS 9.8
EIP-2026-119534 EXPLOITDB python
iSmartViewPro 1.5 - 'DDNS' Buffer Overflow
by Luis Martínez
EIP-2026-119533 EXPLOITDB python
iSmartViewPro 1.5 - 'DDNS' Buffer Overflow
by Luis Martínez
EIP-2026-103318 EXPLOITDB python
RPi Cam Control < 6.4.25 - 'preview.php' Remote Command Execution
by Reigning Shells
CVE-2018-25369 EXPLOITDB MEDIUM python VERIFIED
Visual Ping 0.8.0.0 Buffer Overflow Denial of Service
Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to crash the application by supplying oversized data. Attackers can inject malicious payloads exceeding 4108 bytes into the Host, Time Out, Packet Size, Pause, or Loops fields to trigger a denial of service condition.
by Uriel Corral Salinas
CVSS 6.2
CVE-2018-25246 EXPLOITDB HIGH python VERIFIED
Wikipedia 12.0 Denial of Service via Search
Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated characters into the search bar to trigger an application crash.
by 0xB9
CVSS 7.5