Exploitdb Exploits

4,759 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-116513 EXPLOITDB python VERIFIED
VSAXESS V2.6.2.70 build 20171226_053 - 'Nickname' Denial of Service (PoC)
by Diego Santamaria
EIP-2026-115797 EXPLOITDB python VERIFIED
Microsoft Windows Explorer Out-of-Bound Read - Denial of Service (PoC)
by Ghaaf
EIP-2026-115796 EXPLOITDB python VERIFIED
Microsoft Windows Explorer Out-of-Bound Read - Denial of Service (PoC)
by Ghaaf
EIP-2026-102189 EXPLOITDB python
Trend Micro Virtual Mobile Infrastructure 5.5.1336 - 'Server address' Denial of Service (PoC)
by Luis Martínez
EIP-2026-102186 EXPLOITDB python
Symantec Mobile Encryption for iPhone 2.1.0 - 'Server' Denial of Service (PoC)
by Luis Martínez
EIP-2026-119572 EXPLOITDB python
Acunetix WVS Reporter 10.0 - Denial of Service (PoC)
by Ali Alipour
CVE-2018-25368 EXPLOITDB HIGH python
Nord VPN 6.14.31 Denial of Service via Password Field
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.
by L0RD
CVSS 7.5
CVE-2018-25235 EXPLOITDB MEDIUM python VERIFIED
NetworkActiv Web Server 4.0 Username Field Buffer Overflow DoS
NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding the expected buffer size through the Set username interface.
by Victor Mondragón
CVSS 6.2
CVE-2018-25367 EXPLOITDB MEDIUM python VERIFIED
NASA openVSP 3.16.1 Denial of Service via Buffer Overflow
NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition interface.
by L0RD
CVSS 6.2
CVE-2018-25287 EXPLOITDB MEDIUM python VERIFIED
Drive Power Manager 1.10 Denial of Service via Name Field
Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a 6000-byte payload into the Name field and click Register to trigger a denial of service condition.
by Gionathan Reale
CVSS 5.5
CVE-2018-25286 EXPLOITDB MEDIUM python VERIFIED
Easy PhotoResQ 1.0 Buffer Overflow Denial of Service
Easy PhotoResQ 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Folder/filename field. Attackers can input a 6000-byte payload through the File Options dialog to trigger a denial of service condition.
by Gionathan Reale
CVSS 6.2
CVE-2018-25285 EXPLOITDB MEDIUM python VERIFIED
Fathom 2.4 Denial of Service via Authorization Code Buffer Overflow
Fathom 2.4 contains a buffer overflow vulnerability in the Authorization Code field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 6000-byte payload into the Authorization Code field and click Activate to trigger a denial of service condition.
by Gionathan Reale
CVSS 5.5
CVE-2018-25284 EXPLOITDB MEDIUM python VERIFIED
HD Tune Pro 5.70 Denial of Service via Options Dialog
HD Tune Pro 5.70 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the folder/file name field. Attackers can trigger a denial of service by entering a 6000-byte payload through the File > Options > Save dialog's folder/file name input field.
by Gionathan Reale
CVSS 6.2
CVE-2018-25225 EXPLOITDB HIGH python
SIPP 3.3 Stack-Based Buffer Overflow via Configuration File
SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.
by Juan Sacco
CVSS 8.4
EIP-2026-119618 EXPLOITDB python VERIFIED
Trillian 6.1 Build 16 - 'Sign In' Denial of service (PoC)
by Jose Miguel Gonzalez
EIP-2026-119613 EXPLOITDB python
Skype Empresarial Office 365 16.0.10730.20053 - 'Dirección de inicio de sesión' Denial of service (PoC)
by Samuel Cruz
EIP-2026-119478 EXPLOITDB python VERIFIED
ipPulse 1.92 - 'TCP Port' Denial of Service (PoC)
by Diego Santamaria
EIP-2026-119474 EXPLOITDB python VERIFIED
Immunity Debugger 1.85 - Denial of Service (PoC)
by Gionathan Reale
EIP-2026-117820 EXPLOITDB python
R 3.4.4 - Buffer Overflow (SEH)
by ZwX
EIP-2026-117819 EXPLOITDB python
R 3.4.4 - Buffer Overflow (SEH)
by ZwX
EIP-2026-102158 EXPLOITDB python
Cisco AnyConnect Secure Mobility Client 4.6.01099 - 'Introducir URL' Denial of Service (PoC)
by Luis Martínez
EIP-2026-101717 EXPLOITDB python
Episerver 7 patch 4 - XML External Entity Injection
by Jonas Lejon
EIP-2026-119592 EXPLOITDB python
Instagram App 41.1788.50991.0 - Denial of Service (PoC)
by Ali Alipour
EIP-2026-115054 EXPLOITDB python
Cisco Network Assistant 6.3.3 - 'Cisco Login' Denial of Service (PoC)
by Luis Martínez
CVE-2018-25366 EXPLOITDB HIGH python
CuteFTP 5.0 XP Buffer Overflow via Site Manager Label Field
CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and launched.
by Matteo Malvica
CVSS 8.4