Exploitdb Exploits

2,689 exploits tracked across all sources.

Sort: Activity Stars
CVE-2016-4656 EXPLOITDB HIGH ruby VERIFIED
iPhone OS < 9.3.5 - Remote Code Execution via Memory Corruption
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
by Metasploit
CVSS 7.8
CVE-2016-4655 EXPLOITDB MEDIUM ruby VERIFIED
WebKit not_number defineProperties UAF
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
by Metasploit
CVSS 5.5
CVE-2016-4657 EXPLOITDB HIGH ruby VERIFIED
iPhone OS < 9.3.5 - Remote Code Execution via WebKit Memory Corruption
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
by Metasploit
CVSS 8.8
EIP-2026-117538 EXPLOITDB ruby VERIFIED
Microsoft Windows - UAC Protection Bypass (Via Slui File Handler Hijack) (Metasploit)
by Metasploit
EIP-2026-117537 EXPLOITDB ruby VERIFIED
Microsoft Windows - UAC Protection Bypass (Via Slui File Handler Hijack) (Metasploit)
by Metasploit
CVE-2016-20017 EXPLOITDB CRITICAL ruby VERIFIED
D-Link DSL-2750B <1.05 - Command Injection
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
by Metasploit
CVSS 9.8
CVE-2016-8655 EXPLOITDB HIGH ruby VERIFIED
AF_PACKET chocobo_root Privilege Escalation
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
by Metasploit
CVSS 7.8
CVE-2010-3904 EXPLOITDB HIGH ruby VERIFIED
Reliable Datagram Sockets (RDS) rds_page_copy_user Privilege Escalation
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
by Metasploit
CVSS 7.8
CVE-2017-12500 EXPLOITDB HIGH ruby
HPE Intelligent Management Center PLAT 7.3 (E0504) - Remote Code Execution
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
by TrendyTofu
CVSS 8.8
CVE-2017-8982 EXPLOITDB HIGH ruby
HPE Intelligent Management Center PLAT 7.3 E0504P4 - Remote Authentication Restriction Bypass
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
by TrendyTofu
CVSS 7.5
CVE-2017-7308 EXPLOITDB HIGH ruby VERIFIED
AF_PACKET packet_set_ring Privilege Escalation
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.
by Metasploit
CVSS 7.8
CVE-2017-9791 EXPLOITDB CRITICAL ruby VERIFIED
Apache Struts 2.1.x and 2.3.x - Remote Code Execution via ActionMessage Field Value
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
by Metasploit
CVSS 9.8
CVE-2016-9299 EXPLOITDB CRITICAL ruby VERIFIED
Jenkins < 2.32 and LTS < 2.19.3 - Remote Code Execution via LDAP Query Injection
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
by Metasploit
CVSS 9.8
CVE-2015-3245 EXPLOITDB ruby VERIFIED
libuser < 0.56.13-8 and 0.60 < 0.60-7 - Denial of Service via GECOS Field Newline Injection
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.
by Metasploit
CVE-2015-3246 EXPLOITDB ruby VERIFIED
libuser <0.56.13-8 & 0.60 <0.60-7 - DoS
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
by Metasploit
CVE-2008-4687 EXPLOITDB ruby VERIFIED
Mantis < 1.1.4 - Authenticated Remote Code Execution via Sort Parameter
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.
by Metasploit
CVE-2017-15944 EXPLOITDB CRITICAL ruby VERIFIED
Palo Alto Network PAN-OS - Remote Code Execution
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.
by Metasploit
CVSS 9.8
CVE-2017-9080 EXPLOITDB HIGH ruby VERIFIED
PlaySMS 1.4 - Remote Code Execution
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.
by Metasploit
CVSS 8.8
CVE-2017-9101 EXPLOITDB CRITICAL ruby VERIFIED
PlaySMS 1.4 - Remote Code Execution
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.
by Metasploit
CVSS 9.8
EIP-2026-114160 EXPLOITDB ruby
WordPress Plugin User Role Editor < 4.25 - Privilege Escalation
by Tomislav Paskalev
CVE-2016-0040 EXPLOITDB HIGH ruby VERIFIED
Microsoft Windows - Privilege Escalation
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."
by Metasploit
CVSS 7.8
CVE-2015-10141 EXPLOITDB CRITICAL ruby VERIFIED
Xdebug < 2.5.5 - Unauthenticated OS Command Injection via Remote Debugger Interface
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000 and accepts debugger protocol commands without authentication. An attacker can send a crafted eval command over this interface to execute arbitrary PHP code, which may invoke system-level functions such as system() or passthru(). This results in full compromise of the host under the privileges of the web server user.
by Metasploit
EIP-2026-114691 EXPLOITDB ruby VERIFIED
Metasploit Framework - 'msfd' Remote Code Execution (via Browser) (Metasploit)
by Metasploit
EIP-2026-114690 EXPLOITDB ruby VERIFIED
Metasploit Framework - 'msfd' Remote Code Execution (Metasploit)
by Metasploit
CVE-2018-7602 EXPLOITDB CRITICAL ruby VERIFIED
Drupal 7.x < 7.59 - Remote Code Execution
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
by SixP4ck3r
CVSS 9.8