Exploitdb Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113965 EXPLOITDB text
Wordpress Plugin PicUploader 1.0 - Remote File Upload
by Milad karimi
EIP-2026-108907 EXPLOITDB text
Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
by qw3rTyTy
EIP-2026-103888 EXPLOITDB text
CyberArk PSMP 10.9.1 - Policy Restriction Bypass
by LAHBAL Said
CVE-2020-37144 EXPLOITDB MEDIUM text
Exagate SYSGuard 6001 - CSRF
Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent.
by Metin Yunus Kandemir
CVSS 5.3
CVE-2020-37045 EXPLOITDB HIGH text
Veritas NetBackup 7.0 - Code Injection
Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges.
by El Masas
CVSS 7.8
CVE-2020-10364 EXPLOITDB HIGH text
Mikrotik Routeros < 6.44.3 - Resource Allocation Without Limits
The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.
by FarazPajohan
CVSS 7.5
CVE-2020-20021 EXPLOITDB HIGH text
Mikrotik Routeros < 6.46.3 - Denial of Service
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
by FarazPajohan
CVSS 7.5
EIP-2026-108193 EXPLOITDB text
Joomla! Component ACYMAILING 3.9.0 - Unauthenticated Arbitrary File Upload
by qw3rTyTy
EIP-2026-101891 EXPLOITDB text
Netlink GPON Router 1.0.11 - Remote Code Execution
by shellord
EIP-2026-112842 EXPLOITDB text
UADMIN Botnet 1.0 - 'link' SQL Injection
by n4pst3r
EIP-2026-109467 EXPLOITDB text
MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
by AYADI Mohamed
EIP-2026-100308 EXPLOITDB text
Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
by Miguel Mendez Z
EIP-2026-113676 EXPLOITDB text
WordPress Plugin Custom Searchable Data System - Unauthenticated Data M]odification
by Nawaf Alkeraithe
CVE-2020-10230 EXPLOITDB CRITICAL text
Webpanel - SQL Injection
CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.
by Berke YILMAZ
CVSS 9.8
CVE-2020-37145 EXPLOITDB MEDIUM text
HRSALE 1.1.8 - CSRF
HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.
by Ismail Akıcı
CVSS 4.3
EIP-2026-116818 EXPLOITDB text
ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
by Roberto Piña
CVE-2020-9372 EXPLOITDB HIGH text
Codepeople Appointment Booking Calendar - Remote Code Execution
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
by Daniel Monzón
CVSS 7.8
EIP-2026-108455 EXPLOITDB text
Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
by Milad karimi
EIP-2026-102432 EXPLOITDB text
WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
by RedTeam Pentesting GmbH
CVE-2020-37079 EXPLOITDB MEDIUM text
Wing FTP Server <6.2.7 - CSRF
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper authorization.
by Dhiraj Mishra
CVSS 4.3
CVE-2020-11548 EXPLOITDB CRITICAL text
Search Meter < 2.13.2 - Remote Code Execution
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
by Daniel Monzón
CVSS 9.8
EIP-2026-118391 EXPLOITDB text
CoreFTP 2.0 Build 674 SIZE - Directory Traversal (Metasploit)
by Kevin Randall
EIP-2026-118390 EXPLOITDB text
CoreFTP 2.0 Build 674 MDTM - Directory Traversal (Metasploit)
by Kevin Randall
EIP-2026-116819 EXPLOITDB text
ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
by Roberto Piña
EIP-2026-111327 EXPLOITDB text
PlaySMS 1.4.3 - Template Injection / Remote Code Execution
by Touhid M.Shaikh