Exploitdb Exploits

31,341 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113580 EXPLOITDB text
Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution
by Milad karimi
CVE-2024-29291 EXPLOITDB text
Laravel Framework <11 - Info Disclosure
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose to have debugging logs, but needs to set the access control appropriately for the type of data that may be logged.
by Huseein Amer
EIP-2026-107143 EXPLOITDB text
FlatPress v1.3 - Remote Command Execution
by Ahmet Ümit BAYRAM
CVE-2024-3400 EXPLOITDB CRITICAL text
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
by Kr0ff
CVSS 10.0
CVE-2024-34401 EXPLOITDB MEDIUM text
Savsoft Quiz 6.0 - XSS
Savsoft Quiz 6.0 allows stored XSS via the index.php/quiz/insert_quiz/ quiz_name parameter.
by Eren Sen
CVSS 6.1
CVE-2024-34987 EXPLOITDB CRITICAL text
Phpgurukul Online Fire Reporting System - SQL Injection
A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.
by Diyar Saadi
CVSS 9.1
CVE-2024-31804 EXPLOITDB MEDIUM text
Terratec DMX_6Fire USB <1.23.0.02 - Privilege Escalation
An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component.
by Joseph Kwabena Fiagbor
CVSS 6.7
CVE-2023-6019 EXPLOITDB CRITICAL text
Ray <2.8.1 - Command Injection
A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023
by Fire_Wolf
CVSS 9.8
EIP-2026-114247 EXPLOITDB text
Wordpress Plugin WP Video Playlist 1.1.1 - Stored Cross-Site Scripting (XSS)
by Erdemstar
EIP-2026-113968 EXPLOITDB text
Wordpress Plugin Playlist for Youtube 1.32 - Stored Cross-Site Scripting (XSS)
by Erdemstar
EIP-2026-113193 EXPLOITDB text
WBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)
by tmrswrr
EIP-2026-113188 EXPLOITDB text
WBCE 1.6.0 - Unauthenticated SQL injection
by young pope
EIP-2026-111405 EXPLOITDB text
PopojiCMS Version 2.0.1 - Remote Command Execution
by tmrswrr
EIP-2026-107670 EXPLOITDB text
HTMLy Version v2.9.6 - Stored XSS
by tmrswrr
CVE-2024-31777 EXPLOITDB CRITICAL text
openeclass <3.15 - RCE
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.
by George Tsimpidas
CVSS 9.8
EIP-2026-103810 EXPLOITDB text
PrusaSlicer 2.6.1 - Arbitrary code execution
by Kamil Breński
CVE-2024-24747 EXPLOITDB HIGH text
MinIO - Privilege Escalation
MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hierarchy, the `admin` rights are denied, access keys will be able to simply override their own `s3` permissions to something more permissive. The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.
by Jenson Zhao
CVSS 8.8
CVE-2025-34499 EXPLOITDB MEDIUM text
AnyDesk 7.0.15,9.0.1 - Code Injection
AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be run with high-level system permissions.
by Milad karimi
EIP-2026-107677 EXPLOITDB text
Human Resource Management System v1.0 - Multiple SQLi
by nu11secur1ty
EIP-2026-106339 EXPLOITDB text
Daily Expense Manager 1.0 - 'term' SQLi
by Stefan Hesselman
EIP-2026-105454 EXPLOITDB text
Best Student Result Management System v1.0 - Multiple SQLi
by nu11secur1ty
CVE-2024-0353 EXPLOITDB HIGH text
Eset Endpoint Antivirus < 8.1.2062.0 - Improper Privilege Management
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
by Milad karimi
CVSS 7.8
EIP-2026-113554 EXPLOITDB text
Wordpress Plugin Alemha Watermarker 1.3.1 - Stored Cross-Site Scripting (XSS)
by Erdemstar
EIP-2026-106115 EXPLOITDB text
Computer Laboratory Management System v1.0 - Multiple-SQLi
by nu11secur1ty
CVE-2024-58341 EXPLOITDB HIGH text
OpenCart Core 4.0.2.3 SQL Injection via search Parameter
OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values to extract sensitive database information using boolean-based blind or time-based blind SQL injection techniques.
by Saud Alenazi
CVSS 8.2