Exploitdb Exploits

31,364 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-7474 EXPLOITDB CRITICAL text
Textpattern < 4.6.2 - SQL Injection
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.
by Manuel García Cárdenas
CVSS 9.8
EIP-2026-101137 EXPLOITDB text
Sony Playstation 4 (PS4) 4.55 < 5.50 - WebKit Code Execution (PoC)
by qwertyoruiop
CVE-2018-7581 EXPLOITDB HIGH text
Weblogexpert Weblog Expert - Incorrect Permission Assignment
\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUILTIN\Users:(ID)C), which allows local users to set a cleartext password and login as admin.
by hyp3rlinx
CVSS 7.8
CVE-2017-15367 EXPLOITDB CRITICAL text
Bacula-web < 7.4.0 - SQL Injection
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
by Gustavo Sorondo
CVSS 9.8
EIP-2026-111727 EXPLOITDB text
Redaxo CMS Addon MyEvents 2.2.1 - SQL Injection
by h0n1gsp3cht
CVE-2018-7739 EXPLOITDB CRITICAL text
antsle antman <0.9.1a - Auth Bypass
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. This allows obtaining root permissions within the web management console, because the login process uses Java's ProcessBuilder class and a bash script called antsle-auth with insufficient input validation.
by Joshua Bowser
CVSS 9.8
CVE-2018-7658 EXPLOITDB HIGH text
Softros Network Time System - Improper Input Validation
NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes.
by hyp3rlinx
CVSS 7.5
CVE-2018-7264 EXPLOITDB CRITICAL text
Activepdf Toolkit < 8.1.0.19023 - Out-of-Bounds Write
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
by François Goichon
CVSS 9.8
EIP-2026-105940 EXPLOITDB text
ClipBucket < 4.0.0 - Release 4902 - Command Injection / File Upload / SQL Injection
by SEC Consult
EIP-2026-105939 EXPLOITDB text
ClipBucket < 4.0.0 - Release 4902 - Command Injection / File Upload / SQL Injection
by SEC Consult
CVE-2018-6794 EXPLOITDB MEDIUM text
Suricata <4.0.4 - SSRF
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-way handshake is complete, then the data sent by the malicious server will be accepted by web clients such as a web browser or Linux CLI utilities, but ignored by Suricata IDS signatures. This mostly affects IDS signatures for the HTTP protocol and TCP stream content; signatures for TCP packets will inspect such network traffic as usual.
by Positive Technologies
CVSS 5.3
EIP-2026-103007 EXPLOITDB text
Sophos UTM 9.410 - 'loginuser' 'confd' Service Privilege Escalation
by KoreLogic
CVE-2018-7583 EXPLOITDB HIGH text
Advantig Dualdesk - Improper Input Validation
Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500.
by hyp3rlinx
CVSS 7.5
CVE-2018-7490 EXPLOITDB HIGH text VERIFIED
Unbit Uwsgi < 2.0.17 - Path Traversal
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
by Marios Nicolaides
CVSS 7.5
CVE-2018-7466 EXPLOITDB HIGH text
Testlink < 1.9.16 - Code Injection
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.
by Manish Tanwar
CVSS 7.5
CVE-2018-7739 EXPLOITDB CRITICAL text
antsle antman <0.9.1a - Auth Bypass
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. This allows obtaining root permissions within the web management console, because the login process uses Java's ProcessBuilder class and a bash script called antsle-auth with insufficient input validation.
by Joshua Bowser
CVSS 9.8
CVE-2018-6936 EXPLOITDB MEDIUM text
D-link Dir-600m C1 Firmware - XSS
Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.
by Prasenjit Kanti Paul
CVSS 5.4
CVE-2018-6193 EXPLOITDB MEDIUM text VERIFIED
Routers2 - XSS
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl.
by Lorenzo Di Fuccia
CVSS 4.7
CVE-2018-25249 EXPLOITDB MEDIUM text VERIFIED
MyBB My Arcade Plugin 1.3 Persistent XSS via Comment
MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other users view or edit the comment.
by 0xB9
CVSS 6.4
CVE-2018-7477 EXPLOITDB CRITICAL text
School Management Script - SQL Injection
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php.
by Samiran Santra
CVSS 9.8
CVE-2018-7448 EXPLOITDB HIGH text
Cmsmadesimple Cms Made Simple - OS Command Injection
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
by Keerati T.
CVSS 7.5
EIP-2026-103682 EXPLOITDB text VERIFIED
Transmission - Integer Overflows Parsing Torrent Files
by Google Security Research
CVE-2018-6229 EXPLOITDB CRITICAL text VERIFIED
Trendmicro Email Encryption Gateway - SQL Injection
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
by Core Security
CVSS 9.8
CVE-2018-6228 EXPLOITDB CRITICAL text VERIFIED
Trendmicro Email Encryption Gateway - SQL Injection
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
by Core Security
CVSS 9.8
CVE-2018-6227 EXPLOITDB MEDIUM text VERIFIED
Trendmicro Email Encryption Gateway - XSS
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts into vulnerable systems.
by Core Security
CVSS 5.4