Exploitdb Exploits

31,329 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108878 EXPLOITDB text
Joomla! Component StreetGuessr Game 1.1.8 - SQL Injection
by Ihsan Sencan
EIP-2026-111489 EXPLOITDB text
Premium Servers List Tracker 1.0 - SQL Injection
by Kaan KAMIS
EIP-2026-109655 EXPLOITDB text
Muviko 1.0 - 'q' SQL Injection
by Kaan KAMIS
EIP-2026-108882 EXPLOITDB text
Joomla! Component Ultimate Property Listing 1.0.2 - SQL Injection
by Ihsan Sencan
EIP-2026-108854 EXPLOITDB text
Joomla! Component SIMGenealogy 2.1.5 - SQL Injection
by Ihsan Sencan
EIP-2026-108831 EXPLOITDB text
Joomla! Component PHP-Bridge 1.2.3 - SQL Injection
by Ihsan Sencan
EIP-2026-108775 EXPLOITDB text
Joomla! Component LMS King Professional 3.2.4.0 - SQL Injection
by Ihsan Sencan
EIP-2026-108642 EXPLOITDB text
Joomla! Component Event Registration Pro Calendar 4.1.3 - SQL Injection
by Ihsan Sencan
EIP-2026-106887 EXPLOITDB text
Entrepreneur B2B Script - 'pid' SQL Injection
by Meisam Monsef
EIP-2026-106776 EXPLOITDB text
EDUMOD Pro 1.3 - SQL Injection
by Kaan KAMIS
EIP-2026-113048 EXPLOITDB text
VehicleWorkshop - Authentication Bypass
by Touhid M.Shaikh
EIP-2026-113047 EXPLOITDB text
VehicleWorkshop - Arbitrary File Upload
by Touhid M.Shaikh
EIP-2026-108925 EXPLOITDB text
JoySale 2.2.1 - Arbitrary File Upload
by Mutlu Benmutlu
CVE-2017-7047 EXPLOITDB HIGH text VERIFIED
Apple <10.3.3, <10.12.6, <10.2.2, <3.2.3 - RCE/DoS
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "libxpc" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
by Google Security Research
CVSS 8.8
CVE-2017-11552 EXPLOITDB MEDIUM text
mpg321 <0.3.2-1 - Memory Corruption
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted MP3 file.
by qflb.wu
CVSS 6.5
CVE-2017-11494 EXPLOITDB CRITICAL text
SOL.Connect ISET-mpp meter <1.2.4.2 - SQL Injection
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action.
by Andy Tan
CVSS 9.8
CVE-2017-11358 EXPLOITDB MEDIUM text
Sound Exchange - Out-of-Bounds Read
The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.
by qflb.wu
CVSS 5.5
CVE-2017-11333 EXPLOITDB MEDIUM text
Xiph.org Libvorbis - NULL Pointer Dereference
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.
by qflb.wu
CVSS 5.5
CVE-2017-11332 EXPLOITDB MEDIUM text
Sound Exchange - Divide By Zero
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
by qflb.wu
CVSS 5.5
CVE-2017-15185 EXPLOITDB MEDIUM text
Libmp3splt - Improper Input Validation
plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
by qflb.wu
CVSS 5.0
CVE-2017-11331 EXPLOITDB MEDIUM text
Xiph Vorbis-tools - Memory Corruption
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.
by qflb.wu
CVSS 5.5
CVE-2017-11359 EXPLOITDB MEDIUM text
Sound Exchange - Divide By Zero
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
by qflb.wu
CVSS 5.5
CVE-2017-11548 EXPLOITDB MEDIUM text
Xiph.Org libao 1.2.0 - Memory Corruption
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.
by qflb.wu
CVSS 5.5
CVE-2017-11330 EXPLOITDB MEDIUM text
Divfix++ - Out-of-Bounds Write
The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted avi file.
by qflb.wu
CVSS 5.5
CVE-2017-9259 EXPLOITDB MEDIUM text
SoundTouch 1.9.2 - DoS
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted wav file.
by qflb.wu
CVSS 5.5