Exploitdb Exploits

31,330 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105817 EXPLOITDB text
chatNow - Multiple Vulnerabilities
by HaHwul
CVE-2016-6855 EXPLOITDB HIGH text VERIFIED
Fedora - Out-of-Bounds Write
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
by Kaslov Dmitri
CVSS 7.5
CVE-2016-15055 EXPLOITDB HIGH text VERIFIED
JVC VN-T - Path Traversal
JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.
by Yakir Wizman
CVE-2016-6896 EXPLOITDB HIGH text VERIFIED
WordPress Traversal Directory DoS
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random read operations that deplete the entropy pool.
by Yorick Koster
CVSS 7.1
CVE-2016-6897 EXPLOITDB MEDIUM text VERIFIED
Wordpress < 4.5.5 - CSRF
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.
by Yorick Koster
CVSS 6.5
CVE-2005-4664 EXPLOITDB text VERIFIED
OcoMon <1.21 - SQL Injection
SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.
by Jonatas Fil
EIP-2026-102419 EXPLOITDB text
Sakai 10.7 - Multiple Vulnerabilities
by LiquidWorm
EIP-2026-102101 EXPLOITDB text
VideoIQ Camera - Local File Disclosure
by Yakir Wizman
EIP-2026-101059 EXPLOITDB text
ObiHai ObiPhone 1032/1062 < 5-0-0-3497 - Multiple Vulnerabilities
by David Tomaschik
EIP-2026-100925 EXPLOITDB text
Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Local File Disclosure
by Yakir Wizman
EIP-2026-100813 EXPLOITDB text
Honeywell IP-Camera HICC-1100PT - Local File Disclosure
by Yakir Wizman
EIP-2026-112572 EXPLOITDB text
tcPbX - 'tcpbx_lang' Local File Inclusion
by 0x4148
CVE-2016-7089 EXPLOITDB HIGH text
Watchguard Rapidstream - Access Control
WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLOWMAN.
by Shadow Brokers
CVSS 7.8
CVE-2016-6909 EXPLOITDB CRITICAL text
Fortinet Fortios < 4.1.11 - Memory Corruption
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
by Shadow Brokers
CVSS 9.8
EIP-2026-101478 EXPLOITDB text
TOPSEC Firewalls - 'ELIGIBLEBACHELOR' Remote Command Execution
by Shadow Brokers
CVE-2016-6367 EXPLOITDB HIGH text
Cisco ASA <8.4(1) - Privilege Escalation
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
by Shadow Brokers
CVSS 7.8
EIP-2026-100948 EXPLOITDB text VERIFIED
ZYCOO IP Phone System - Remote Command Execution
by 0x4148
EIP-2026-100924 EXPLOITDB text
Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Credentials Disclosure
by Yakir Wizman
EIP-2026-100914 EXPLOITDB text
TOSHIBA IP-Camera IK-WP41A - Authentication Bypass / Configuration Download
by Todor Donev
EIP-2026-100913 EXPLOITDB text
TOPSEC Firewalls - 'ELIGIBLECONTESTANT' Remote Code Execution
by Shadow Brokers
EIP-2026-100912 EXPLOITDB text
TOPSEC Firewalls - 'ELIGIBLECANDIDATE' Remote Code Execution
by Shadow Brokers
EIP-2026-100911 EXPLOITDB text
TOPSEC Firewalls - 'ELIGIBLEBOMBSHELL' Remote Code Execution
by Shadow Brokers
EIP-2026-100891 EXPLOITDB text VERIFIED
SIEMENS IP Cameras (Multiple Models) - Credential Disclosure / Configuration Download
by Todor Donev
EIP-2026-100854 EXPLOITDB text
MESSOA IP-Camera NIC990 - Authentication Bypass / Configuration Download
by Todor Donev
EIP-2026-100838 EXPLOITDB text VERIFIED
JVC IP-Camera VN-T216VPRU - Credentials Disclosure
by Yakir Wizman