Exploitdb Exploits
31,346 exploits tracked across all sources.
Bludit 3.9.2 - RCE
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
by James Green
CVSS 8.8
Suprema BioStar 2 <2.8.2 - Path Traversal
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.
by SITE Team
CVSS 7.5
UBICOD Medivision Digital Signage 1.5.1 - Auth Bypass
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication.
by LiquidWorm
CVSS 9.8
Nexos theme <1.7 - XSS
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
by Vlad Vector
CVSS 6.1
Docsify < 4.11.4 - XSS
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.
by Amin Sharifi
CVSS 6.1
SonarQube 8.3.1 - Privilege Escalation
SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.
by Velayutham Selvaraj
CVSS 7.8
Cmsuno < 1.6.1 - CSRF
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
by Noth
CVSS 6.5
Wing FTP Server 6.3.8 - RCE
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function.
by V1n1v131r4
CVSS 8.8
Infor Storefront B2B 1.0 - SQL Injection
Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to potentially extract or modify database information.
by ratboy
CVSS 8.2
Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass
by KeopssGroup0day_Inc
Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting
by KeopssGroup0day_Inc
Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
by Mehmet Kelepçe
Zyxel Wap6806 Firmware - Path Traversal
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
by Rajivarnan R
CVSS 8.6
Supermicro X10DRH-iT - CSRF
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
by Metin Yunus Kandemir
CVSS 8.8
Global RADAR BSA Radar <1.6.7234.24750 - Info Disclosure
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files.
by William Summerhill
CVSS 4.3
Park Ticketing Management System 1.0 - Authentication Bypass
by gh1mau
Park Ticketing Management System 1.0 - 'viewid' SQL Injection
by gh1mau
HelloWeb 2.0 - Path Traversal
HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.
by bRpsd
CVSS 7.5
Wordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site Scripting
by mqt
Supermicro X10DRH-iT - CSRF
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
by Metin Yunus Kandemir
CVSS 8.8
By Source