Exploitdb Exploits

50,130 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105452 EXPLOITDB text
Best pos Management System v1.0 - SQL Injection
by Ahmed Ismail
CVE-2023-0943 EXPLOITDB MEDIUM text VERIFIED
Best Pos Management System - Unrestricted File Upload
A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler. The manipulation of the argument img with the input ../../shell.php leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-221591.
by Ahmed Ismail
CVSS 4.7
CVE-2023-0915 EXPLOITDB MEDIUM text VERIFIED
Auto Dealer Management System - SQL Injection
A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. Affected is an unknown function of the file /adms/admin/?page=user/manage_user. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221490 is the identifier assigned to this vulnerability.
by Muhammad Navaid Zafar Ansari
CVSS 6.3
CVE-2023-0913 EXPLOITDB MEDIUM text VERIFIED
Auto Dealer Management System - SQL Injection
A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. This vulnerability affects unknown code of the file /adms/admin/?page=vehicles/sell_vehicle. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221482 is the identifier assigned to this vulnerability.
by Muhammad Navaid Zafar Ansari
CVSS 4.7
CVE-2023-0912 EXPLOITDB MEDIUM text VERIFIED
Auto Dealer Management System - SQL Injection
A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. This affects an unknown part of the file /adms/admin/?page=vehicles/view_transaction. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221481 was assigned to this vulnerability.
by Muhammad Navaid Zafar Ansari
CVSS 4.7
CVE-2023-0916 EXPLOITDB MEDIUM text VERIFIED
Auto Dealer Management System - Improper Access Control
A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221491.
by Muhammad Navaid Zafar Ansari
CVSS 6.3
EIP-2026-105285 EXPLOITDB text
atrocore 1.5.25 User interaction - Unauthenticated File upload - RCE
by nu11secur1ty
CVE-2023-23156 EXPLOITDB CRITICAL python VERIFIED
Phpgurukul Art Gallery Management System - SQL Injection
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
by Yogesh Verma
CVSS 9.8
CVE-2023-24217 EXPLOITDB HIGH python
AgileBio Electronic Lab Notebook <4.234 - Local File Inclusion
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
by Anthony Cole
CVSS 8.8
EIP-2026-104213 EXPLOITDB text
craftercms 4.x.x - CORS
by nu11secur1ty
EIP-2026-103373 EXPLOITDB ruby
HospitalRun 1.0.0-beta - Local Root Exploit for macOS
by Jean Pereira
CVE-2023-27826 EXPLOITDB HIGH python
Seowonintech Swc-5100w Firmware - OS Command Injection
SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.
by Momen Eldawakhly
CVSS 8.8
EIP-2026-101404 EXPLOITDB text
Osprey Pump Controller v1.0.1 - Unauthenticated Reflected XSS
by LiquidWorm
EIP-2026-101403 EXPLOITDB python
Osprey Pump Controller 1.0.1 - Unauthenticated Remote Code Execution Exploit
by LiquidWorm
EIP-2026-101402 EXPLOITDB text
Osprey Pump Controller 1.0.1 - Unauthenticated File Disclosure
by LiquidWorm
EIP-2026-101401 EXPLOITDB text
Osprey Pump Controller 1.0.1 - Predictable Session Token / Session Hijack
by LiquidWorm
EIP-2026-101400 EXPLOITDB text
Osprey Pump Controller 1.0.1 - Cross-Site Request Forgery
by LiquidWorm
EIP-2026-101399 EXPLOITDB python
Osprey Pump Controller 1.0.1 - Authentication Bypass Credentials Modification
by LiquidWorm
EIP-2026-101398 EXPLOITDB text
Osprey Pump Controller 1.0.1 - Administrator Backdoor Access
by LiquidWorm
EIP-2026-101397 EXPLOITDB text
Osprey Pump Controller 1.0.1 - (userName) Blind Command Injection
by LiquidWorm
EIP-2026-101396 EXPLOITDB text
Osprey Pump Controller 1.0.1 - (pseudonym) Semi-blind Command Injection
by LiquidWorm
EIP-2026-101395 EXPLOITDB text
Osprey Pump Controller 1.0.1 - (eventFileSelected) Command Injection
by LiquidWorm
CVE-2023-0830 EXPLOITDB MEDIUM python
Easynas - Command Injection
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
by Ivan Spiridonov
CVSS 6.3
CVE-2022-45701 EXPLOITDB HIGH python
Commscope Arris Tg2482a Firmware < 9.1.103 - Command Injection
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
by Yerodin Richards
CVSS 8.8
CVE-2023-26609 EXPLOITDB HIGH text
ABUS TVIP - RCE
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.
CVSS 7.2