Exploit Database

149,243 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-38193 INTHEWILD HIGH
Windows Ancillary Function Driver - Privilege Escalation
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2024-38189 INTHEWILD HIGH
Microsoft Project 2016 < 16.0.5461.1001 - Remote Code Execution
Microsoft Project Remote Code Execution Vulnerability
CVSS 8.8
CVE-2024-38100 INTHEWILD HIGH
Windows File Explorer - Privilege Escalation
Windows File Explorer Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2024-3806 INTHEWILD CRITICAL
Porto theme for WordPress <7.1.0 - Local File Inclusion
The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.
CVSS 9.8
CVE-2024-38041 INTHEWILD MEDIUM
Windows Kernel - Information Disclosure
Windows Kernel Information Disclosure Vulnerability
CVSS 5.5
CVE-2024-37085 INTHEWILD MEDIUM
VMware ESXi - Authentication Bypass via Recreated Active Directory Group
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
CVSS 6.8
CVE-2024-37084 INTHEWILD CRITICAL
Spring Cloud Data Flow < 2.11.4 - Authenticated Arbitrary File Write via Skipper Server API
In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
CVSS 9.8
CVE-2024-3393 INTHEWILD HIGH
Palo Alto Networks PAN-OS >= 11.1.0 < 11.1.1 - Unauthenticated Denial of Service via Malicious DNS Packet
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
CVSS 7.5
CVE-2024-32709 INTHEWILD CRITICAL
Plechev Andrey WP-Recall <16.26.5 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.
CVSS 9.3
CVE-2024-32523 INTHEWILD HIGH
EverPress Mailster <4.0.6 - Path Traversal
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in EverPress Mailster mailster.This issue affects Mailster: from n/a through <= 4.0.6.
CVSS 8.1
CVE-2024-31497 INTHEWILD MEDIUM
PuTTY 0.68-0.80 - Cryptographically Weak PRNG in ECDSA Nonce Generation
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures were made by Pageant through an agent-forwarding mechanism. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. After a key compromise, an adversary may be able to conduct supply-chain attacks on software maintained in Git. A second, independent scenario is that the adversary is an operator of an SSH server to which the victim authenticates (for remote login or file copy), even though this server is not fully trusted by the victim, and the victim uses the same private key for SSH connections to other services operated by other entities. Here, the rogue server operator (who would otherwise have no way to determine the victim's private key) can derive the victim's private key, and then use it for unauthorized access to those other services. If the other services include Git services, then again it may be possible to conduct supply-chain attacks on software maintained in Git. This also affects, for example, FileZilla before 3.67.0, WinSCP before 6.3.3, TortoiseGit before 2.15.0.1, and TortoiseSVN through 1.14.6.
CVSS 5.9
CVE-2024-31345 INTHEWILD CRITICAL
Sukhchain Singh Auto Poster <1.2 - Unrestricted Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.
CVSS 9.1
CVE-2024-31286 INTHEWILD CRITICAL
J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus <8.6.03.005 - Unr...
Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.
CVSS 9.9
CVE-2024-30078 INTHEWILD HIGH
Windows Wi-Fi Driver - Remote Code Execution
Windows Wi-Fi Driver Remote Code Execution Vulnerability
CVSS 8.8
CVE-2024-28987 INTHEWILD CRITICAL
SolarWinds Web Help Desk - Hardcoded Credential
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
CVSS 9.1
CVE-2024-28987 INTHEWILD CRITICAL
SolarWinds Web Help Desk - Hardcoded Credential
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
CVSS 9.1
CVE-2024-28987 INTHEWILD CRITICAL
SolarWinds Web Help Desk - Hardcoded Credential
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
CVSS 9.1
CVE-2024-28987 INTHEWILD CRITICAL
SolarWinds Web Help Desk - Hardcoded Credential
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
CVSS 9.1
CVE-2024-28222 INTHEWILD CRITICAL
Veritas NetBackup < 8.1.2 and NetBackup Appliance < 3.1.2 - Unauthenticated Path Traversal and Arbitrary File Write
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
CVSS 9.8
CVE-2024-27971 INTHEWILD HIGH
Premmerce Permalink Manager <2.3.10 - Path Traversal
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce woo-permalink-manager.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through <= 2.3.10.
CVSS 8.3
CVE-2024-27564 INTHEWILD MEDIUM
ChatGPT个人专用版 - Server Side Request Forgery
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.
CVSS 5.8
CVE-2024-27191 INTHEWILD HIGH
Inperstton Slivery Extender <1.0.2 - Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender allows Remote Code Inclusion.This issue affects Slivery Extender: from n/a through <= 1.0.2.
CVSS 8.5
CVE-2024-27130 INTHEWILD HIGH
QNAP QTS and QuTS hero - Remote Code Execution via Stack-based Buffer Overflow
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later
CVSS 7.2
CVE-2024-26304 INTHEWILD CRITICAL
L2/L3 Management service - Buffer Overflow
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVSS 9.8
CVE-2024-26198 INTHEWILD HIGH
Microsoft Exchange Server - Remote Code Execution via Untrusted Search Path
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS 8.8