Exploit Database

150,152 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-10283 WRITEUP HIGH
Tenda RX9/RX9 Pro 22.03.02.20 - Buffer Overflow
A vulnerability, which was classified as critical, has been found in Tenda RX9 and RX9 Pro 22.03.02.20. Affected by this issue is the function sub_4337EC of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 8.8
CVE-2024-10351 WRITEUP HIGH
Tenda RX9 Pro Firmware 22.03.02.20 - Stack-based Buffer Overflow via setMacFilterCfg deviceList Parameter
A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 8.8
CVE-2024-11175 WRITEUP LOW
PublicCMS 5.202406.d - Cross-Site Scripting in Voting Management
A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of the file /admin/cmsVote/save of the component Voting Management. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named b9530b9cc1f5cfdad4b637874f59029a6283a65c. It is recommended to apply a patch to fix this issue.
CVSS 3.5
CVE-2024-12326 WRITEUP MEDIUM
jirafeau < 4.6.1 - Stored Cross-Site Scripting via Case-Insensitive MIME Type Bypass
Jirafeau normally prevents browser preview for SVG files due to the possibility that manipulated SVG files could be exploited for cross site scripting. This was done by storing the MIME type of a file and preventing the browser preview for MIME type image/svg+xml. This issue was first reported in CVE-2022-30110. However, it was still possible to do a browser preview of a SVG file by sending a manipulated MIME type during the upload, where the case of any letter in image/svg+xml had been changed (like image/svg+XML). The check for image/svg+xml has been changed to be case insensitive.
CVSS 6.1
CVE-2024-13978 WRITEUP LOW
libtiff < 4.7.0 - Null Pointer Dereference in t2p_read_tiff_init
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation appears to be difficult. The patch is named 2ebfffb0e8836bfb1cd7d85c059cd285c59761a4. It is recommended to apply a patch to fix this issue.
CVSS 2.5
CVE-2024-2338 WRITEUP HIGH
PostgreSQL Anonymizer 1.2 - Authenticated SQL Injection via Dynamic Masking Expression
PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to superuser when dynamic masking is enabled. PostgreSQL Anonymizer enables users to set security labels on tables to mask specified columns. There is a flaw that allows complex expressions to be provided as a value. This expression is then later used as it to create the masked views leading to SQL Injection. If dynamic masking is enabled, this will lead to privilege escalation to superuser after the label is created. Users that don't own a table, especially masked users cannot exploit this vulnerability. The problem is resolved in v1.3.
CVSS 8.0
CVE-2024-2339 WRITEUP HIGH
PostgreSQL Anonymizer 1.2 - Privilege Escalation via Malicious Masking Function
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the malicious code is executed and can grant escalated privileges to the malicious user. PostgreSQL Anonymizer v1.2 does provide a protection against this risk with the restrict_to_trusted_schemas option, but that protection is incomplete. Users that don't own a table, especially masked users cannot exploit this vulnerability. The problem is resolved in v1.3.
CVSS 8.0
CVE-2024-28054 WRITEUP HIGH
Amavis <2.12.3, 2.13.x <2.13.1 - Info Disclosure
Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.
CVSS 7.4
CVE-2024-28560 WRITEUP MEDIUM
Niushop B2B2C < 5.3.3 - SQL Injection via Address.php deleteArea() Function
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.
CVSS 5.4
CVE-2024-28559 WRITEUP HIGH
Niushop B2B2C < 5.3.3 - SQL Injection via Goodsbatchset.php setPrice() Function
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.
CVSS 8.8
CVE-2024-2828 WRITEUP MEDIUM
lakernote EasyAdmin < 2024-03-15 - Server-Side Request Forgery via Thumbnail URL Parameter
A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 23165d8cb569048c531150f194fea39f8800b8d5. It is recommended to apply a patch to fix this issue. VDB-257718 is the identifier assigned to this vulnerability.
CVSS 6.3
CVE-2024-32409 WRITEUP HIGH
SEMCMS 4.8 - Remote Code Execution
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
CVSS 7.1
CVE-2024-40075 WRITEUP MEDIUM
Laravel 11.x - XML External Entity Injection
Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.
CVSS 4.3
CVE-2024-40518 WRITEUP HIGH
SeaCMS 12.9 - Authenticated Remote Code Execution via admin_weixin.php
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
CVSS 8.8
CVE-2024-40519 WRITEUP HIGH
SeaCMS 12.9 - Remote Code Execution
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
CVSS 8.8
CVE-2024-40520 WRITEUP HIGH
SeaCMS 12.9 - Remote Code Execution
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user input data into inc_photowatermark_config.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
CVSS 8.8
CVE-2024-40521 WRITEUP HIGH
SeaCMS 12.9 - Authenticated Remote Code Execution via admin_template.php
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrictions on the edited file, attackers can still bypass the restrictions and write code in some way, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CVSS 8.8
CVE-2024-40522 WRITEUP HIGH
SeaCMS 12.9 - Authenticated Remote Code Execution via phomebak.php Variable Injection
There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in without filtering them before writing them into the php file. An authenticated attacker can exploit this vulnerability to execute arbitrary commands and obtain system permissions.
CVSS 8.8
CVE-2024-42598 WRITEUP MEDIUM
SeaCMS 13.0 - Authenticated Remote Code Execution via admin_editplayer.php
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CVSS 6.7
CVE-2024-42599 WRITEUP HIGH
SeaCMS 13.0 - Authenticated Remote Code Execution via admin_files.php
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CVSS 8.8
CVE-2024-45993 WRITEUP MEDIUM
giflib 5.2.2 - Heap-based Buffer Overflow via gif2rgb
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.
CVSS 6.5
CVE-2024-46640 WRITEUP CRITICAL
SeaCMS 13.2 - Remote Code Execution via MySQL Slow Query Method
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
CVSS 9.8
CVE-2024-47191 WRITEUP HIGH
oath-toolkit <2.6.12 - Privilege Escalation
pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.
CVSS 7.1
CVE-2024-48290 WRITEUP MEDIUM
Realtek RTL8762E BLE SDK <1.4.0 - DoS
An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ll_terminate_ind packet.
CVSS 4.3
CVE-2025-60269 WRITEUP CRITICAL
JEEWMS 20250820 - SQL Injection in exportXls Function
JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.
CVSS 9.4