Exploit Database

152,668 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-1759 EXPLOITDB html
Apple Safari < 5.0 - Remote Code Execution via Node.normalize Use-After-Free
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Node.normalize method.
CVE-2013-4710 EXPLOITDB ruby
Android 3.0-4.1.x - Remote Code Execution via WebView.addJavascriptInterface
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
CVE-2012-2995 EXPLOITDB
Trend Micro InterScan Messaging Security Suite 7.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to inject arbitrary web script or HTML via (1) the wrsApprovedURL parameter to addRuleAttrWrsApproveUrl.imss or (2) the src parameter to initUpdSchPage.imss.
CVE-2012-2179 EXPLOITDB
IBM AIX 5.3, 6.1, 7.1 - Arbitrary File Write via Symlink Attack on Temporary File
libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
CVE-2005-2232 EXPLOITDB c
IBM AIX 5.1.0-5.3.0 - Buffer Overflow via Long Command Line Argument
Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.
CVE-2026-0915 GITHUB HIGH shell
glibc 2.0-2.42 - Information Leak via getnetbyaddr DNS Query
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
by cyberwulfy200-dev
CVSS 7.5
CVE-2023-33869 NOMISEC MEDIUM
Enphase Envoy D7.0.88 - Command Injection
Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.
by NAP3XD
CVSS 6.3
CVE-2009-5154 WRITEUP CRITICAL
MOBOTIX S14 Firmware - Use of Hard-coded Credentials
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account.
CVSS 9.8
CVE-2012-6684 WRITEUP
RedCloth < 4.2.9 - Cross-Site Scripting via JavaScript URI
Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.
CVE-2014-0645 WRITEUP
EMC Cloud Tiering Appliance 9.x-10 SP1 and File Management Appliance 7.x - Weak Password Hash Storage
EMC Cloud Tiering Appliance (CTA) 9.x through 10 SP1 and File Management Appliance (FMA) 7.x store DES password hashes for the root, super, and admin accounts, which makes it easier for context-dependent attackers to obtain sensitive information via a brute-force attack.
CVE-2014-1263 WRITEUP
Apple macOS X < 10.9.2 - Certificate Hostname Validation Bypass via Numerical IP Address
curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
CVE-2014-3926 WRITEUP MEDIUM
lg_project/lg < 1.8 - Cross-Site Scripting via addr Parameter
Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9 allows remote attackers to inject arbitrary web script or HTML via the "addr" parameter.
CVSS 6.1
CVE-2014-4976 WRITEUP
Dell SonicWall Scrutinizer 11.0.1 - Privilege Escalation
Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.
CVE-2014-4976 WRITEUP
Dell SonicWall Scrutinizer 11.0.1 - Privilege Escalation
Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.
CVE-2014-7922 WRITEUP
Google Play Services SDK < 6.1 - OAuth Token Scope Bypass via _opt_ Parameter Injection
The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests upon finding a corresponding _opt_ parameter in the Bundle extras argument, which allows attackers to bypass an intended consent dialog and retrieve tokens for arbitrary OAuth scopes including the SID and LSID scopes, and consequently obtain access to a Google account, via a crafted application, as demonstrated by setting the has_permission=1 parameter value upon finding _opt_has_permission in that argument.
CVE-2015-0921 WRITEUP
McAfee ePolicy Orchestrator < 4.6.9 and 5.x < 5.1.2 - Authenticated XML External Entity Injection via Server Task Log
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
CVE-2015-1206 WRITEUP MEDIUM
Google Chrome <M40 - Buffer Overflow
Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged memory write and process crash) via a crafted MP4 file.
CVSS 5.5
CVE-2015-1207 WRITEUP MEDIUM
Google Chrome - Double Free in FFMPEG libavformat/mov.c via Crafted .m4a File
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
CVSS 6.5
CVE-2015-2787 WRITEUP
PHP < 5.4.39 - Use-After-Free via Unserialize with __wakeup Function
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages use of the unset function within an __wakeup function, a related issue to CVE-2015-0231.
CVE-2016-10131 WRITEUP CRITICAL
CodeIgniter < 3.1.3 - Remote Code Execution via Email From Field
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.
CVSS 9.8
CVE-2016-10518 WRITEUP HIGH
WS < 1.0.1 - Memory Corruption
A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memory by sending a ping frame. The ping functionality by default responds with a pong frame and the previously given payload of the ping frame. This is exactly what you expect, but internally ws always transforms all data that we need to send to a Buffer instance and that is where the vulnerability existed. ws didn't do any checks for the type of data it was sending. With buffers in node when you allocate it when a number instead of a string it will allocate the amount of bytes.
CVSS 7.5
CVE-2016-10548 WRITEUP MEDIUM
reduce-css-calc <=1.2.4 - Arbitrary Code Execution via Crafted CSS Input
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the `calc` function.
CVSS 6.1
CVE-2016-4072 WRITEUP CRITICAL
PHP < 5.5.34, 5.6.x < 5.6.20, 7.x < 7.0.5 - Remote Code Execution via Phar Filename Handling
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c.
CVSS 9.8
CVE-2016-4073 WRITEUP CRITICAL
PHP <5.5.34, <5.6.20, <7.0.5 - Buffer Overflow
Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted mb_strcut call.
CVSS 9.8
CVE-2016-4566 WRITEUP MEDIUM
WordPress < 4.5.2 - Cross-Site Scripting via Plupload Flash Component
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
CVSS 6.1