Exploitdb Exploits

49,983 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-14427 EXPLOITDB MEDIUM text
WEB STUDIO Ultimate Loan Manager 2.0 - XSS
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.
by Metin Yunus Kandemir
CVSS 6.1
CVE-2019-13069 EXPLOITDB HIGH ruby
Extenua Silvershield < 6.1.14.144 - Incorrect Permission Assignment
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an additional user account, and then use SSH and port forwarding to reach a 127.0.0.1 service.
by Ian Bredemeyer
CVSS 7.8
EIP-2026-101586 EXPLOITDB html
Cisco Catalyst 3850 Series Device Manager - Cross-Site Request Forgery
by Alperen Soydan
CVE-2019-2861 EXPLOITDB MEDIUM text VERIFIED
Oracle Hyperion Planning - XXE
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Planning. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Planning accessible data. CVSS 3.0 Base Score 4.2 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N).
by Lucas Dinucci
CVSS 4.2
CVE-2019-8662 EXPLOITDB CRITICAL text VERIFIED
Apple Iphone OS < 12.4 - Insecure Deserialization
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
by Google Security Research
CVSS 9.8
CVE-2019-8671 EXPLOITDB HIGH text VERIFIED
Apple Icloud < 7.13 - Out-of-Bounds Write
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
by Google Security Research
CVSS 8.8
CVE-2019-8672 EXPLOITDB HIGH text VERIFIED
Apple Icloud < 7.13 - Out-of-Bounds Write
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
by Google Security Research
CVSS 8.8
CVE-2019-8646 EXPLOITDB HIGH text VERIFIED
Apple Iphone OS < 12.4 - Out-of-Bounds Read
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to leak memory.
by Google Security Research
CVSS 7.5
CVE-2019-8647 EXPLOITDB CRITICAL text VERIFIED
Apple Iphone OS < 12.4 - Use After Free
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause arbitrary code execution.
by Google Security Research
CVSS 9.8
CVE-2019-8660 EXPLOITDB CRITICAL text VERIFIED
Apple Iphone OS < 12.4 - Out-of-Bounds Write
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
by Google Security Research
CVSS 9.8
EIP-2026-103212 EXPLOITDB ruby VERIFIED
Redis 4.x / 5.x - Unauthenticated Code Execution (Metasploit)
by Metasploit
CVE-2019-3948 EXPLOITDB HIGH python VERIFIED
Amcrest Ip2m-841b Firmware < 2018-05-18 - Missing Authentication
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.
by Jacob Baines
CVSS 7.5
CVE-2019-6814 EXPLOITDB CRITICAL ruby VERIFIED
Schneider-electric Net5501 Firmware < 2.1.9.7 - Authentication Bypass
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.
by Metasploit
CVSS 9.8
EIP-2026-114347 EXPLOITDB text
WordPress Theme Real Estate 2.8.9 - Cross-Site Scripting
by m0ze
CVE-2019-14328 EXPLOITDB HIGH html
WordPress Simple Membership <3.8.5 - CSRF
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
by rubyman
CVSS 8.8
EIP-2026-107410 EXPLOITDB text
GigToDo 1.3 - Cross-Site Scripting
by m0ze
EIP-2026-104789 EXPLOITDB ruby VERIFIED
WordPress Plugin Database Backup < 5.2 - Remote Code Execution (Metasploit)
by Metasploit
CVE-2019-1132 EXPLOITDB HIGH c++
Windows - Privilege Escalation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
by ShivamTrivedi
CVSS 7.8
CVE-2018-1042 EXPLOITDB MEDIUM text
Moodle < 3.1.9 - SSRF
Moodle 3.x has Server Side Request Forgery in the filepicker.
by Fabian Mosch_ Nick Theisinger
CVSS 6.5
CVE-2019-14267 EXPLOITDB HIGH text VERIFIED
PDFResurrect 0.15 - Buffer Overflow
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.
by j0lama
CVSS 7.8
CVE-2019-10267 EXPLOITDB HIGH python VERIFIED
Ahsay Cloud Backup Suite < 8.1.1.50 - Unrestricted File Upload
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the system, as the configured user (e.g., Administrator).
by Wietse Boonstra
CVSS 8.8
CVE-2019-10266 EXPLOITDB HIGH text
Ahsay Cloud Backup Suite < 8.1.1.50 - XXE
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.
by Wietse Boonstra
CVSS 7.5
CVE-2019-10267 EXPLOITDB HIGH ruby
Ahsay Cloud Backup Suite < 8.1.1.50 - Unrestricted File Upload
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the system, as the configured user (e.g., Administrator).
by Wietse Boonstra
CVSS 8.8
EIP-2026-110418 EXPLOITDB text
Ovidentia 8.4.3 - SQL Injection
by UserX
CVE-2019-13977 EXPLOITDB MEDIUM text
Ovidentia 8.4.3 - XSS
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.
by n3k00n3
CVSS 5.4