Exploitdb Exploits

49,989 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-25638 EXPLOITDB HIGH text
Meeplace Business Review Script Lastest SQL Injection via addclick.php
Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the addclick.php endpoint with crafted SQL payloads in the 'id' parameter to extract sensitive database information or cause denial of service.
by Ahmet Ümit BAYRAM
CVSS 7.1
CVE-2019-7303 EXPLOITDB HIGH c VERIFIED
Canonical snapd <2.37.4 - Privilege Escalation
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.
by Google Security Research
CVSS 7.5
CVE-2019-25642 EXPLOITDB HIGH text
Bootstrapy CMS Lastest Multiple SQL Injection via Forum and Contact Modules
Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can inject SQL payloads into the thread_id parameter of forum-thread.php, the subject parameter of contact-submit.php, the post-id parameter of post-new-submit.php, and the thread-id parameter to extract sensitive database information or cause denial of service.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25641 EXPLOITDB HIGH text
Netartmedia Vlog System Lastest SQL Injection via email Parameter
Netartmedia Vlog System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with malicious email values in the forgotten_password module to extract sensitive database information.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25530 EXPLOITDB HIGH text VERIFIED
uHotelBooking System - SQL Injection
uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL injection techniques to extract sensitive database information.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25529 EXPLOITDB HIGH text
Placeto CMS Alpha rv.4 - SQL Injection
Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'page' parameter. Attackers can send GET requests to the admin/edit.php endpoint with malicious 'page' values using boolean-based blind, time-based blind, or union-based techniques to extract sensitive database information.
by Abdullah Çelebi
CVSS 7.1
CVE-2018-9128 EXPLOITDB HIGH python
Dvd-x-player Dvd X Player - Memory Corruption
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
by Paolo Perego
CVSS 7.8
CVE-2019-9768 EXPLOITDB HIGH php
Thinkst Canarytokens <4e89ee0 - Info Disclosure
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token.
by Benjamin Zink Loft_ Gionathan Reale
CVSS 7.5
EIP-2026-112632 EXPLOITDB text VERIFIED
The Company Business Website CMS - Multiple Vulnerabilities
by Ahmet Ümit BAYRAM
CVE-2019-5418 EXPLOITDB HIGH python
Ruby On Rails File Content Disclosure (
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
by NotoriousRebel
CVSS 7.5
CVE-2019-25539 EXPLOITDB HIGH text
202CMS v10 beta - SQL Injection
202CMS v10 beta contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send POST requests to index.php with crafted SQL payloads using time-based blind injection techniques to extract sensitive database information.
by Mehmet EMIROGLU
CVSS 8.2
CVE-2019-25538 EXPLOITDB HIGH text
202CMS v10 beta - SQL Injection
202CMS v10 beta contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send crafted requests with malicious SQL statements in the log_user field to extract sensitive database information or modify database contents.
by Mehmet EMIROGLU
CVSS 8.2
CVE-2019-25536 EXPLOITDB HIGH text
Netartmedia PHP Real Estate Agency 4.0 - SQL Injection
Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[] parameter to extract sensitive database information or manipulate database queries.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25535 EXPLOITDB HIGH text
Netartmedia PHP Dating Site - SQL Injection
Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads in the Email field to extract sensitive database information.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25534 EXPLOITDB HIGH text
Netartmedia PHP Car Dealer - SQL Injection
Netartmedia PHP Car Dealer contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can submit POST requests to index.php with crafted SQL payloads in the features[] parameter to extract sensitive database information or manipulate database queries.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25533 EXPLOITDB HIGH text
Netartmedia PHP Business Directory 4.2 - SQL Injection
Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Email field to extract sensitive database information or bypass authentication.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25532 EXPLOITDB HIGH text
Netartmedia Jobs Portal 6.1 - SQL Injection
Netartmedia Jobs Portal 6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with crafted SQL payloads in the Email field to extract sensitive database information or bypass authentication.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25531 EXPLOITDB HIGH text
Netartmedia Deals Portal - SQL Injection
Netartmedia Deals Portal contains an SQL injection vulnerability in the Email parameter of loginaction.php that allows unauthenticated attackers to manipulate database queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive information or bypass authentication mechanisms.
by Ahmet Ümit BAYRAM
CVSS 8.2
EIP-2026-117687 EXPLOITDB python
NetShareWatcher 1.5.8.0 - Local SEH Buffer Overflow
by Peyman Forouzan
CVE-2019-6279 EXPLOITDB HIGH text
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN - Privilege Escalation
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
by Kumar Saurav
CVSS 8.8
CVE-2019-6282 EXPLOITDB HIGH text
Chinamobileltd Gpn2.4p21-c-cn Firmware - CSRF
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
by Kumar Saurav
CVSS 8.8
CVE-2019-25643 EXPLOITDB HIGH text
eNdonesia Portal v8.7 SQL Injection via banners.php
eNdonesia Portal v8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the bid parameter. Attackers can send GET requests to banners.php with crafted SQL payloads in the bid parameter to extract sensitive database information from the INFORMATION_SCHEMA tables.
by Mehmet EMIROGLU
CVSS 8.2
CVE-2019-25543 EXPLOITDB HIGH text VERIFIED
Netartmedia Real Estate Portal 5.0 - SQL Injection
Netartmedia Real Estate Portal 5.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can submit POST requests to index.php with malicious SQL payloads in the page field to bypass authentication, extract sensitive data, or modify database contents.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25542 EXPLOITDB HIGH text VERIFIED
Netartmedia Real Estate Portal 5.0 - SQL Injection
Netartmedia Real Estate Portal 5.0 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_email parameter. Attackers can send POST requests to index.php with malicious payloads in the user_email field to bypass authentication, extract sensitive data, or modify database contents.
by Ahmet Ümit BAYRAM
CVSS 8.2
CVE-2019-25541 EXPLOITDB HIGH text VERIFIED
Netartmedia PHP Mall 4.1 - SQL Injection
Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' parameter in loginaction.php to extract sensitive database information.
by Ahmet Ümit BAYRAM
CVSS 8.2