Exploitdb Exploits

49,989 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-109944 EXPLOITDB text
No-Cms 1.0 - 'order_by' SQL Injection
by Loading Kura Kura
CVE-2018-14665 EXPLOITDB MEDIUM ruby VERIFIED
xorg-x11-server <1.20.3 - Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
by Metasploit
CVSS 6.6
EIP-2026-102669 EXPLOITDB text
MariaDB Client 10.1.26 - Denial of Service (PoC)
by strider
EIP-2026-102146 EXPLOITDB text
Zyxel VMG1312-B10D 5.13AAXA.8 - Directory Traversal
by numan türle
EIP-2026-101954 EXPLOITDB text
Ricoh myPrint 2.9.2.4 - Hard-Coded Credentials
by Hodorsec
CVE-2018-25210 EXPLOITDB HIGH text
WebOfisi E-Ticaret 4.0 SQL Injection via urun Parameter
WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL payloads through the 'urun' parameter to execute boolean-based blind, error-based, time-based blind, and stacked query attacks against the backend database.
by AkkuS
CVSS 8.2
CVE-2018-25133 EXPLOITDB MEDIUM text
Synaccess netBooter NP-0801DU 7.4 - CSRF
Synaccess netBooter NP-0801DU 7.4 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages with hidden form submissions to add admin users by tricking authenticated administrators into loading a malicious page.
by LiquidWorm
CVSS 4.3
EIP-2026-114311 EXPLOITDB text
WordPress Theme CherryFramework 3.1.4 - Backup File Download
by b1p0l4r
EIP-2026-112671 EXPLOITDB text
Ticketly 1.0 - 'name' SQL Injection
by Javier Olmedo
CVE-2018-18955 EXPLOITDB HIGH bash
Linux Nested User Namespace idmap Limit Local Privilege Escalation
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
by bcoles
CVSS 7.0
CVE-2018-18955 EXPLOITDB HIGH bash
Linux Nested User Namespace idmap Limit Local Privilege Escalation
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
by bcoles
CVSS 7.0
CVE-2018-18922 EXPLOITDB CRITICAL text
AbiSoft Ticketly 1.0 - RCE
add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.
by Javier Olmedo
CVSS 9.8
CVE-2018-8550 EXPLOITDB HIGH text VERIFIED
Windows COM Aggregate Marshaler - Privilege Escalation
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
by Google Security Research
CVSS 7.8
EIP-2026-103362 EXPLOITDB c
Apple macOS 10.13 - 'workq_kernreturn' Denial of Service (PoC)
by Fabiano Anemone
EIP-2026-119529 EXPLOITDB python
HTML Video Player 1.2.5 - Buffer-Overflow (SEH)
by Kağan Çapar
EIP-2026-119528 EXPLOITDB python
HTML Video Player 1.2.5 - Buffer-Overflow (SEH)
by Kağan Çapar
EIP-2026-116617 EXPLOITDB python
XMPlay 3.8.3 - '.m3u' Denial of Service (PoC)
by s7acktrac3
EIP-2026-116616 EXPLOITDB python
XMPlay 3.8.3 - '.m3u' Denial of Service (PoC)
by s7acktrac3
EIP-2026-115648 EXPLOITDB javascript VERIFIED
Microsoft Edge Chakra - OP_Memset Type Confusion
by Google Security Research
EIP-2026-115647 EXPLOITDB javascript VERIFIED
Microsoft Edge Chakra - OP_Memset Type Confusion
by Google Security Research
CVE-2018-16323 EXPLOITDB MEDIUM bash
Imagemagick < 6.9.10-9 - Information Disclosure
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.
by ttffdd
CVSS 6.5
CVE-2018-25161 EXPLOITDB HIGH text
Warranty Tracking System 11.06.3 - SQL Injection
Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting malicious code through the txtCustomerCode, txtCustomerName, and txtPhone POST parameters in SearchCustomer.php. Attackers can submit crafted SQL statements using UNION SELECT to extract sensitive database information including usernames, database names, and version details.
by Ihsan Sencan
CVSS 8.2
CVE-2024-1186 EXPLOITDB LOW python
Munsoft Easy Archive Recovery - Improper Resource Release
A vulnerability classified as problematic was found in Munsoft Easy Archive Recovery 2.0. This vulnerability affects unknown code of the component Registration Key Handler. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252676. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
by Ihsan Sencan
CVSS 3.3
EIP-2026-119584 EXPLOITDB text
Easy Outlook Express Recovery 2.0 - Denial of Service (PoC)
by Ihsan Sencan
EIP-2026-107583 EXPLOITDB text
Helpdezk 1.1.1 - Arbitrary File Upload
by Ihsan Sencan