Exploitdb Exploits

49,989 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-25263 EXPLOITDB HIGH python
Faleemi Desktop Software 1.8.2 Local Buffer Overflow SEH
Faleemi Desktop Software 1.8.2 contains a local buffer overflow vulnerability in the Device alias field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Device alias field within the Managing Log interface to execute arbitrary code with calculator proof-of-concept execution.
by Gionathan Reale
CVSS 8.4
CVE-2018-17381 EXPLOITDB CRITICAL text
Dutch Auction Factory 2.0.2 - SQL Injection
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
by Ihsan Sencan
CVSS 9.8
EIP-2026-119522 EXPLOITDB python VERIFIED
Easy PhoroResQ 1.0 - Buffer Overflow
by Cemal Cihad ÇİFTÇİ
CVE-2017-3622 EXPLOITDB HIGH ruby VERIFIED
Oracle Sun Systems Products Suite <10 - RCE
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)). The supported version that is affected is 10. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. Note: CVE-2017-3622 is assigned for the "Extremeparr". CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
by Metasploit
CVSS 7.8
CVE-2018-17391 EXPLOITDB CRITICAL text VERIFIED
Super Cms Blog Pro 1.0 - SQL Injection
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17394 EXPLOITDB CRITICAL text
Joomla! Timetable Schedule <3.6.8 - SQL Injection
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17384 EXPLOITDB CRITICAL text VERIFIED
Swap Factory 2.2.1 - SQL Injection
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17385 EXPLOITDB CRITICAL text VERIFIED
Social Factory 3.8.3 - SQL Injection
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17376 EXPLOITDB CRITICAL text VERIFIED
Joomla! Reverse Auction Factory 4.3.8 - SQL Injection
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
by Ihsan Sencan
CVSS 9.8
EIP-2026-108847 EXPLOITDB text
Joomla! Component Responsive Portfolio 1.6.1 - 'filter_order_Dir' SQL Injection
by AkkuS
CVE-2018-17379 EXPLOITDB CRITICAL text VERIFIED
Raffle Factory 3.5.2 - SQL Injection
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17377 EXPLOITDB CRITICAL text
Joomla! 1.4.3 - SQL Injection
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17378 EXPLOITDB CRITICAL text VERIFIED
Penny Auction Factory 2.0.4 - SQL Injection
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17375 EXPLOITDB CRITICAL text VERIFIED
Music Collection 3.0.3 - SQL Injection
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17382 EXPLOITDB CRITICAL text VERIFIED
Jobs Factory 2.0.4 - SQL Injection
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
by Ihsan Sencan
CVSS 9.8
EIP-2026-108646 EXPLOITDB text
Joomla! Component eXtroForms 2.1.5 - 'filter_type_id' SQL Injection
by AkkuS
CVE-2018-17383 EXPLOITDB CRITICAL text
Joomla! - SQL Injection
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17380 EXPLOITDB CRITICAL text VERIFIED
Article Factory Manager 4.3.9 - SQL Injection
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17397 EXPLOITDB CRITICAL text
AlphaIndex Dictionaries <1.0 - SQL Injection
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-4315 EXPLOITDB HIGH html VERIFIED
Apple Safari < 12 - Use After Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
by Google Security Research
CVSS 8.8
CVE-2018-4318 EXPLOITDB HIGH html VERIFIED
Apple Safari < 12 - Use After Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
by Google Security Research
CVSS 8.8
CVE-2018-4314 EXPLOITDB HIGH html VERIFIED
Apple Safari < 12 - Use After Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
by Google Security Research
CVSS 8.8
CVE-2018-4197 EXPLOITDB HIGH html VERIFIED
Apple Safari < 12 - Use After Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
by Google Security Research
CVSS 8.8
CVE-2018-4323 EXPLOITDB HIGH html VERIFIED
Apple Safari < 12 - Memory Corruption
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
by Google Security Research
CVSS 8.8
CVE-2018-4317 EXPLOITDB HIGH html VERIFIED
Apple Safari < 12 - Use After Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
by Google Security Research
CVSS 8.8