Exploitdb Exploits

49,996 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-25142 EXPLOITDB CRITICAL text
NovaRad NovaPACS Diagnostics Viewer <8.5.19.75 - XXE Injection
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.
by LiquidWorm
CVSS 9.8
CVE-2018-0437 EXPLOITDB HIGH c
Cisco Umbrella Enterprise Roaming Client < 2.1.118 - Improper Privilege Management
A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system permissions, which could allow non-administrative users to place files within restricted directories. An attacker could exploit this vulnerability by placing an executable file within the restricted directory, which when executed by the ERC client, would run with Administrator privileges.
by ParagonSec
CVSS 7.8
CVE-2018-0438 EXPLOITDB HIGH c
Cisco Umbrella Enterprise Roaming Client - Improper Input Validation
A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system permissions, which could allow non-administrative users to place files within restricted directories. An attacker could exploit this vulnerability by placing an executable file within the restricted directory, which when executed by the ERC client, would run with Administrator privileges.
by ParagonSec
CVSS 7.8
CVE-2018-15917 EXPLOITDB MEDIUM text
Jorani - XSS
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
by Javier Olmedo
CVSS 5.4
CVE-2018-15918 EXPLOITDB MEDIUM text VERIFIED
Jorani - SQL Injection
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.
by Javier Olmedo
CVSS 5.4
CVE-2014-0030 EXPLOITDB CRITICAL python
Apache Roller <5.0.3 - XXE
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
by Marko Jokic
CVSS 9.8
CVE-2018-16059 EXPLOITDB MEDIUM text
Endress Wirelesshart Fieldgate Swg70 Firmware - Path Traversal
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
by Hamit CİBO
CVSS 5.3
EIP-2026-101626 EXPLOITDB text
D-Link Dir-600M N150 - Cross-Site Scripting
by PUNIT DARJI
CVE-2018-16709 EXPLOITDB CRITICAL python
Fuji Xerox Devices - Info Disclosure
Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V C5576, DocuCentre-IV C2263, DocuCentre-V C2263, and ApeosPort-V 5070 devices allow remote attackers to read or write to files via crafted PJL commands.
by vr_system
CVSS 9.8
EIP-2026-119594 EXPLOITDB text
Microsoft People 10.1807.2131.0 - Denial of service (PoC)
by L0RD
CVE-2018-14497 EXPLOITDB MEDIUM text
Tenda D152 - XSS
Tenda D152 ADSL routers allow XSS via a crafted SSID.
by Sandip Dey
CVSS 5.4
CVE-2018-19457 EXPLOITDB HIGH text
Logicspice FAQ Script <2.9.7 - Command Injection
Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.
by AkkuS
CVSS 7.2
CVE-2018-17110 EXPLOITDB CRITICAL text
Simple POS 4.0.24 - SQL Injection
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.
by Renos Nikolaou
CVSS 9.8
EIP-2026-119534 EXPLOITDB python
iSmartViewPro 1.5 - 'DDNS' Buffer Overflow
by Luis Martínez
EIP-2026-119533 EXPLOITDB python
iSmartViewPro 1.5 - 'DDNS' Buffer Overflow
by Luis Martínez
EIP-2026-110696 EXPLOITDB text
PHP File Browser Script 1 - Directory Traversal
by AkkuS
EIP-2026-109589 EXPLOITDB text
mooSocial Store Plugin 2.6 - SQL Injection
by Andrea Bocchetti
EIP-2026-103318 EXPLOITDB python
RPi Cam Control < 6.4.25 - 'preview.php' Remote Command Execution
by Reigning Shells
CVE-2018-25246 EXPLOITDB HIGH python VERIFIED
Wikipedia 12.0 Denial of Service via Search
Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated characters into the search bar to trigger an application crash.
by 0xB9
CVSS 7.5
CVE-2018-25207 EXPLOITDB HIGH text
Online Quiz Maker 1.0 SQL Injection via catid Parameter
Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in POST parameters to extract sensitive database information or bypass authentication.
by AkkuS
CVSS 7.1
EIP-2026-119620 EXPLOITDB python VERIFIED
Visual Ping 0.8.0.0 - 'Host' Denial of Service (PoC)
by Uriel Corral Salinas
CVE-2018-16252 EXPLOITDB LOW text
Fspro Event Log Explorer - XXE
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
by hyp3rlinx
CVSS 3.3
EIP-2026-116513 EXPLOITDB python VERIFIED
VSAXESS V2.6.2.70 build 20171226_053 - 'Nickname' Denial of Service (PoC)
by Diego Santamaria
EIP-2026-115797 EXPLOITDB python VERIFIED
Microsoft Windows Explorer Out-of-Bound Read - Denial of Service (PoC)
by Ghaaf
EIP-2026-115796 EXPLOITDB python VERIFIED
Microsoft Windows Explorer Out-of-Bound Read - Denial of Service (PoC)
by Ghaaf