Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-6367 EXPLOITDB HIGH python
Cerberus FTP Server 8.0.10.1 - Denial of Service via Long Host Header
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.
by Peter Baris
CVSS 7.5
EIP-2026-112429 EXPLOITDB text
Steam Profile Integration 2.0.11 - SQL injection
by DrWhat
EIP-2026-105721 EXPLOITDB text
Car Workshop System - SQL Injection
by Ihsan Sencan
EIP-2026-102943 EXPLOITDB text VERIFIED
Oracle VM VirtualBox - Cooperating VMs can Escape from Shared Folder
by Google Security Research
CVE-2016-6277 EXPLOITDB HIGH ruby VERIFIED
NETGEAR D6220/D6400/R6250/R6400/R6700/R6900/R7000/R7100LG/R7300DST/R7900/R8000 Firmware - Remote Code Execution
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.
by Metasploit
CVSS 8.8
CVE-2017-8367 EXPLOITDB HIGH python VERIFIED
Ether Software Easy MOV Converter 1.4.24 - Buffer Overflow via Long Username
Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burner, Easy RM RMVB to DVD Burner, Easy CD DVD Copy, MP3/AVI/MPEG/WMV/RM to Audio CD Burner, MP3/WAV/OGG/WMA/AC3 to CD Burner, MP3 WAV to CD Burner, My Video Converter, Easy AVI DivX Converter, Easy Video to iPod Converter, Easy Video to PSP Converter, Easy Video to 3GP Converter, Easy Video to MP4 Converter, and Easy Video to iPod/MP4/PSP/3GP Converter allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long username.
by Muhann4d
CVSS 7.8
CVE-2016-4657 EXPLOITDB HIGH html
iPhone OS < 9.3.5 - Remote Code Execution via WebKit Memory Corruption
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
by qwertyoruiop
CVSS 8.8
EIP-2026-119525 EXPLOITDB c++ VERIFIED
Fortinet FortiClient 5.2.3 (Windows 10 x86) - Local Privilege Escalation
by sickness
CVE-2017-6805 EXPLOITDB MEDIUM text VERIFIED
MobaXterm Personal Edition 9.4 - Path Traversal
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET command.
by hyp3rlinx
CVSS 5.3
EIP-2026-114520 EXPLOITDB text
Yellow Pages Script 3.2 - 'category_id' SQL Injection
by Ihsan Sencan
EIP-2026-114499 EXPLOITDB text
Yacht Listing Script 2.0 - SQL Injection
by Ihsan Sencan
EIP-2026-112955 EXPLOITDB text
Vanelo - SQL Injection
by Ihsan Sencan
EIP-2026-112788 EXPLOITDB text
Travel Tours Script 2.0 - SQL Injection
by Ihsan Sencan
EIP-2026-111551 EXPLOITDB text
Property Listing Script 3.1 - SQL Injection
by Ihsan Sencan
EIP-2026-110702 EXPLOITDB text
PHP Forum Script 3.0 - SQL Injection
by Ihsan Sencan
EIP-2026-110555 EXPLOITDB text
Pet Listing Script 3.0 - SQL Injection
by Ihsan Sencan
EIP-2026-109493 EXPLOITDB text
Mirage - SQL Injection
by Ihsan Sencan
EIP-2026-107427 EXPLOITDB text
Global In - SQL Injection
by Ihsan Sencan
EIP-2026-107426 EXPLOITDB text
Global In - Arbitrary File Upload
by Ihsan Sencan
CVE-2017-6823 EXPLOITDB HIGH text
Fiyo CMS 2.0.6.1 - Privilege Escalation
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.
by rungga_reksya
CVSS 8.8
EIP-2026-106532 EXPLOITDB text
Domain Marketplace Script - SQL Injection
by Ihsan Sencan
CVE-2017-6528 EXPLOITDB HIGH text
dnaTools dnaLIMS 4-2015s13 - Insufficiently Protected Credentials in Password Storage
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file).
by Shorebreak Security
CVSS 8.1
CVE-2017-6527 EXPLOITDB HIGH text
dnaTools dnaLIMS 4-2015s13 - Unauthenticated Path Traversal via viewAppletFsa.cgi seqID Parameter
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID parameter).
by Shorebreak Security
CVSS 7.5
CVE-2017-6526 EXPLOITDB CRITICAL text
dnaTools dnaLIMS 4-2015s13 - Unauthenticated Remote Code Execution via sysAdmin.cgi
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests).
by Shorebreak Security
CVSS 9.8
EIP-2026-119687 EXPLOITDB html
WatchGuard XTMv 11.12 Build 516911 - User Management Cross-Site Request Forgery
by KoreLogic