Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-111203 EXPLOITDB text
PHPShell 2.4 - Session Fixation
by hyp3rlinx
CVE-2017-6097 EXPLOITDB HIGH text
Mail Masta 1.0 - Authenticated SQL Injection via camp_id Parameter
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.
by Hanley Shun
CVSS 7.2
CVE-2017-6096 EXPLOITDB HIGH text
Mail Masta 1.0 - Authenticated SQL Injection via Filter List Parameter
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.
by Hanley Shun
CVSS 7.2
CVE-2017-6095 EXPLOITDB CRITICAL text
Mail Masta 1.0 - Unauthenticated SQL Injection via list_id Parameter
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.
by Hanley Shun
CVSS 9.8
CVE-2017-5496 EXPLOITDB CRITICAL text
Sawmill Enterprise 8.7.9 - Authentication Bypass via Password Hash
Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
by hyp3rlinx
CVSS 9.8
CVE-2017-6098 EXPLOITDB HIGH text
Mail Masta 1.0 - Authenticated SQL Injection via list_id Parameter
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.
by Hanley Shun
CVSS 7.2
EIP-2026-108849 EXPLOITDB text
Joomla! Component Room Management 1.0 - SQL Injection
by Ihsan Sencan
EIP-2026-108819 EXPLOITDB text
Joomla! Component OS Services Booking 2.5.1 - SQL Injection
by Ihsan Sencan
EIP-2026-108818 EXPLOITDB text
Joomla! Component OS Property 3.0.8 - SQL Injection
by Ihsan Sencan
EIP-2026-108797 EXPLOITDB text
Joomla! Component Most Wanted Real Estate 1.1.0 - SQL Injection
by Ihsan Sencan
EIP-2026-108746 EXPLOITDB text
Joomla! Component Joomloc-Lite 1.3.2 - 'site_id' SQL Injection
by Ihsan Sencan
EIP-2026-108745 EXPLOITDB text
Joomla! Component Joomloc-CAT 4.1.3 - 'ville' SQL Injection
by Ihsan Sencan
EIP-2026-108734 EXPLOITDB text
Joomla! Component JomWALL 4.0 - 'wuid' SQL Injection
by Ihsan Sencan
EIP-2026-108662 EXPLOITDB text
Joomla! Component Google Map Store Locator 4.4 - SQL Injection
by Ihsan Sencan
EIP-2026-108639 EXPLOITDB text
Joomla! Component EShop 2.5.1 - 'id' SQL Injection
by Ihsan Sencan
EIP-2026-108220 EXPLOITDB text
Joomla! Component Bazaar Platform 3.0 - SQL Injection
by Ihsan Sencan
CVE-2017-6077 EXPLOITDB CRITICAL python
NETGEAR DGN2200 Firmware < 10.0.0.50 - Authenticated OS Command Injection via ping_IPAddr Parameter
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
by SivertPL
CVSS 9.8
EIP-2026-108899 EXPLOITDB text
Joomla! Component WMT Content Timeline 1.0 - 'id' SQL Injection
by Ihsan Sencan
EIP-2026-108880 EXPLOITDB text
Joomla! Component Team Display 1.2.1 - 'filter_category' SQL Injection
by Ihsan Sencan
EIP-2026-108664 EXPLOITDB text
Joomla! Component Groovy Gallery 1.0.0 - SQL Injection
by Ihsan Sencan
CVE-2017-6060 EXPLOITDB HIGH text VERIFIED
MuPDF - Stack-based Buffer Overflow in jstest_main.c
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.
by Agostino Sarubbo
CVSS 7.8
EIP-2026-113658 EXPLOITDB text VERIFIED
WordPress Plugin Corner Ad 1.0.7 - Cross-Site Scripting
by Atik Rahman
EIP-2026-108871 EXPLOITDB text
Joomla! Component Spider FAQ Lite 1.3.1 - SQL Injection
by Ihsan Sencan
EIP-2026-108869 EXPLOITDB text
Joomla! Component Spider Facebook 1.6.1 - SQL Injection
by Ihsan Sencan
EIP-2026-108867 EXPLOITDB text
Joomla! Component Spider Catalog Lite 1.8.10 - SQL Injection
by Ihsan Sencan