Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-117570 EXPLOITDB text VERIFIED
Microsoft Windows Media Center 6.1.7600 - 'ehshell.exe' XML External Entity Injection
by hyp3rlinx
EIP-2026-117486 EXPLOITDB text
Microsoft Excel Starter 2010 - XML External Entity Injection
by hyp3rlinx
EIP-2026-117477 EXPLOITDB text VERIFIED
Microsoft Authorization Manager 6.1.7601 - 'azman' XML External Entity Injection
by hyp3rlinx
EIP-2026-101184 EXPLOITDB python
BlackStratus LOGStorm 4.5.1.35/4.5.1.96 - Remote Code Execution
by Jeremy Brown
EIP-2026-112228 EXPLOITDB text
Smart Guard Network Manager 6.3.2 - SQL Injection
by Rahul Raz
EIP-2026-102128 EXPLOITDB text
Xfinity Gateway - Remote Code Execution
by Gregory Smiley
EIP-2026-118420 EXPLOITDB python VERIFIED
Disk Savvy Enterprise 9.1.14 - 'GET' Remote Buffer Overflow
by vportal
EIP-2026-118013 EXPLOITDB
Tor (Firefox 41 < 50) - Code Execution
by 649
CVE-2017-9417 EXPLOITDB CRITICAL text
Broadcom BCM43xx Wi-Fi Firmware Broadpwn - Remote Code Execution
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.
by 649
CVSS 9.8
CVE-2016-20064 EXPLOITDB MEDIUM text VERIFIED
WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter
WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attackers can supply directory traversal sequences through the wpv-image GET parameter to access sensitive files like system configuration and credentials.
by Lenon Leite
CVSS 6.2
EIP-2026-116601 EXPLOITDB python VERIFIED
Xitami Web Server 5.0a0 - Denial of Service
by sm
EIP-2026-102127 EXPLOITDB text
Xfinity Gateway - Cross-Site Request Forgery
by Pabstersac
EIP-2026-118129 EXPLOITDB java VERIFIED
WinPower 4.9.0.4 - Local Privilege Escalation
by Kacper Szurek
EIP-2026-119262 EXPLOITDB python VERIFIED
VX Search Enterprise 9.1.12 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-119191 EXPLOITDB python VERIFIED
Sync Breeze Enterprise 9.1.16 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-118442 EXPLOITDB python VERIFIED
Dup Scout Enterprise 9.1.14 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-118424 EXPLOITDB python VERIFIED
Disk Sorter Enterprise 9.1.12 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-118421 EXPLOITDB python VERIFIED
Disk Savvy Enterprise 9.1.14 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-118410 EXPLOITDB python VERIFIED
Disk Pulse Enterprise 9.1.16 - 'Login' Remote Buffer Overflow
by Tulpa
CVE-2016-0063 EXPLOITDB HIGH text VERIFIED
Microsoft Internet Explorer 9-11 - Remote Code Execution via Memory Corruption
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0067, and CVE-2016-0072.
by Skylined
CVSS 8.8
CVE-2015-0050 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 8 and 9 - Remote Code Execution or Denial of Service via Memory Corruption
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-8967 and CVE-2015-0044.
by Skylined
EIP-2026-115678 EXPLOITDB html
Microsoft Internet Explorer 11 - MSHTML 'CGenerated­Content::Has­Generated­SVGMarker' Type Confusion
by Skylined
CVE-2013-3120 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 10 - Memory Corruption
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3125.
by Skylined
CVE-2016-5195 EXPLOITDB HIGH c VERIFIED
Linux Kernel 2.x-4.x < 4.8.3 - Local Privilege Escalation via Dirty COW Race Condition
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
by FireFart
CVSS 7.0
CVE-2015-7855 EXPLOITDB MEDIUM python VERIFIED
ntp 4.2.0-4.2.8 - Denial of Service via Long Data Value in Mode 6 or 7 Packet
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.
by Magnus Klaaborg Stubman
CVSS 6.5