Exploitdb Exploits

50,126 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-32432 EXPLOITDB CRITICAL python
CraftCMS - Remote Code Execution
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
by banyamer
CVSS 10.0
CVE-2025-71326 EXPLOITDB HIGH text
AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that execute with high-level system permissions.
by Milad Karimi (Ex3ptionaL)
CVSS 7.8
CVE-2025-67586 EXPLOITDB MEDIUM go
Highlight and Share <= 5.2.0 - Missing Authorization
Missing Authorization vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Highlight and Share: from n/a through <= 5.2.0.
by cydev.turing
CVSS 4.7
CVE-2025-7771 EXPLOITDB HIGH text
ThrottleStop.sys - Privilege Escalation
ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbitrary code in kernel context, resulting in privilege escalation and potential follow-on attacks, such as disabling security software or bypassing kernel-level protections. ThrottleStop.sys version 3.0.0.0 and possibly others are affected. Apply updates per vendor instructions.
by Xavi Beltran
CVE-2025-14018 EXPLOITDB HIGH text
NetBT Consulting Services Inc. E-Fatura <1.2.15 - Path Traversal
Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Libraries. This issue affects e-Fatura: before 1.2.15.
by seccops
CVSS 7.3
EIP-2026-120643 EXPLOITDB text
D-Link DIR-650IN - Authenticated Command Injection
by Sanjay Singh
CVE-2025-65027 EXPLOITDB HIGH text
romm < 4.4.1 - Authenticated Unrestricted File Upload and Stored Cross-Site Scripting via SVG/HTML Files
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malicious SVG or HTML files. When these files are accessed the browser executes embedded JavaScript, leading to stored Cross-Site Scripting (XSS) which when combined with a CSRF misconfiguration they lead to achieve full administrative account takeover, creating a rogue admin account, escalating the attacker account role to admin, and much more. This vulnerability is fixed in 4.4.1 and 4.4.1-beta.2.
by mmohammedheshamm
CVSS 7.6
CVE-2025-55182 EXPLOITDB CRITICAL python
React Server Components <19.2.0 - RCE
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
by danieljavanrad
CVSS 10.0
EIP-2026-120679 EXPLOITDB python
Jumbo Website Manager - Remote Code Execution
by Mirabbas Ağalarov
EIP-2026-120637 EXPLOITDB python
ZSH 5.9 - RCE
by sinanadilrana
CVE-2025-6965 EXPLOITDB CRITICAL python
SQLite < 3.50.2 - Memory Corruption via Aggregate Terms Overflow
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
by Mohammed Idrees Banyamer
CVSS 9.8
CVE-2025-11001 EXPLOITDB HIGH python
7-Zip - Remote Code Execution via Symbolic Link Traversal in ZIP File Parsing
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26753.
by Mohammed Idrees Banyamer
CVSS 7.8
CVE-2025-26633 EXPLOITDB HIGH python
Microsoft Management Console - Auth Bypass
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
by Mohammed Idrees Banyamer
CVSS 7.0
CVE-2023-33177 EXPLOITDB HIGH python
Xibo CMS <2.3.17-3.3.5 - Path Traversal
Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded to the CMS via the layout import function by an authenticated user which would allow creation of files outside of the CMS library directory as the webserver user. This can be used to upload a PHP webshell inside the web root directory and achieve remote code execution as the webserver user. Users should upgrade to version 2.3.17 or 3.3.5, which fix this issue. Customers who host their CMS with Xibo Signage have already received an upgrade or patch to resolve this issue regardless of the CMS version that they are running.
by complexusprada
CVSS 8.8
CVE-2025-48868 EXPLOITDB HIGH python
Horilla 1.3.0 - Authenticated Remote Code Execution via Eval Injection in project_bulk_archive
Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the project_bulk_archive view. This allows privileged users (e.g., administrators) to execute arbitrary system commands on the server. While having Django’s DEBUG=True makes exploitation visibly easier by returning command output in the HTTP response, this is not required. The vulnerability can still be exploited in DEBUG=False mode by using blind payloads such as a reverse shell, leading to full remote code execution. This issue has been patched in version 1.3.1.
by nakleh
CVSS 7.2
CVE-2025-64446 EXPLOITDB CRITICAL python
Fortinet FortiWeb unauthenticated RCE
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
by Mohammed Idrees Banyamer
CVSS 9.8
CVE-2025-62215 EXPLOITDB HIGH text
Windows Kernel - Use-After-Free via Race Condition
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
by E1 Coders
CVSS 7.0
CVE-2025-59254 EXPLOITDB HIGH text
Windows 10/11, Server 2016 - Privilege Escalation via Heap Overflow
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
by nu11secur1ty
CVSS 7.8
CVE-2025-4524 EXPLOITDB CRITICAL text
Madara WordPress <2.2.2 - Local File Inclusion
The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
by Beatriz Fresno Naumova
CVSS 9.8
EIP-2026-120683 EXPLOITDB text
WBCE CMS 1.6.4 - Remote Code Execution
by red
EIP-2026-120682 EXPLOITDB text
RiteCMS 3.1.0 - Authenticated Remote Code Execution
by red
CVE-2025-55315 EXPLOITDB CRITICAL python
ASP.NET Core 2.3.0-2.3.5 - HTTP Request Smuggling via Inconsistent Request Interpretation
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
by Mohammed Idrees Banyamer
CVSS 9.9
EIP-2026-120677 EXPLOITDB text
is-localhost-ip 2.0.0 - SSRF
by nu11secur1ty
CVE-2025-34040 EXPLOITDB CRITICAL text
Zhiyuan OA Web Application System - Unauthenticated Arbitrary File Upload and Remote Code Execution via wpsAssistServlet
An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of intended directories using path traversal. Successful exploitation enables remote code execution as the uploaded file can be accessed and executed through the web server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-01 UTC.
by Beatriz Fresno Naumova
CVE-2025-4123 EXPLOITDB HIGH text
Grafana < 10.4.18 - XSS
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
by Beatriz Fresno Naumova
CVSS 7.6