Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-117329 EXPLOITDB text
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed 15.1.0.0096 - Unquoted Service Path Privilege Escalation
by Joey Lane
EIP-2026-117327 EXPLOITDB text
Intel(R) Management Engine Components 8.0.1.1399 - Unquoted Service Path Privilege Escalation
by Joey Lane
EIP-2026-117273 EXPLOITDB python
HikVision Security Systems - Activex Buffer Overflow
by Yuriy Gurkin
EIP-2026-114432 EXPLOITDB python
XhP CMS 0.5.1 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
by Ahsan Tahir
EIP-2026-107879 EXPLOITDB text
Intel(R) PROSet/Wireless WiFi Software 15.01.1000.0927 - Unquoted Service Path Privilege Escalation
by Joey Lane
EIP-2026-106040 EXPLOITDB html
CNDSOFT 2.3 - Cross-Site Request Forgery / Arbitrary File Upload
by Besim
CVE-2016-5195 EXPLOITDB HIGH c VERIFIED
Linux Kernel 2.x-4.x < 4.8.3 - Local Privilege Escalation via Dirty COW Race Condition
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
by Phil Oester
CVSS 7.0
CVE-2011-1249 EXPLOITDB c VERIFIED
Microsoft Windows - Local Privilege Escalation via AFD.sys Input Validation
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
by Tomislav Paskalev
CVE-2016-7185 EXPLOITDB HIGH VERIFIED
Microsoft Windows - Local Privilege Escalation via Win32k Kernel-Mode Driver
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." a different vulnerability than CVE-2016-3266, CVE-2016-3376, and CVE-2016-7211.
by Google Security Research
CVSS 7.8
CVE-2016-0073 EXPLOITDB MEDIUM VERIFIED
Windows Kernel - Local Privilege Escalation via Registry API Call
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0075.
by Google Security Research
CVSS 5.0
CVE-2016-0075 EXPLOITDB MEDIUM VERIFIED
Microsoft Windows 8.1/10, Server 2012, RT 8.1 - Local Privilege Escalation via Registry API
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0073.
by Google Security Research
CVSS 5.5
EIP-2026-117398 EXPLOITDB python VERIFIED
LanSpy 2.0.0.155 - Local Buffer Overflow
by n30m1nd
EIP-2026-111357 EXPLOITDB python
Pluck CMS 4.7.3 - Cross-Site Request Forgery (Add Page)
by Ahsan Tahir
EIP-2026-104572 EXPLOITDB python VERIFIED
The Unarchiver 3.11.1 - '.tar.Z' Crash (PoC)
by Antonio Z.
EIP-2026-102407 EXPLOITDB text
ManageEngine ServiceDesk Plus 9.2 Build 9207 - Unauthorized Information Disclosure
by p0z
EIP-2026-100770 EXPLOITDB perl VERIFIED
Cgiemail 1.6 - Source Code Disclosure
by Finbar Crago
CVE-2016-20056 EXPLOITDB HIGH text
Spy Emergency build 23.0.205 Unquoted Service Path Privilege Escalation
Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
by Amir.ght
CVSS 7.8
CVE-2016-7188 EXPLOITDB HIGH c++ VERIFIED
Windows 10 - Privilege Escalation via Standard Collector Service Library Loading
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability."
by Google Security Research
CVSS 7.8
EIP-2026-112465 EXPLOITDB text VERIFIED
Subrion CMS 4.0.5 - Cross-Site Request Forgery Bypass / Persistent Cross-Site Scripting
by Ahsan Tahir
EIP-2026-110657 EXPLOITDB text
PHP Business Directory - Multiple Vulnerabilities
by larrycompress
CVE-2016-0752 EXPLOITDB HIGH ruby VERIFIED
Ruby on Rails Dynamic Render File Upload Remote Code Execution
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
by Metasploit
CVSS 7.5
EIP-2026-110768 EXPLOITDB text VERIFIED
PHP Telephone Directory - Multiple Vulnerabilities
by larrycompress
EIP-2026-110734 EXPLOITDB html
PHP NEWS 1.3.0 - Cross-Site Request Forgery (Add Admin)
by Meryem AKDOĞAN
EIP-2026-110708 EXPLOITDB text
PHP Image Database - Multiple Vulnerabilities
by larrycompress
CVE-2016-6187 EXPLOITDB HIGH c
Linux kernel <4.6.5 - Privilege Escalation
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.
by Vitaly Nikolenko
CVSS 7.8