Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112130 EXPLOITDB text VERIFIED
Simple PHP Blog 0.8.4 - Cross-Site Request Forgery (Add Admin)
by Besim
EIP-2026-106891 EXPLOITDB text
Entrepreneur Job Portal Script 2.06 - SQL Injection
by OoN_Boy
CVE-2016-20090 EXPLOITDB HIGH text VERIFIED
Comodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service Path
Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot.
by Th3GundY
CVSS 7.8
CVE-2016-20088 EXPLOITDB HIGH text VERIFIED
Comodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege Escalation
Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot.
by Th3GundY
CVSS 7.8
EIP-2026-110670 EXPLOITDB text VERIFIED
PHP Classifieds Rental Script - Blind SQL Injection
by OoN_Boy
EIP-2026-109514 EXPLOITDB text VERIFIED
MLM Unilevel Plan Script 1.0.2 - SQL Injection
by N4TuraL
EIP-2026-108939 EXPLOITDB text VERIFIED
Just Dial Clone Script - 'fid' SQL Injection
by OoN_Boy
EIP-2026-105356 EXPLOITDB text VERIFIED
B2B Portal Script - Blind SQL Injection
by OoN_Boy
EIP-2026-104972 EXPLOITDB text VERIFIED
Advance MLM Script - SQL Injection
by OoN_Boy
EIP-2026-101268 EXPLOITDB text
Exagate WEBPack Management System - Multiple Vulnerabilities
by Halil Dalabasmaz
EIP-2026-101183 EXPLOITDB python
Billion 7700NR4 Router - Remote Command Execution
by R-73eN
CVE-2016-20087 EXPLOITDB HIGH text VERIFIED
Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the service binary path. Attackers can insert malicious executables in the system root path that execute with SYSTEM privileges during service startup or system reboot.
by Tulpa
CVSS 7.8
EIP-2026-119261 EXPLOITDB python VERIFIED
VX Search Enterprise 9.0.26 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-119190 EXPLOITDB python VERIFIED
Sync Breeze Enterprise 8.9.24 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-118441 EXPLOITDB python VERIFIED
Dup Scout Enterprise 9.0.28 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-118423 EXPLOITDB python VERIFIED
Disk Sorter Enterprise 9.0.24 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-118419 EXPLOITDB python VERIFIED
Disk Savvy Enterprise 9.0.32 - 'Login' Remote Buffer Overflow
by Tulpa
EIP-2026-116709 EXPLOITDB text VERIFIED
Abyss Web Server X1 2.11.1 - Unquoted Service Path Privilege Escalation
by Tulpa
EIP-2026-111268 EXPLOITDB text
Picosafe Web GUI - Multiple Vulnerabilities
by Shahab Shamsi
CVE-2016-6434 EXPLOITDB HIGH text
Cisco Firepower Management Center 6.0.1 - Info Disclosure
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.
by KoreLogic
CVSS 7.8
EIP-2026-100935 EXPLOITDB python
Witbe - Remote Code Execution
by BeLmar
CVE-2016-6433 EXPLOITDB HIGH text VERIFIED
Cisco Firepower Mgmt Cntr <6.0.1 - RCE
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
by KoreLogic
CVSS 8.8
CVE-2016-6435 EXPLOITDB MEDIUM text
Cisco Firepower Management Center 6.0.1 - Info Disclosure
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
by KoreLogic
CVSS 6.5
EIP-2026-109275 EXPLOITDB text
Mambo < 4.5.4 - SQL Injection
by GulfTech Security
CVE-2016-2776 EXPLOITDB HIGH python
Oracle Linux < 9.9.9 - Improper Input Validation
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
by Infobyte
CVSS 7.5