Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
CVE-2016-7083 EXPLOITDB HIGH text VERIFIED
VMware Workstation Pro and Player 12.x - Remote Code Execution via Cortado ThinPrint EMFSPOOL TrueType Fonts
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via TrueType fonts embedded in EMFSPOOL.
by Google Security Research
CVSS 7.8
CVE-2016-7084 EXPLOITDB HIGH text VERIFIED
VMware Workstation Player 12.x - Remote Code Execution via JPEG 2000 Image
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via a JPEG 2000 image.
by Google Security Research
CVSS 7.8
EIP-2026-114629 EXPLOITDB text
ZineBasic 1.1 - Arbitrary File Disclosure
by bd0rk
EIP-2026-113943 EXPLOITDB text
WordPress Plugin Order Export Import for WooCommerce - Order Information Disclosure
by david-peltier
EIP-2026-112033 EXPLOITDB text
ShoreTel Connect ONSITE - Blind SQL Injection
by Iraklis Mathiopoulos
EIP-2026-109701 EXPLOITDB text
MyBB 1.8.6 - SQL Injection
by Curesec Research Team
EIP-2026-108961 EXPLOITDB text
Kajona 4.7 - Cross-Site Scripting / Directory Traversal
by Curesec Research Team
EIP-2026-102822 EXPLOITDB ruby VERIFIED
Docker Daemon - Local Privilege Escalation (Metasploit)
by Metasploit
EIP-2026-100657 EXPLOITDB text
MuM MapEdit 3.2.6.0 - Multiple Vulnerabilities
by Paul Baade & Sven Krewitt
EIP-2026-108833 EXPLOITDB text
Joomla! Component Portfolio Gallery 1.0.6 - SQL Injection
by Larry W. Cashdollar
EIP-2026-108230 EXPLOITDB text
Joomla! Component Catalog 1.0.7 - SQL Injection
by Larry W. Cashdollar
EIP-2026-105186 EXPLOITDB html
AnoBBS 1.0.1 - Remote File Inclusion
by bd0rk
EIP-2026-101198 EXPLOITDB python
Cisco ASA 9.2(3) - 'EXTRABACON' Authentication Bypass
by Sean Dillon
CVE-2016-6253 EXPLOITDB HIGH ruby VERIFIED
NetBSD <7.0 - Local Privilege Escalation
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
by Metasploit
CVSS 7.8
EIP-2026-100199 EXPLOITDB text
Cisco EPC 3925 - Multiple Vulnerabilities
by Patryk Bogdan
EIP-2026-119647 EXPLOITDB python
PrivateTunnel Client 2.7.0 (x64) - Local Credentials Disclosure
by Yakir Wizman
EIP-2026-103846 EXPLOITDB text
Apache Mina 2.0.13 - Remote Command Execution
by Gregory Draperi
EIP-2026-100028 EXPLOITDB text VERIFIED
Google Android - getpidcon Usage binder Service Replacement Race Condition
by Google Security Research
CVE-2016-6853 EXPLOITDB MEDIUM text
Open-Xchange OX Guard < 2.4.2 - Stored Cross-Site Scripting via PGP Public Key Name
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on using a specific URL, such script code might get executed. In case of injecting external websites, users might get lured into a phishing scheme. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
by Benjamin Daniel Mussler
CVSS 6.1
CVE-2016-6851 EXPLOITDB MEDIUM text
Open-Xchange OX Guard < 2.4.2 - Unauthenticated Stored Cross-Site Scripting via Guest Reader Parameter
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users since no prior authentication is needed. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.) in case the user has an active session on the same domain already.
by Benjamin Daniel Mussler
CVSS 6.1
EIP-2026-118195 EXPLOITDB text
Zapya Desktop 1.803 - 'ZapyaService.exe' Local Privilege Escalation
by Arash Khazaei
EIP-2026-118135 EXPLOITDB text
WinSMS 3.43 - Insecure File Permissions Privilege Escalation
by Tulpa
EIP-2026-117652 EXPLOITDB text
Multiple Icecream Apps - Insecure File Permissions Privilege Escalation
by Tulpa
EIP-2026-116884 EXPLOITDB text
Battle.Net 1.5.0.7963 - Insecure File Permissions Privilege Escalation
by Tulpa
EIP-2026-115685 EXPLOITDB html
Microsoft Internet Explorer 11.0.9600.18482 - Use After Free
by Marcin Ressel