Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113199 EXPLOITDB text
wdCalendar 2 - SQL Injection
by Alfonso Castillo Angel
EIP-2026-106151 EXPLOITDB text VERIFIED
Contrexx CMS egov Module 1.0.0 - SQL Injection
by hamidreza borghei
CVE-2015-8309 EXPLOITDB MEDIUM python VERIFIED
Cherry Music <0.36.0 - Path Traversal
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
by feedersec
CVSS 4.3
CVE-2016-6854 EXPLOITDB MEDIUM text
Open-Xchange OX Guard < 2.4.2 - Stored Cross-Site Scripting via PGP Signature Verification
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
by Benjamin Daniel Mussler
CVSS 6.1
CVE-2016-5740 EXPLOITDB MEDIUM text
Open-Xchange OX App Suite <7.8.2-rev5 - RCE
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment's location, will be presented to the user at the E-Mail App, depending on the invitation workflow. This code gets executed within the context of the user's current session. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).
by Jakub A>>oczek
CVSS 6.1
EIP-2026-100909 EXPLOITDB bash
Tenda ADSL2/2+ Modem 963281TAN - DNS Change
by Todor Donev
EIP-2026-100878 EXPLOITDB bash
PLANET VDR-300NU ADSL Router - DNS Change
by Todor Donev
EIP-2026-100877 EXPLOITDB bash
PIKATEL 96338WS_ 96338L-2M-8M - DNS Change
by Todor Donev
EIP-2026-100827 EXPLOITDB bash
Inteno EG101R1 VoIP Router - DNS Change
by Todor Donev
EIP-2026-100798 EXPLOITDB bash
Exper EWM-01 ADSL/MODEM - DNS Change
by Todor Donev
EIP-2026-100780 EXPLOITDB bash
COMTREND ADSL Router CT-5367 C01_R12 / CT-5624 C01_R03 - DNS Change
by Todor Donev
EIP-2026-100738 EXPLOITDB bash
ASUS DSL-X11 ADSL Router - DNS Change
by Todor Donev
CVE-2016-6662 EXPLOITDB CRITICAL python
Oracle MySQL, MariaDB, Percona Server - Privilege Escalation via my.cnf
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
by Dawid Golunski
CVSS 9.8
EIP-2026-104623 EXPLOITDB text
Airmail 3.0.2 - Cross-Site Scripting
by redrain
EIP-2026-103153 EXPLOITDB python
LamaHub 0.0.6.2 - Remote Buffer Overflow
by Pi3rrot
EIP-2026-102106 EXPLOITDB python
Vodafone Mobile Wifi - Reset Admin Password
by Daniele Linguaglossa
EIP-2026-119639 EXPLOITDB python
LogMeIn Client 1.3.2462 (x64) - Local Credentials Disclosure
by Yakir Wizman
EIP-2026-119631 EXPLOITDB python
Dropbox Desktop Client 9.4.49 (x64) - Local Credentials Disclosure
by Yakir Wizman
EIP-2026-116802 EXPLOITDB python
Apple iCloud Desktop Client 5.2.1.0 - Local Credentials Disclosure
by Yakir Wizman
EIP-2026-114562 EXPLOITDB python
Zabbix 2.0 < 3.0.3 - SQL Injection
by Zzzians
EIP-2026-108112 EXPLOITDB text
Jobberbase 2.0 - Multiple Vulnerabilities
by Ross Marks
CVE-2016-4232 EXPLOITDB HIGH text VERIFIED
Adobe Flash Player <18.0.0.366,19.x-22.x - Info Disclosure
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information from process memory via unspecified vectors.
by Google Security Research
CVSS 7.5
CVE-2016-4231 EXPLOITDB HIGH text VERIFIED
Adobe Flash Player <22.0.0.209 - Use After Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4222, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-4229, CVE-2016-4230, and CVE-2016-4248.
by Google Security Research
CVSS 8.8
CVE-2016-3861 EXPLOITDB HIGH text VERIFIED
Android <4.4.4, <5.0.2, <5.1.1, <2016-09-01 - RCE
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted file, aka internal bug 29250543.
by Google Security Research
CVSS 7.8
CVE-2025-25034 EXPLOITDB CRITICAL ruby
SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection
A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the SugarRestSerialize.php script. The vulnerable code fails to sanitize the rest_data parameter before passing it to the unserialize() function. This allows an unauthenticated attacker to submit crafted serialized data containing malicious object declarations, resulting in arbitrary code execution within the application context. Although SugarCRM released a prior fix in advisory sugarcrm-sa-2016-001, the patch was incomplete and failed to address some vectors. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-13 UTC.
by Egidio Romano