Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-110921 EXPLOITDB php
phpATM 1.32 (Windows) - Arbitrary File Upload / Remote Command Execution
by Paolo Massenio
EIP-2026-103180 EXPLOITDB ruby VERIFIED
op5 7.1.9 - Configuration Command Execution (Metasploit)
by Metasploit
CVE-2025-34113 EXPLOITDB HIGH text VERIFIED
Tiki Wiki CMS <14.1-6.14 - Command Injection
An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET parameter in `tiki-calendar.php`. When the calendar module is enabled and an authenticated user has permission to access it, an attacker can inject and execute arbitrary PHP code. Successful exploitation leads to remote code execution in the context of the web server user.
by Dany Ouellet
EIP-2026-119373 EXPLOITDB text
Gemalto Sentinel License Manager 18.0.1.55505 - Directory Traversal
by LiquidWorm
EIP-2026-114990 EXPLOITDB text VERIFIED
Blat 3.2.14 - Stack Overflow
by Vishnu
EIP-2026-112215 EXPLOITDB html
SlimCMS 0.1 - Cross-Site Request Forgery (Change Admin Password)
by Avinash Thapa
EIP-2026-111804 EXPLOITDB text
Roxy Fileman 1.4.4 - Arbitrary File Upload
by Tyrell Sassen
CVE-2016-3643 EXPLOITDB HIGH text
SolarWinds Virtualization Manager <6.3.1 - Privilege Escalation
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."
by Nate Kettlewell
CVSS 7.8
EIP-2026-101534 EXPLOITDB text
ATCOM PBX IP01 / IP08 / IP4 / IP2G4A - Authentication Bypass
by i-Hmx
EIP-2026-116729 EXPLOITDB text
AdobeUpdateService 3.6.0.248 - Unquoted Service Path Privilege Escalation
by Cyril Vallicari
CVE-2016-0173 EXPLOITDB HIGH text VERIFIED
Windows - Local Privilege Escalation via Win32k Bitmap Use-After-Free
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0171, CVE-2016-0174, and CVE-2016-0196.
by Nils Sommer
CVSS 7.8
CVE-2016-0171 EXPLOITDB HIGH text VERIFIED
Windows Kernel-Mode Drivers - Local Privilege Escalation via Crafted Application
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0173, CVE-2016-0174, and CVE-2016-0196.
by Nils Sommer
CVSS 7.8
EIP-2026-113170 EXPLOITDB text
w2wiki - Multiple Cross-Site Scripting Vulnerabilities
by HaHwul
EIP-2026-112892 EXPLOITDB text
Ultrabenosaurus ChatBoard - Persistent Cross-Site Scripting
by HaHwul
EIP-2026-112891 EXPLOITDB html
Ultrabenosaurus ChatBoard - Cross-Site Request Forgery (Send Message)
by HaHwul
EIP-2026-111124 EXPLOITDB python
PHPLive 4.4.8 < 4.5.4 - Password Recovery SQL Injection
by Tiago Carvalho
EIP-2026-108337 EXPLOITDB text VERIFIED
Joomla! Component com_enmasse 5.1 < 6.4 - SQL Injection
by Hamed Izadi
EIP-2026-108067 EXPLOITDB text
jbFileManager - Directory Traversal
by HaHwul
EIP-2026-106507 EXPLOITDB text
Dokeos 2.2.1 - Blind SQL Injection
by Mormoroth
EIP-2026-105591 EXPLOITDB text
BookingWizz Booking System < 5.5 - Multiple Vulnerabilities
by Mehmet Ince
CVE-2015-0935 EXPLOITDB ruby
Bomgar Remote Support < 14.3.2 - Remote Code Execution via PHP Deserialization
Bomgar Remote Support before 15.1.1 allows remote attackers to execute arbitrary PHP code via crafted serialized data to unspecified PHP scripts.
by Markus Wulftange
EIP-2026-102617 EXPLOITDB text VERIFIED
Google Chrome - GPU Process MailboxManagerImpl Double-Read
by Google Security Research
EIP-2026-101791 EXPLOITDB text
Hyperoptic (Tilgin) Router HG23xx - Multiple Vulnerabilities
by LiquidWorm
EIP-2026-116017 EXPLOITDB python VERIFIED
Oracle Orakill.exe 11.2.0 - Buffer Overflow (PoC)
by hyp3rlinx
EIP-2026-114072 EXPLOITDB php
WordPress Plugin Social Stream 1.5.15 - wp_options Overwrite
by wp0Day.com