Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
CVE-2015-8636 EXPLOITDB HIGH text VERIFIED
Adobe AIR < 20.0.0.233 - Remote Code Execution via Memory Corruption
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8645.
by Google Security Research
CVSS 8.8
CVE-2016-1909 EXPLOITDB CRITICAL python
Fortinet <5.0.12 - Hardcoded Passphrase
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.
by operator8203
CVSS 9.8
EIP-2026-114243 EXPLOITDB text
WordPress Plugin WP Symposium Pro Social Network Plugin 15.12 - Multiple Vulnerabilities
by Rahul Pratap Singh
CVE-2013-7285 EXPLOITDB CRITICAL text
Oracle Endeca Information Discovery Studio - Remote Code Execution via XStream Input Stream Manipulation
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
by Brian D. Hysell
CVSS 9.8
CVE-2015-2049 EXPLOITDB ruby VERIFIED
D-Link DCS-931L Firmware < 1.04 - Authenticated Remote Code Execution via File Upload
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
by Metasploit
EIP-2026-101168 EXPLOITDB text
AVM FRITZ!Box < 6.30 - Remote Buffer Overflow
by RedTeam Pentesting
EIP-2026-101842 EXPLOITDB text
MediaAccess TG788vn - File Disclosure
by 0x4148
CVE-2015-8398 EXPLOITDB MEDIUM text
Confluence < 5.8.16 - Cross-Site Scripting via PATH_INFO to rest/prototype/1/session/check
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
by Sebastian Perez
CVSS 6.1
CVE-2015-7944 EXPLOITDB HIGH perl
Ganeti DoS via SSL Parameter Renegotiation
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote attackers to cause a denial of service (resource consumption) via SSL parameter renegotiation.
by Pierre Kim
CVSS 7.5
CVE-2015-8399 EXPLOITDB MEDIUM text
Atlassian Confluence <5.8.17 - Info Disclosure
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.
by Sebastian Perez
CVSS 4.3
EIP-2026-112132 EXPLOITDB text
Simple PHP Polling System - Multiple Vulnerabilities
by WICS
EIP-2026-111077 EXPLOITDB text
PHPIPAM 1.1.010 - Multiple Vulnerabilities
by Mickael Dorigny
EIP-2026-110055 EXPLOITDB text
Online Airline Booking System - Multiple Vulnerabilities
by Manish Tanwar
CVE-2015-7945 EXPLOITDB HIGH perl
Ganeti <2.9.7-2.15.2 - Info Disclosure
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the DRBD secret via instance information job results.
by Pierre Kim
CVSS 7.5
CVE-2015-8660 EXPLOITDB MEDIUM c VERIFIED
Overlayfs Privilege Escalation
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
by rebel
CVSS 6.7
CVE-2014-6287 EXPLOITDB CRITICAL python VERIFIED
Rejetto HTTP File Server <2.3c - RCE
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
by Avinash Thapa
CVSS 9.8
EIP-2026-117215 EXPLOITDB python VERIFIED
FTPShell Client 5.24 - 'Add to Favorites' Buffer Overflow
by INSECT.B
EIP-2026-103627 EXPLOITDB text VERIFIED
pdfium IsFlagSet (v8 memory management) - SIGSEGV
by Google Security Research
CVE-2015-6787 EXPLOITDB text VERIFIED
Google Chrome < 46.0.2490.86 - Denial of Service
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
by Google Security Research
CVE-2015-6787 EXPLOITDB text VERIFIED
Google Chrome < 46.0.2490.86 - Denial of Service
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
by Google Security Research
CVE-2015-6787 EXPLOITDB text VERIFIED
Google Chrome < 46.0.2490.86 - Denial of Service
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
by Google Security Research
EIP-2026-114870 EXPLOITDB text VERIFIED
Advanced Encryption Package - Buffer Overflow (Denial of Service) (PoC)
by Vishnu
EIP-2026-110220 EXPLOITDB text VERIFIED
Open Audit - SQL Injection
by Rahul Pratap Singh
EIP-2026-115684 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11.0.9600.18124 EdUtil::GetCommonAncestorElement - Denial of Service
by Marcin Ressel
EIP-2026-117217 EXPLOITDB python
FTPShell Client 5.24 - Local Buffer Overflow
by hyp3rlinx