Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-101929 EXPLOITDB text
PROLiNK H5004NK ADSL Wireless Modem - Multiple Vulnerabilities
by Karn Ganeshen
EIP-2026-101888 EXPLOITDB text
netis RealTek Wireless Router / ADSL Modem - Multiple Vulnerabilities
by Karn Ganeshen
EIP-2026-116920 EXPLOITDB python VERIFIED
Boxoft WAV to MP3 Converter 1.1 - Local Buffer Overflow (SEH)
by ArminCyber
CVE-2015-3036 EXPLOITDB python
KCodes NetUSB - Stack-Based Buffer Overflow via Long Computer Name
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in certain NETGEAR products, TP-LINK products, and other products, allows remote attackers to execute arbitrary code by providing a long computer name in a session on TCP port 20005.
by blasty
CVE-2015-6018 EXPLOITDB CRITICAL text
ZyXEL PMG5318-B20A <1.00(AANC.2)C0 - RCE
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
by Karn Ganeshen
CVSS 9.8
CVE-2014-8357 EXPLOITDB HIGH text
Zhone zNID GPON 2426A < S3.0.501 - Unauthenticated Password Disclosure via Session Key in URL
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.
by Lyon Yang
CVSS 8.8
CVE-2014-8356 EXPLOITDB HIGH text
Zhone zNID 2426A < s3.0.501 - Authenticated Authorization Bypass via Insecure Direct Object Reference
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.
by Lyon Yang
CVSS 8.8
EIP-2026-116943 EXPLOITDB text
CDex Genre 1.79 - Local Stack Buffer Overflow
by Un_N0n
EIP-2026-108992 EXPLOITDB text
Kerio Control 8.6.1 - Multiple Vulnerabilities
by Raschin Tavakoli
CVE-2015-7805 EXPLOITDB perl
libsndfile 1.0.25 - Buffer Overflow
Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.
by Marco Romano
EIP-2026-101872 EXPLOITDB text
Netgear Voice Gateway 2.3.0.23_2.3.23 - Multiple Vulnerabilities
by Karn Ganeshen
CVE-2015-4040 EXPLOITDB text
F5 Enterprise Manager 3.0.0-3.1.1 - Authenticated Path Traversal
Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.
by Karn Ganeshen
CVE-2014-9118 EXPLOITDB HIGH text
Zhone zNID GPON 2426A <S3.0.501 - RCE
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.
by Lyon Yang
CVSS 8.8
EIP-2026-119500 EXPLOITDB python VERIFIED
Tomabo MP4 Converter 3.10.12 < 3.11.12 - '.m3u' File Crush Application (Denial of Service)
by mohammed Mohammed
EIP-2026-109124 EXPLOITDB text
Liferay 6.1.0 CE - Privilege Escalation
by Massimo De Luca
EIP-2026-108510 EXPLOITDB text
Joomla! Component com_realestatemanager 3.7 - SQL Injection
by Omer Ramić
EIP-2026-106564 EXPLOITDB html
Dream CMS 2.3.0 - Cross-Site Request Forgery (Add Extension) / Arbitrary File Upload / PHP Code Execution
by LiquidWorm
EIP-2026-104678 EXPLOITDB text
PHPMyLicense 3.0.0 < 3.1.4 - Denial of Service
by Aria Akhavan Rezayat
EIP-2026-118050 EXPLOITDB python VERIFIED
VeryPDF Image2PDF Converter - Local Buffer Overflow (SEH)
by Robbie Corley
CVE-2015-5285 EXPLOITDB text
Kallithea <0.3 - HTTP Response Splitting
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.
by LiquidWorm
CVE-2015-7293 EXPLOITDB HIGH text
Plone - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
by hyp3rlinx
CVSS 8.8
EIP-2026-115542 EXPLOITDB python
Last PassBroker 3.2.16 - Stack Buffer Overflow (PoC)
by Un_N0n
EIP-2026-115541 EXPLOITDB python
LanWhoIs.exe 1.0.1.120 - Stack Buffer Overflow (PoC)
by hyp3rlinx
EIP-2026-110809 EXPLOITDB text
PHP-Fusion 7.02.07 - Blind SQL Injection
by Manuel García Cárdenas
EIP-2026-107434 EXPLOITDB text
GLPI 0.85.5 - Arbitrary File Upload / Filter Bypass / Remote Code Execution
by Raffaele Forte