Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-36599 EXPLOITDB MEDIUM text
Aegon Life Insurance Management System 1.0 - Cross-Site Scripting via insertClient.php Name Parameter
A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php.
by Aslam Anwar Mahimkar
CVSS 6.1
CVE-2024-36597 EXPLOITDB HIGH text
Aegon Life v1.0 - SQL Injection via client_id Parameter
Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.
by Aslam Anwar Mahimkar
CVSS 8.8
EIP-2026-114380 EXPLOITDB text
WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS) (Authenticated)
by Onur Göğebakan
EIP-2026-110635 EXPLOITDB python
PHP < 8.3.8 - Remote Code Execution (Unauthenticated) (Windows)
by Yesith Alvarez
EIP-2026-105576 EXPLOITDB text
Boelter Blue System Management 1.3 - SQL Injection
by CBKB
CVE-2024-58283 EXPLOITDB HIGH python
WBCE CMS 1.6.2 - Authenticated Remote Code Execution via Elfinder File Upload
WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.
by Ahmet Ümit BAYRAM
CVSS 8.8
CVE-2024-58282 EXPLOITDB HIGH python
Serendipity 2.5.0 - Authenticated Remote Code Execution via Media Upload
Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell with a command execution form that enables arbitrary system command execution on the web server.
by Ahmet Ümit BAYRAM
CVSS 7.2
CVE-2024-58281 EXPLOITDB HIGH python
Dotclear 2.29 - Authenticated Remote Code Execution via Media Upload
Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload process by crafting a PHP shell with a command execution form to gain system access through the uploaded file.
by Ahmet Ümit BAYRAM
CVSS 8.8
CVE-2024-58280 EXPLOITDB HIGH text
CMSimple 5.15 - Authenticated Remote Command Execution via Extensions Configuration
CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.
by Ahmet Ümit BAYRAM
CVSS 8.8
CVE-2024-58279 EXPLOITDB HIGH python
appRain CMF 4.0.5 - Authenticated Remote Code Execution via Filemanager Upload
appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can leverage authenticated access to generate a web shell with command execution capabilities by uploading a crafted PHP file to the site's uploads directory.
by Ahmet Ümit BAYRAM
CVSS 8.8
EIP-2026-109571 EXPLOITDB python
Monstra CMS 3.0.4 - Remote Code Execution (RCE)
by Ahmet Ümit BAYRAM
CVE-2023-27636 EXPLOITDB MEDIUM text
Progress Sitefinity < 15.0.0 - Authenticated Cross-Site Scripting via Content Form
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
by Aldi Saputra Wahyudi
CVSS 5.4
CVE-2024-58294 EXPLOITDB HIGH php
FreePBX 16 - Authenticated Remote Code Execution via API Module Generatedocs Endpoint
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.
by Cold z3ro
CVSS 8.8
CVE-2024-58293 EXPLOITDB HIGH text
Akaunting 3.1.8 - Authenticated Server-Side Template Injection via Form Input Fields
Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform arithmetic operations and string manipulations.
by tmrswrr
CVE-2024-58295 EXPLOITDB HIGH text
ElkArte Forum 1.1.9 - Authenticated Remote Code Execution via Theme Upload
ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.
by tmrswrr
CVE-2025-25037 EXPLOITDB CRITICAL python
Aquatronica Controller System <= 5.1.6 - Information Disclosure
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.
by LiquidWorm
CVE-2024-22855 EXPLOITDB MEDIUM text
ITSS iMLog < 1.308 - Stored Cross-Site Scripting via User Maintenance Last Name Parameter
A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.
by Gabriel Felipe
CVSS 5.4
EIP-2026-105666 EXPLOITDB text
BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL Injection
by Ivan Spiridonov
EIP-2026-104196 EXPLOITDB python
changedetection < 0.45.20 - Remote Code Execution (RCE)
by Zach Crosman (zcrosman)
EIP-2026-101583 EXPLOITDB python
Check Point Security Gateway - Information Disclosure (Unauthenticated)
by Yesith Alvarez
CVE-2024-58284 EXPLOITDB HIGH python
PopojiCMS 2.0.1 - Authenticated Remote Code Execution via Metadata Settings
PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.
by Ahmet Ümit BAYRAM
CVSS 7.2
CVE-2024-33559 EXPLOITDB CRITICAL text
8theme XStore <9.3.5 - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.
by Abdualhadi khalifa
CVSS 9.3
CVE-2024-34241 EXPLOITDB MEDIUM
Rocketsoft Rocket LMS 1.9 - Stored Cross-Site Scripting in Course Creation Interface
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.
by Sergio Medeiros
CVSS 4.8
CVE-2022-35914 EXPLOITDB CRITICAL bash
GLPI htmLawed php command injection
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
by Miguel Redondo
CVSS 9.8
EIP-2026-105375 EXPLOITDB python VERIFIED
Backdrop CMS 1.27.1 - Authenticated Remote Command Execution (RCE)
by Ahmet Ümit BAYRAM