Exploitdb Exploits

50,121 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-27744 EXPLOITDB MEDIUM text
Petrol Pump Mangement Software v.1.0 - XSS
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.
by Shubham Pandey
CVSS 6.1
CVE-2024-27746 EXPLOITDB CRITICAL text
Petrol Pump Mangement Software <1.0 - SQL Injection
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.
by Shubham Pandey
CVSS 9.8
EIP-2026-104707 EXPLOITDB text
AC Repair and Services System v1.0 - Multiple SQL Injection
by Gnanaraj Mauviel
EIP-2026-104315 EXPLOITDB text
Magento ver. 2.4.6 - XSLT Server Side Injection
by tmrswrr
EIP-2026-103761 EXPLOITDB python
A-PDF All to MP3 Converter 2.0.0 - DEP Bypass via HeapCreate + HeapAlloc
by George Washington
EIP-2026-101484 EXPLOITDB c
TPC-110W - Missing Authentication for Critical Function
by Amirhossein Bahramizadeh
EIP-2026-101477 EXPLOITDB python
TitanNit Web Control 2.01 / Atemio 7600 - Root Remote Code Execution
by LiquidWorm
EIP-2026-101353 EXPLOITDB text
Maxima Max Pro Power - BLE Traffic Replay (Unauthenticated)
by Alok kumar
CVE-2023-46454 EXPLOITDB CRITICAL python
GL.iNET GL-AR300M <4.3.7 - Command Injection
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.
by cyberaz0r
CVSS 9.8
CVE-2023-46455 EXPLOITDB HIGH python
GL.iNET GL-AR300M <4.3.7 - Path Traversal
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
by cyberaz0r
CVSS 7.5
CVE-2023-46456 EXPLOITDB CRITICAL python
GL.iNET GL-AR300M <3.216 - Command Injection
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
by cyberaz0r
CVSS 9.8
CVE-2024-58311 EXPLOITDB CRITICAL c
Dormakaba Saflok System 6000 - Info Disclosure
Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.
by planthopper3301
CVSS 9.8
EIP-2026-114378 EXPLOITDB python
WP Rocket < 2.10.3 - Local File Inclusion (LFI)
by E1 Coders
EIP-2026-114377 EXPLOITDB text
WP Fastest Cache 1.2.2 - Unauthenticated SQL Injection
by Meryem Taşkın
EIP-2026-113535 EXPLOITDB text
WordPress Plugin Admin Bar & Dashboard Access Control Version: 1.2.8 - _Dashboard Redirect_ field Stored Cross-Site Scripting (XSS)
by Rachit Arora
EIP-2026-105534 EXPLOITDB text
Blood Bank v1.0 - Multiple SQL Injection
by Ersin Erenler
EIP-2026-102769 EXPLOITDB c
(shellcode) Linux-x64 - create a shell with execve() sending argument using XOR (/bin//sh) [55 bytes]
by Alexys (0x177git)
CVE-2024-58278 EXPLOITDB HIGH text
perl2exe < V30.10C - RCE
perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.
by decrazyo
CVE-2023-53734 EXPLOITDB HIGH text
dawa-pharma-1.0 - SQL Injection
dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.
by nu11secur1ty
CVE-2022-40924 EXPLOITDB HIGH text
Zoo Management System v1.0 - File Upload
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
by Çağatay Ceyhan
CVSS 7.2
EIP-2026-113619 EXPLOITDB python
Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)
by Leopoldo Angulo (leoanggal1)
EIP-2026-112492 EXPLOITDB text
SuperStoreFinder - Multiple Vulnerabilities
by bRpsd
EIP-2026-109584 EXPLOITDB text
Moodle 4.3 - Insecure Direct Object Reference
by tmrswrr
EIP-2026-105318 EXPLOITDB text
Automatic-Systems SOC FL9600 FastLine - The device contains hardcoded login and password for super admin
by Marcin Kozlowski
EIP-2026-105317 EXPLOITDB text
Automatic-Systems SOC FL9600 FastLine - Directory Transversal
by Marcin Kozlowski