Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-101484 EXPLOITDB c
TPC-110W - Missing Authentication for Critical Function
by Amirhossein Bahramizadeh
EIP-2026-101477 EXPLOITDB python
TitanNit Web Control 2.01 / Atemio 7600 - Root Remote Code Execution
by LiquidWorm
EIP-2026-101353 EXPLOITDB text
Maxima Max Pro Power - BLE Traffic Replay (Unauthenticated)
by Alok kumar
CVE-2023-46454 EXPLOITDB CRITICAL python
GL.iNET GL-AR300M <4.3.7 - Command Injection
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.
by cyberaz0r
CVSS 9.8
CVE-2023-46455 EXPLOITDB HIGH python
GL.iNET GL-AR300M <4.3.7 - Path Traversal
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
by cyberaz0r
CVSS 7.5
CVE-2023-46456 EXPLOITDB CRITICAL python
GL.iNET GL-AR300M <3.216 - Command Injection
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
by cyberaz0r
CVSS 9.8
CVE-2024-58311 EXPLOITDB CRITICAL c
Dormakaba Saflok System 6000 - Info Disclosure
Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.
by planthopper3301
CVSS 9.8
EIP-2026-114378 EXPLOITDB python
WP Rocket < 2.10.3 - Local File Inclusion (LFI)
by E1 Coders
EIP-2026-114377 EXPLOITDB text
WP Fastest Cache 1.2.2 - Unauthenticated SQL Injection
by Meryem Taşkın
EIP-2026-113535 EXPLOITDB text
WordPress Plugin Admin Bar & Dashboard Access Control Version: 1.2.8 - _Dashboard Redirect_ field Stored Cross-Site Scripting (XSS)
by Rachit Arora
EIP-2026-105534 EXPLOITDB text
Blood Bank v1.0 - Multiple SQL Injection
by Ersin Erenler
EIP-2026-102769 EXPLOITDB c
(shellcode) Linux-x64 - create a shell with execve() sending argument using XOR (/bin//sh) [55 bytes]
by Alexys (0x177git)
CVE-2024-58278 EXPLOITDB HIGH text
perl2exe <= V30.10C - Authenticated Arbitrary Code Execution via Packed Executable Argument
perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.
by decrazyo
CVE-2023-53734 EXPLOITDB HIGH text
dawa-pharma 1.0-2022 - Unauthenticated SQL Injection via Email Parameter
dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.
by nu11secur1ty
CVE-2022-40924 EXPLOITDB HIGH text
Zoo Management System v1.0 - File Upload
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
by Çağatay Ceyhan
CVSS 7.2
EIP-2026-113619 EXPLOITDB python
Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)
by Leopoldo Angulo (leoanggal1)
EIP-2026-112492 EXPLOITDB text
SuperStoreFinder - Multiple Vulnerabilities
by bRpsd
EIP-2026-109584 EXPLOITDB text
Moodle 4.3 - Insecure Direct Object Reference
by tmrswrr
EIP-2026-105318 EXPLOITDB text
Automatic-Systems SOC FL9600 FastLine - The device contains hardcoded login and password for super admin
by Marcin Kozlowski
EIP-2026-105317 EXPLOITDB text
Automatic-Systems SOC FL9600 FastLine - Directory Transversal
by Marcin Kozlowski
EIP-2026-104175 EXPLOITDB ruby
Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)
by Emir Polat
EIP-2026-101469 EXPLOITDB text
TEM Opera Plus FM Family Transmitter 35.45 - XSRF
by LiquidWorm
EIP-2026-101468 EXPLOITDB text
TEM Opera Plus FM Family Transmitter 35.45 - Remote Code Execution
by LiquidWorm
CVE-2024-58316 EXPLOITDB HIGH text
Online Shopping System Advanced 1.0 - SQL Injection via Payment Success Parameter
Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter.
by Furkan Gedik
CVSS 7.5
CVE-2022-44151 EXPLOITDB CRITICAL text
Simple Inventory Management System v1.0 - SQL Injection
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
by SoSPiro
CVSS 9.8