Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-54350 EXPLOITDB HIGH python
WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated
WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create malicious PHP files in the file_manager directory and execute them on the server.
by Milad karimi
CVSS 7.5
CVE-2025-5553 EXPLOITDB HIGH text
PHPGurukul Rail Pass Management System 1.0 - SQL Injection
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download-pass.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by yozgatalperen1
CVSS 7.3
EIP-2026-110151 EXPLOITDB text
Online Nurse Hiring System 1.0 - Time-Based SQL Injection
by yozgatalperen1
EIP-2026-104990 EXPLOITDB text
Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)
by Furkan ÖZER
EIP-2026-103456 EXPLOITDB text
Elasticsearch - StackOverflow DoS
by TOUHAMI Kasbaoui
EIP-2026-101505 EXPLOITDB text
Zyxel zysh - Format string
by Marco Ivaldi
EIP-2026-109496 EXPLOITDB text
MISP 2.4.171 - Stored XSS
by Mücahit Çeri
EIP-2026-107542 EXPLOITDB text
GYM MS - GYM Management System - Cross Site Scripting (Stored)
by yozgatalperen1
EIP-2026-106278 EXPLOITDB text
Curfew e-Pass Management System 1.0 - FromDate SQL Injection
by Puja Dey
EIP-2026-105925 EXPLOITDB text
Clinic's Patient Management System 1.0 - Unauthenticated RCE
by Oğulcan Hami Gül
EIP-2026-104490 EXPLOITDB text
WhatsUp Gold 2022 (22.1.0 Build 39) - XSS
by Andreas Finstad
EIP-2026-101358 EXPLOITDB python
Milesight Routers UR5X_ UR32L_ UR32_ UR35_ UR41 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption
by Bipin Jitiya
CVE-2024-58299 EXPLOITDB CRITICAL python
PCMan FTP Server 2.0 - Stack-based Buffer Overflow via PWD Command
PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.
by Waqas Ahmed Faroouqi
CVSS 9.8
EIP-2026-119265 EXPLOITDB text
WebCatalog 48.4 - Arbitrary Protocol Execution
by ItsSixtyN3in
EIP-2026-108936 EXPLOITDB python
Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)
by whiteOwl
EIP-2026-102072 EXPLOITDB text
TP-Link TL-WR740N - UnAuthenticated Directory Transversal
by Syed Affan Ahmed (ZEROXINN)
EIP-2026-102071 EXPLOITDB text
TP-LINK TL-WR740N - Multiple HTML Injection
by Shujaat Amin (ZEROXINN)
EIP-2026-101712 EXPLOITDB python
Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal
by LiquidWorm
EIP-2026-101711 EXPLOITDB text
Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution
by LiquidWorm
EIP-2026-101710 EXPLOITDB text
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure
by LiquidWorm
EIP-2026-101709 EXPLOITDB text
Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass
by LiquidWorm
EIP-2026-101708 EXPLOITDB text
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
by LiquidWorm
EIP-2026-101015 EXPLOITDB text
Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS
by LiquidWorm
CVE-2023-53155 EXPLOITDB HIGH text
EmbedThis GoAhead 2.5 - Code Injection
goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.
by Syed Affan Ahmed (ZEROXINN)
CVSS 7.2
EIP-2026-107507 EXPLOITDB text
Grocy <=4.0.2 - CSRF
by Chance Proctor