56,966 blogs · [ { "id": "01a094f9-783f-7295-bf6e-36e32ee7a61b", "title": "[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE", "url": "https://www.exploit-db.com/exploits/52682", "published_at": "2026-09-11T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546c887bc65", "title": "[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)", "url": "https://www.exploit-db.com/exploits/52681", "published_at": "2026-09-03T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546c9223d0d", "title": "[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution", "url": "https://www.exploit-db.com/exploits/52680", "published_at": "2026-09-03T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546c98077aa", "title": "[dos] EVerest 2025.9.0 - DoS", "url": "https://www.exploit-db.com/exploits/52679", "published_at": "2026-09-02T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546ca307aa8", "title": "[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting", "url": "https://www.exploit-db.com/exploits/52678", "published_at": "2026-09-02T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546ca7d8e05", "title": "[webapps] PodcastGenerator 3.2.9 - Stored XSS", "url": "https://www.exploit-db.com/exploits/52677", "published_at": "2026-09-02T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546ca88721c", "title": "[webapps] Ghost_CMS 6.19.0 - Remote Code Execution", "url": "https://www.exploit-db.com/exploits/52676", "published_at": "2026-09-02T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546cb66e931", "title": "[webapps] Langflow 1.10.0 - RCE", "url": "https://www.exploit-db.com/exploits/52675", "published_at": "2026-09-02T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546cc09c3e6", "title": "[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities", "url": "https://www.exploit-db.com/exploits/52674", "published_at": "2026-09-02T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546ccfd9d95", "title": "[webapps] Marimo 0.20.4 - RCE", "url": "https://www.exploit-db.com/exploits/52673", "published_at": "2026-09-02T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546cda1c766", "title": "[webapps] Wolf CMS 0.8.3.1 - RCE v", "url": "https://www.exploit-db.com/exploits/52672", "published_at": "2026-09-01T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546ce5caef9", "title": "[webapps] Payload CMS 3.72.0 - Blind SQL Injection", "url": "https://www.exploit-db.com/exploits/52671", "published_at": "2026-09-01T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546cf006cd3", "title": "[webapps] Bludit CMS - Stored XSS", "url": "https://www.exploit-db.com/exploits/52670", "published_at": "2026-09-01T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546cfd1bafa", "title": "[webapps] Grav CMS 2.0.7 - RCE", "url": "https://www.exploit-db.com/exploits/52669", "published_at": "2026-09-01T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d0953d6e", "title": "[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass", "url": "https://www.exploit-db.com/exploits/52668", "published_at": "2026-09-01T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d0a0255e", "title": "[webapps] EasyAppointments 1.5.1 - Blind SQL Injection", "url": "https://www.exploit-db.com/exploits/52667", "published_at": "2026-09-01T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d0b63a18", "title": "[webapps] C-MOR 6.0104 - Directory Traversal", "url": "https://www.exploit-db.com/exploits/52666", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d0f73509", "title": "[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)", "url": "https://www.exploit-db.com/exploits/52665", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d1b9e290", "title": "[webapps] CubeCart 6.7.4 - SQL injection", "url": "https://www.exploit-db.com/exploits/52664", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d21e974e", "title": "[webapps] CubeCart 6.7.4 - SQL", "url": "https://www.exploit-db.com/exploits/52663", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d2fa3bcf", "title": "[webapps] CubeCart 6.7.4 - Stored XSS", "url": "https://www.exploit-db.com/exploits/52662", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d35c3ace", "title": "[webapps] CubeCart 6.7.4 - Cross-Site Scripting", "url": "https://www.exploit-db.com/exploits/52661", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d4420010", "title": "[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command Injection", "url": "https://www.exploit-db.com/exploits/52660", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d48f325a", "title": "[webapps] Langflow 1.8.4 - Path Traversal to Remote Code Execution", "url": "https://www.exploit-db.com/exploits/52659", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d4940c6f", "title": "[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE", "url": "https://www.exploit-db.com/exploits/52658", "published_at": "2026-08-25T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d4a158e4", "title": "[remote] PCMan 2.0.7 - Buffer Overflow", "url": "https://www.exploit-db.com/exploits/52657", "published_at": "2026-08-18T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d4e9e4fe", "title": "[dos] NanaZip 6.5 - DoS", "url": "https://www.exploit-db.com/exploits/52656", "published_at": "2026-08-18T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d56c005a", "title": "[webapps] flyto-core 2.26.7 - Arbitrary File Write", "url": "https://www.exploit-db.com/exploits/52655", "published_at": "2026-08-18T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d64291f6", "title": "[webapps] Nodemailer 9.0.0 - File Read/ SSRF", "url": "https://www.exploit-db.com/exploits/52654", "published_at": "2026-08-18T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d7132a7e", "title": "[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF", "url": "https://www.exploit-db.com/exploits/52653", "published_at": "2026-08-18T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d7a45975", "title": "[dos] NanaZip 6.5 - DoS", "url": "https://www.exploit-db.com/exploits/52652", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d82e7f3e", "title": "[webapps] flyto_core 2.26.7 - Server-Side Request Forgery", "url": "https://www.exploit-db.com/exploits/52651", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d8c34b6f", "title": "[webapps] Probo 0.222.2 - IDOR", "url": "https://www.exploit-db.com/exploits/52650", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546d9268dc4", "title": "[webapps] webpack_devserver 5.2.5 - CSRF", "url": "https://www.exploit-db.com/exploits/52649", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546da20966a", "title": "[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass", "url": "https://www.exploit-db.com/exploits/52648", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546dab30e21", "title": "[dos] Nmap 7.99 - Extension Header Integer Underflow", "url": "https://www.exploit-db.com/exploits/52647", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546dac8c5f8", "title": "[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak", "url": "https://www.exploit-db.com/exploits/52646", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546db968716", "title": "[webapps] Joomla JCE_2.9.15 - Remote Code Execution", "url": "https://www.exploit-db.com/exploits/52645", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546dc93b6ab", "title": "[remote] ipTIME A3004T - Remote Code Execution", "url": "https://www.exploit-db.com/exploits/52644", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546dce41cdd", "title": "[remote] D-Link DNS_340L - OS Command Injection", "url": "https://www.exploit-db.com/exploits/52643", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546dda220f4", "title": "[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload", "url": "https://www.exploit-db.com/exploits/52642", "published_at": "2026-08-17T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546de8adb23", "title": "[webapps] Apache Gravitino 1.2.1 - SSRF", "url": "https://www.exploit-db.com/exploits/52641", "published_at": "2026-08-11T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546df322ee3", "title": "[webapps] Blocksy Companion 2.1.46 - RCE", "url": "https://www.exploit-db.com/exploits/52640", "published_at": "2026-08-11T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546dfe64fe1", "title": "[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution", "url": "https://www.exploit-db.com/exploits/52639", "published_at": "2026-08-11T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546e0850293", "title": "[remote] mcp-server-kubernetes 3.8.x - Argument Injection", "url": "https://www.exploit-db.com/exploits/52638", "published_at": "2026-08-11T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546e0cf767a", "title": "[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting", "url": "https://www.exploit-db.com/exploits/52637", "published_at": "2026-08-11T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546e190ae5a", "title": "[webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF", "url": "https://www.exploit-db.com/exploits/52636", "published_at": "2026-08-11T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546e1c9a64a", "title": "[webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion", "url": "https://www.exploit-db.com/exploits/52635", "published_at": "2026-08-11T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546e20b74de", "title": "[webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution", "url": "https://www.exploit-db.com/exploits/52633", "published_at": "2026-08-10T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546e284a060", "title": "[local] Microsoft Edge 150.0.4078.48 - RCE", "url": "https://www.exploit-db.com/exploits/52632", "published_at": "2026-08-10T00:00:00+00:00" }, { "id": "01a07df2-e856-71be-8589-e546e28fb9f8", "title": "[webapps] CorgetGpsDget 2_3.2 - OS Command Injection", "url": "https://www.exploit-db.com/exploits/52631", "published_at": "2026-08-10T00:00:00+00:00" } ] posts Claim your blog
Back to Exploit Database
Blog · corpus.blog/blogs/exploit-db.com/posts

Exploit Database

exploit-db.com

2026