0x04 // Latest Exploits
source: Exploit-DB →
Type
EDB-ID
CVE
Platform
Exploit
Published
WebApps
EDB-52660
CVE-2025-60689
hardware
Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
Aug 31, 2026
WebApps
EDB-52659
CVE-2026-5027
multiple
Langflow 1.8.4 - Path Traversal to Remote Code Execution
Aug 31, 2026
Remote
EDB-52658
CVE-2026-42167
multiple
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
Aug 25, 2026
WebApps
EDB-52642
CVE-2026-3891
multiple
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
Aug 17, 2026
Remote
EDB-52639
CVE-2026-61447
multiple
PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
Aug 11, 2026
Remote
EDB-52638
CVE-2026-61459
multiple
mcp-server-kubernetes 3.8.x - Argument Injection
Aug 11, 2026
DoS
EDB-52637
CVE-2026-61876
multiple
LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
Aug 11, 2026
WebApps
EDB-52636
CVE-2026-3576
multiple
Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
Aug 11, 2026
WebApps
EDB-52633
CVE-2026-58138
multiple
OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
Aug 10, 2026
WebApps
EDB-52630
CVE-2026-48907
multiple
Joomla 2.9.99.4 - Unauthenticated Remote Code Execution
Aug 10, 2026
WebApps
EDB-52629
CVE-2026-38526
multiple
Krayin CRM v2.2.x - Authenticated Remote Code Execution
Jul 8, 2026
WebApps
EDB-52628
CVE-2025-60188
multiple
Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
Jul 8, 2026
WebApps
EDB-52626
CVE-2026-56290
multiple
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
Jul 8, 2026
Local
EDB-52615
CVE-2026-36213
windows
MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
Jul 6, 2026
WebApps
EDB-52611
CVE-2026-49069
multiple
WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
Jul 6, 2026
WebApps
EDB-52609
CVE-2026-3180
multiple
WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
Jun 5, 2026
WebApps
EDB-52596
CVE-2026-1830
multiple
Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution
May 29, 2026
Local
EDB-52595
CVE-2026-46522
multiple
ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
May 29, 2026
Local
EDB-52594
CVE-2026-34473
multiple
ZTE Routers - Unauthenticated Denial of Service
May 29, 2026
Local
EDB-52592
CVE-2026-34474
multiple
ZTE H298A / H108N - Unauthenticated Credential Exposure
May 29, 2026
WebApps
EDB-52590
CVE-2026-42471
php
MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution
May 29, 2026
Remote
EDB-52589
CVE-2026-44403
multiple
Wing FTP Server 8.1.3 - Authenticated Remote Code Execution
May 29, 2026
WebApps
EDB-52588
CVE-2026-44376
multiple
CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
May 29, 2026
Remote
EDB-52587
CVE-2026-35330
multiple
strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow
May 29, 2026
WebApps
EDB-52584
CVE-2026-6815
go
Casdoor 3.54.1 - Arbitrary File Write via Path Traversal
May 27, 2026
WebApps
EDB-52577
CVE-2026-23918
multiple
Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service
May 26, 2026
WebApps
EDB-52575
CVE-2026-7567
multiple
Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover
May 26, 2026
Local
EDB-52570
—
windows
Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path
May 21, 2026
Local
EDB-52566
—
windows
Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing
May 15, 2026
Local
EDB-52565
—
windows
Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution
May 15, 2026
WebApps
EDB-52564
CVE-2026-4257
multiple
WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI
May 14, 2026
No exploits match your filter.