Html Exploits

2,054 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-111042 EXPLOITDB html
phpEnter 4.2.7 - Cross-Site Request Forgery (Add New Post)
by Besim
EIP-2026-105484 EXPLOITDB html
BirdBlog 1.4.0 - Cross-Site Request Forgery (Add New Post)
by Besim
EIP-2026-105202 EXPLOITDB html
ApPHP MicroBlog 1.0.2 - Cross-Site Request Forgery (Add New Author)
by Besim
EIP-2026-112365 EXPLOITDB html VERIFIED
Spacemarc News - Cross-Site Request Forgery (Add New Post)
by Besim
EIP-2026-109264 EXPLOITDB html
Maian Weblog 4.0 - Cross-Site Request Forgery (Add New Post)
by Besim
EIP-2026-105186 EXPLOITDB html
AnoBBS 1.0.1 - Remote File Inclusion
by bd0rk
EIP-2026-115685 EXPLOITDB html
Microsoft Internet Explorer 11.0.9600.18482 - Use After Free
by Marcin Ressel
CVE-2016-20032 EXPLOITDB HIGH html
ZKTeco ZKAccess Security System 5.3.1 Stored XSS
ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the 'holiday_name' and 'memo' POST parameters. Attackers can submit crafted requests with script code in these parameters to compromise user browser sessions and steal sensitive information.
by LiquidWorm
CVSS 7.2
CVE-2016-20028 EXPLOITDB MEDIUM html
ZKTeco ZKBioSecurity 3.0 Cross-Site Request Forgery Superadmin
ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Attackers can craft HTTP requests that add superadmin accounts without validity checks, enabling unauthorized administrative access when authenticated users visit attacker-controlled pages.
by LiquidWorm
CVSS 4.3
EIP-2026-111809 EXPLOITDB html
RSS News AutoPilot Script 1.0.1/3.0.3 - Cross-Site Request Forgery
by Arbin Godar
CVE-2016-3288 EXPLOITDB HIGH html VERIFIED
Microsoft Internet Explorer - Memory Corruption
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3290.
by Google Security Research
CVSS 7.5
CVE-2016-7454 EXPLOITDB HIGH html
Technicolor Xfinity Gateway Router Dpc3941t Firmware - CSRF
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remote management interface, or reset the router.
by Ayushman Dutta
CVSS 8.0
EIP-2026-109998 EXPLOITDB html
NUUO NVRmini 2 3.0.8 - Cross-Site Request Forgery (Add Admin)
by LiquidWorm
EIP-2026-103705 EXPLOITDB html VERIFIED
WebKit - TypedArray.fill Memory Corruption
by Google Security Research
EIP-2026-103704 EXPLOITDB html VERIFIED
WebKit - TypedArray.copyWithin Memory Corruption
by Google Security Research
CVE-2016-20035 EXPLOITDB MEDIUM html
Wowza Streaming Engine 4.5.0 CSRF via user edit endpoint
Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.
by LiquidWorm
CVSS 5.3
CVE-2016-20034 EXPLOITDB HIGH html
Wowza Streaming Engine 4.5.0 Privilege Escalation via user edit
Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access.
by LiquidWorm
CVSS 8.8
EIP-2026-114170 EXPLOITDB html
WordPress Plugin Video Player 1.5.16 - SQL Injection
by David Vaartjes
EIP-2026-100919 EXPLOITDB html
Ubiquiti Administration Portal - Remote Command Execution (via Cross-Site Request Forgery)
by KoreLogic
EIP-2026-114492 EXPLOITDB html
XuezhuLi FileSharing - Cross-Site Request Forgery (Add User)
by HaHwul
CVE-2016-0199 EXPLOITDB HIGH html
Microsoft Internet Explorer 9-11 - Code Injection
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0200 and CVE-2016-3211.
by Skylined
CVSS 8.8
EIP-2026-114536 EXPLOITDB html VERIFIED
Yona CMS - Cross-Site Request Forgery
by s0nk3y
EIP-2026-107944 EXPLOITDB html VERIFIED
IonizeCMS 1.0.8 - Cross-Site Request Forgery (Add Admin)
by s0nk3y
EIP-2026-114136 EXPLOITDB html
WordPress Plugin Ultimate Product Catalog 3.8.1 - Privilege Escalation
by i0akiN SEC-LABORATORY
EIP-2026-105036 EXPLOITDB html
Airia - Cross-Site Request Forgery (Add Content)
by HaHwul