Exploitdb Exploits

2,012 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105563 EXPLOITDB html
Bluethrust Clan Scripts v4 R17 - Multiple Vulnerabilities
by Brandon Murphy
CVE-2015-2419 EXPLOITDB HIGH html
Microsoft Internet Explorer - Out-of-Bounds Write
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."
by checkpoint
CVSS 8.8
EIP-2026-110565 EXPLOITDB html
pfSense Firewall 2.2.5 - Config File Cross-Site Request Forgery
by Aatif Shahdad
CVE-2016-3987 EXPLOITDB CRITICAL html VERIFIED
Trend Micro Password Manager - Command Injection
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
by Google Security Research
CVSS 9.8
EIP-2026-115684 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11.0.9600.18124 EdUtil::GetCommonAncestorElement - Denial of Service
by Marcin Ressel
EIP-2026-110422 EXPLOITDB html
Ovidentia maillist Module 4.0 - Remote File Inclusion
by bd0rk
CVE-2015-6152 EXPLOITDB html
Microsoft Internet Explorer - Memory Corruption
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6162.
by Moritz Jodeit
EIP-2026-115683 EXPLOITDB html
Microsoft Internet Explorer 11.0.9600.18097 - COmWindowProxy::SwitchMarkup NULL PTR
by Marcin Ressel
EIP-2026-105793 EXPLOITDB html
CF Image Host 1.65 - Cross-Site Request Forgery
by hyp3rlinx
CVE-2017-16836 EXPLOITDB MEDIUM html
Arris TG1682G - Unauthenticated XSS
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
by Nu11By73
CVSS 6.1
EIP-2026-110759 EXPLOITDB html
PHP Server Monitor 3.1.1 - Cross-Site Request Forgery / Privilege Escalation
by hyp3rlinx
EIP-2026-106564 EXPLOITDB html
Dream CMS 2.3.0 - Cross-Site Request Forgery (Add Extension) / Arbitrary File Upload / PHP Code Execution
by LiquidWorm
EIP-2026-102140 EXPLOITDB html
ZTE ZXHN H108N Router - Configuration Disclosure
by Todor Donev
EIP-2026-115681 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11 - Stack Underflow Crash (PoC)
by Mjx
CVE-2015-6827 EXPLOITDB html
Auto-exchanger - CSRF
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php.
by Aryan Bayaninejad
CVE-2015-6965 EXPLOITDB html
Creative-solutions Contact Form Generator < 2.0.1 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6) delete a form, (7) create a template, (8) update a template, (9) delete a template, or (10) conduct cross-site scripting (XSS) attacks via a crafted request to the cfg_forms page in wp-admin/admin.php.
by i0akiN SEC-LABORATORY
EIP-2026-101761 EXPLOITDB html
GPON Home Router FTP G-93RG1 - Cross-Site Request Forgery / Command Execution
by Phan Thanh Duy
CVE-2015-6655 EXPLOITDB html
Pligg Cms - CSRF
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.
by Arash Khazaei
EIP-2026-111339 EXPLOITDB html
Pligg CMS 2.0.2 - Arbitrary Code Execution
by Arash Khazaei
EIP-2026-112907 EXPLOITDB html
up.time 7.5.0 - Superadmin Privilege Escalation
by LiquidWorm
CVE-2015-2444 EXPLOITDB html
Microsoft Internet Explorer - Memory Corruption
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2442.
by Blue Frost Security GmbH
EIP-2026-109451 EXPLOITDB html
Microweber 1.0.3 - Persistent Cross-Site Scripting / Cross-Site Request Forgery (Add Admin)
by LiquidWorm
EIP-2026-115593 EXPLOITDB html
McAfee SiteAdvisor 3.7.2 - Firefox Use-After-Free (PoC)
by Marcin Ressel
EIP-2026-119442 EXPLOITDB html
Tango FTP 1.0 (Build 136) - Activex HeapSpray
by metacom
CVE-2007-3071 EXPLOITDB html VERIFIED
Digital River Esellerate SDK - Buffer Overflow
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.
by metacom