Exploitdb Exploits

2,009 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-110565 EXPLOITDB html
pfSense Firewall 2.2.5 - Config File Cross-Site Request Forgery
by Aatif Shahdad
CVE-2016-3987 EXPLOITDB CRITICAL html VERIFIED
Trend Micro Password Manager - Command Injection
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
by Google Security Research
CVSS 9.8
EIP-2026-115684 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11.0.9600.18124 EdUtil::GetCommonAncestorElement - Denial of Service
by Marcin Ressel
EIP-2026-110422 EXPLOITDB html
Ovidentia maillist Module 4.0 - Remote File Inclusion
by bd0rk
CVE-2015-6152 EXPLOITDB html
Internet Explorer 10 - Remote Code Execution via Memory Corruption
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6162.
by Moritz Jodeit
EIP-2026-115683 EXPLOITDB html
Microsoft Internet Explorer 11.0.9600.18097 - COmWindowProxy::SwitchMarkup NULL PTR
by Marcin Ressel
EIP-2026-105793 EXPLOITDB html
CF Image Host 1.65 - Cross-Site Request Forgery
by hyp3rlinx
CVE-2017-16836 EXPLOITDB MEDIUM html
Arris TG1682G - Unauthenticated XSS
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
by Nu11By73
CVSS 6.1
EIP-2026-110759 EXPLOITDB html
PHP Server Monitor 3.1.1 - Cross-Site Request Forgery / Privilege Escalation
by hyp3rlinx
EIP-2026-106564 EXPLOITDB html
Dream CMS 2.3.0 - Cross-Site Request Forgery (Add Extension) / Arbitrary File Upload / PHP Code Execution
by LiquidWorm
EIP-2026-102140 EXPLOITDB html
ZTE ZXHN H108N Router - Configuration Disclosure
by Todor Donev
EIP-2026-115681 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11 - Stack Underflow Crash (PoC)
by Mjx
CVE-2015-6827 EXPLOITDB html
Auto-Exchanger 5.1.0 - Cross-Site Request Forgery via Password Change Request
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php.
by Aryan Bayaninejad
CVE-2015-6965 EXPLOITDB html
Contact Form Generator < 2.0.1 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6) delete a form, (7) create a template, (8) update a template, (9) delete a template, or (10) conduct cross-site scripting (XSS) attacks via a crafted request to the cfg_forms page in wp-admin/admin.php.
by i0akiN SEC-LABORATORY
EIP-2026-101761 EXPLOITDB html
GPON Home Router FTP G-93RG1 - Cross-Site Request Forgery / Command Execution
by Phan Thanh Duy
CVE-2015-6655 EXPLOITDB html
Pligg CMS 2.0.2 - Cross-Site Request Forgery via Admin User Addition
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.
by Arash Khazaei
EIP-2026-111339 EXPLOITDB html
Pligg CMS 2.0.2 - Arbitrary Code Execution
by Arash Khazaei
EIP-2026-112907 EXPLOITDB html
up.time 7.5.0 - Superadmin Privilege Escalation
by LiquidWorm
CVE-2015-2444 EXPLOITDB html
Microsoft Internet Explorer 8-11 - Remote Code Execution via Memory Corruption
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2442.
by Blue Frost Security GmbH
EIP-2026-109451 EXPLOITDB html
Microweber 1.0.3 - Persistent Cross-Site Scripting / Cross-Site Request Forgery (Add Admin)
by LiquidWorm
EIP-2026-115593 EXPLOITDB html
McAfee SiteAdvisor 3.7.2 - Firefox Use-After-Free (PoC)
by Marcin Ressel
EIP-2026-119442 EXPLOITDB html
Tango FTP 1.0 (Build 136) - Activex HeapSpray
by metacom
CVE-2007-3071 EXPLOITDB html VERIFIED
eSellerate SDK 3.6.5.0 - Buffer Overflow via GetWebStoreURL ActiveX Control
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.
by metacom
EIP-2026-115053 EXPLOITDB html
Cisco AnyConnect Secure Mobility 2.x/3.x/4.x - Client Denial of Service (PoC)
by LiquidWorm
EIP-2026-115676 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11 - Crash (PoC) (2)
by Pawel Wylecial