Html Exploits

2,054 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105793 EXPLOITDB html
CF Image Host 1.65 - Cross-Site Request Forgery
by hyp3rlinx
CVE-2017-16836 EXPLOITDB MEDIUM html
Arris TG1682G - Unauthenticated XSS
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
by Nu11By73
CVSS 6.1
EIP-2026-110759 EXPLOITDB html
PHP Server Monitor 3.1.1 - Cross-Site Request Forgery / Privilege Escalation
by hyp3rlinx
EIP-2026-106564 EXPLOITDB html
Dream CMS 2.3.0 - Cross-Site Request Forgery (Add Extension) / Arbitrary File Upload / PHP Code Execution
by LiquidWorm
EIP-2026-102140 EXPLOITDB html
ZTE ZXHN H108N Router - Configuration Disclosure
by Todor Donev
EIP-2026-115681 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11 - Stack Underflow Crash (PoC)
by Mjx
CVE-2015-6827 EXPLOITDB html
Auto-exchanger - CSRF
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php.
by Aryan Bayaninejad
CVE-2015-6965 EXPLOITDB html
Creative-solutions Contact Form Generator < 2.0.1 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6) delete a form, (7) create a template, (8) update a template, (9) delete a template, or (10) conduct cross-site scripting (XSS) attacks via a crafted request to the cfg_forms page in wp-admin/admin.php.
by i0akiN SEC-LABORATORY
EIP-2026-101761 EXPLOITDB html
GPON Home Router FTP G-93RG1 - Cross-Site Request Forgery / Command Execution
by Phan Thanh Duy
CVE-2015-6655 EXPLOITDB html
Pligg Cms - CSRF
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.
by Arash Khazaei
EIP-2026-111339 EXPLOITDB html
Pligg CMS 2.0.2 - Arbitrary Code Execution
by Arash Khazaei
EIP-2026-112907 EXPLOITDB html
up.time 7.5.0 - Superadmin Privilege Escalation
by LiquidWorm
CVE-2015-2444 EXPLOITDB html
Microsoft Internet Explorer - Memory Corruption
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2442.
by Blue Frost Security GmbH
EIP-2026-109451 EXPLOITDB html
Microweber 1.0.3 - Persistent Cross-Site Scripting / Cross-Site Request Forgery (Add Admin)
by LiquidWorm
EIP-2026-115593 EXPLOITDB html
McAfee SiteAdvisor 3.7.2 - Firefox Use-After-Free (PoC)
by Marcin Ressel
EIP-2026-119442 EXPLOITDB html
Tango FTP 1.0 (Build 136) - Activex HeapSpray
by metacom
CVE-2007-3071 EXPLOITDB html VERIFIED
Digital River Esellerate SDK - Buffer Overflow
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.
by metacom
EIP-2026-115053 EXPLOITDB html
Cisco AnyConnect Secure Mobility 2.x/3.x/4.x - Client Denial of Service (PoC)
by LiquidWorm
EIP-2026-115676 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11 - Crash (PoC) (2)
by Pawel Wylecial
EIP-2026-116673 EXPLOITDB html VERIFIED
1 Click Extract Audio 2.3.6 - Activex Buffer Overflow
by metacom
EIP-2026-116672 EXPLOITDB html VERIFIED
1 Click Audio Converter 2.3.6 - Activex Local Buffer Overflow
by metacom
EIP-2026-115675 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 11 - Crash (PoC) (1)
by Garage4Hackers
EIP-2026-119394 EXPLOITDB html VERIFIED
ManageEngine EventLog Analyzer 10.0 Build 10001 - Cross-Site Request Forgery
by Akash S. Chavan
CVE-2015-0555 EXPLOITDB html
Samsung Ipolis Device Manager - Memory Corruption
Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue function.
by Praveen Darshanam
EIP-2026-105381 EXPLOITDB html
Balero CMS 0.7.2 - Multiple JS/HTML Injection Vulnerabilities
by LiquidWorm