Html Exploits

2,054 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-117418 EXPLOITDB html VERIFIED
LiquidXML Studio 2012 - ActiveX Insecure Method Executable File Creation
by Dr_IDE
EIP-2026-117417 EXPLOITDB html VERIFIED
LiquidXML Studio 2010 - ActiveX Code Execution
by Dr_IDE
EIP-2026-113830 EXPLOITDB html VERIFIED
WordPress Plugin IndiaNIC FAQs Manager 1.0 - Multiple Vulnerabilities
by m3tamantra
EIP-2026-117089 EXPLOITDB html VERIFIED
EastFTP 4.6.02 - ActiveX Control
by Dr_IDE
EIP-2026-113933 EXPLOITDB html VERIFIED
WordPress Plugin Occasions 1.0.4 - Cross-Site Request Forgery
by m3tamantra
EIP-2026-113932 EXPLOITDB html VERIFIED
WordPress Plugin Occasions - Cross-Site Request Forgery
by m3tamantra
EIP-2026-111632 EXPLOITDB html VERIFIED
Question2Answer - Cross-Site Request Forgery
by MustLive
EIP-2026-103892 EXPLOITDB html VERIFIED
Dell SonicWALL Scrutinizer - Multiple HTML Injection Vulnerabilities
by Benjamin Kunz Mejri
CVE-2013-0804 EXPLOITDB html VERIFIED
Novell GroupWise <8.0.3-2012 - RCE/DoS
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors.
by High-Tech Bridge
CVE-2012-1876 EXPLOITDB html VERIFIED
Microsoft Internet Explorer - Code Injection
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
by sickness
CVE-2012-6429 EXPLOITDB html VERIFIED
Samsung Kies < 2.5.0.12114_1 - Memory Corruption
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument.
by High-Tech Bridge
CVE-2012-5878 EXPLOITDB CRITICAL html VERIFIED
Bulbsecurity Smartphone Pentest Framework - OS Command Injection
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.
by High-Tech Bridge
CVSS 9.8
EIP-2026-114433 EXPLOITDB html VERIFIED
XiVO - Cross-Site Request Forgery
by Francis Provencher
EIP-2026-110244 EXPLOITDB html VERIFIED
Open-Realty 2.5.8 - Cross-Site Request Forgery
by Aung Khant
EIP-2026-118246 EXPLOITDB html VERIFIED
Aladdin Knowledge System Ltd - 'PrivAgent.ocx' ChooseFilePath Buffer Overflow
by b33f
EIP-2026-113409 EXPLOITDB html VERIFIED
WHMCompleteSolution (WHMCS) 4.5.2 - 'googlecheckout.php' SQL Injection
by Starware Security Team
EIP-2026-114196 EXPLOITDB html VERIFIED
WordPress Plugin Wordfence Security - Cross-Site Scripting
by MustLive
EIP-2026-102677 EXPLOITDB html VERIFIED
Midori Browser 0.3.2 - Denial of Service
by Ryuzaki Lawlet
EIP-2026-114035 EXPLOITDB html VERIFIED
WordPress Plugin Sexy Add Template - Cross-Site Request Forgery
by the_cyber_nuxbie
EIP-2026-113503 EXPLOITDB html VERIFIED
WordPress Core 3.4.2 - Cross-Site Request Forgery
by AkaStep
EIP-2026-102484 EXPLOITDB html VERIFIED
IFOBS - 'regclientprint.jsp' Multiple HTML Injection Vulnerabilities
by MustLive
EIP-2026-105589 EXPLOITDB html VERIFIED
Booking System Pro - Cross-Site Request Forgery
by DaOne
CVE-2012-2517 EXPLOITDB MEDIUM html VERIFIED
PrestaShop <1.4.9 - XSS
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.
by High-Tech Bridge
CVSS 6.1
EIP-2026-111850 EXPLOITDB html
RV Shopping Cart - Cross-Site Request Forgery
by DaOne
EIP-2026-111849 EXPLOITDB html
RV Article Publisher - Cross-Site Request Forgery
by DaOne