Exploitdb Exploits
2,012 exploits tracked across all sources.
Pro Softnet IDrive Online Backup 3.4.0 - ActiveX 'SaveToFile()' Arbitrary File Overwrite
by High-Tech Bridge SA
iMesh 10.0 - 'IMWebControl.dll' ActiveX Control Buffer Overflow
by KedAns-Dz
CygniCon CyViewer - ActiveX Control 'SaveData()' Insecure Method
by High-Tech Bridge SA
LeadTools Imaging LEADSmtp - ActiveX Control 'SaveMessage()' Insecure Method
by High-Tech Bridge SA
Easewe FTP OCX ActiveX Control 4.5.0.9 - 'EaseWeFtp.ocx' Multiple Insecure Method Vulnerabilities
by High-Tech Bridge SA
Black Ice Fax Voice SDK 12.6 - Remote Code Execution
by mr_me
Opera Browser - Resource Management Error
Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a FONT element within an IFRAME element after changing the SRC attribute of this IFRAME element to an about:blank value.
by echo
The Pacer Edition CMS 2.1 - 'email' Cross-Site Scripting
by LiquidWorm
Magneto ICMP ActiveX 4.0.0.20 - ICMPSendEchoRequest Remote Code Execute
by boahat
cPanel < 11.25 - Cross-Site Request Forgery (Add User PHP Script)
by ninjashell
Andy's PHP KnowledgeBase 0.95.4 - 'step5.php' PHP Remote Code Execution
by AutoSec Tools
Ampache 3.5.4 - 'login.php' Cross-Site Scripting
by AutoSec Tools
VCalendar 1.1.5 - Cross-Site Request Forgery
by High-Tech Bridge SA
ICONICS BizViz <9.22, GENESIS32 <9.22 - RCE
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary code via a long string in the argument. NOTE: some of these details are obtained from third party information.
by sgb & bls
Exponent CMS 2.0 Beta 1.1 - Cross-Site Request Forgery (Add Administrator Account)
by outlaw.dll
Gesytec ElonFmt ActiveX 1.1.14 - 'ElonFmt.ocx' pid Item Buffer Overflow (SEH)
by LiquidWorm
Socialcms - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in SocialCMS 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrator accounts via a member_new action to my_admin/admin1_members.php or (2) modify the default site title via a save action to my_admin/admin1_configuration.php.
by vir0e5
docuFORM Mercury WebApp 6.16a/5.20 - Multiple Cross-Site Scripting Vulnerabilities
by LiquidWorm
Allomani Web Links 1.0 - Cross-Site Request Forgery (Add Admin)
by AtT4CKxT3rR0r1ST
Allomani Super MultiMedia Library 2.5.0 - Cross-Site Request Forgery (Add Admin)
by AtT4CKxT3rR0r1ST
By Source