Text Exploits

31,383 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-24893 EXPLOITDB CRITICAL text
XWiki Platform - Remote Code Execution
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance, without being logged in, go to `<host>/xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28"Hello%20from"%20%2B%20"%20search%20text%3A"%20%2B%20%2823%20%2B%2019%29%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D%20`. If there is an output, and the title of the RSS feed contains `Hello from search text:42`, then the instance is vulnerable. This vulnerability has been patched in XWiki 15.10.11, 16.4.1 and 16.5.0RC1. Users are advised to upgrade. Users unable to upgrade may edit `Main.SolrSearchMacros` in `SolrSearchMacros.xml` on line 955 to match the `rawResponse` macro in `macros.vm#L2824` with a content type of `application/xml`, instead of simply outputting the content of the feed.
by Al Baradi Joy
CVSS 9.8
CVE-2025-24813 EXPLOITDB CRITICAL text
Tomcat Partial PUT Java Deserialization
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
by Al Baradi Joy
CVSS 9.8
CVE-2024-9458 EXPLOITDB MEDIUM text
Reservit Hotel WordPress Plugin < 3.0 - Authenticated Stored Cross-Site Scripting in Settings
The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
by Ilteris Kaan Pehlivan
CVSS 4.8
CVE-2025-29927 EXPLOITDB CRITICAL text
Next.js Middleware Bypass
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
by kOaDT
CVSS 9.1
CVE-2022-22536 EXPLOITDB CRITICAL text
SAP Content Server 7.53 - Unauthenticated HTTP Request Smuggling
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
by C41Tx90
CVSS 10.0
CVE-2025-66573 EXPLOITDB HIGH text
Solstice Pod API <6.2 - Info Disclosure
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.
by Thomas Heverin
CVSS 7.5
CVE-2024-0132 EXPLOITDB CRITICAL text
NVIDIA Container Toolkit < 1.16.2 - Time-of-check Time-of-use Race Condition
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
by r0binak
CVSS 9.0
CVE-2025-56241 EXPLOITDB HIGH text
Aztech DSL5005EN - Privilege Escalation
Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication.
by Amir Hossein Jamshidi
CVSS 7.5
CVE-2024-21320 EXPLOITDB MEDIUM text
Windows 10/11, Server 2012-2022 - Sensitive Info Exposure via Theme Spoofing
Windows Themes Spoofing Vulnerability
by Abinesh kamal K U
CVSS 6.5
EIP-2026-108044 EXPLOITDB text
Jasmin Ransomware - SQL Injection Login Bypass
by Buğra Enis Dönmez
CVE-2025-2126 EXPLOITDB MEDIUM text
JoomlaUX JUX Real Estate 3.4.0 - SQL Injection
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties of the component GET Parameter Handler. The manipulation of the argument title leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
by CraCkEr
CVSS 6.3
EIP-2026-107159 EXPLOITDB text
FluxBB 1.5.11 - Stored Cross-Site Scripting (XSS)
by Chokri Hammedi
CVE-2025-66575 EXPLOITDB HIGH text
VeeVPN 1.6.1 - Unquoted Service Path Remote Code Execution via VeePNService
VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.
by Doğukan Orhan
CVSS 7.8
CVE-2025-66574 EXPLOITDB MEDIUM text
TranzAxis 3.2.41.10.26 - Authenticated Stored Cross-Site Scripting via Open Object in Tree Endpoint
TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges.
by ABABANK REDTEAM
CVSS 5.4
CVE-2025-66572 EXPLOITDB MEDIUM text
Loaded Commerce 6.6 - Unauthenticated Remote Code Execution via Search Parameter
Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthenticated attackers to execute arbitrary code in the victim's browser context when they visit a crafted URL.
by tmrswrr
EIP-2026-104265 EXPLOITDB text
Gitea 1.24.0 - HTML Injection
by Mikail KOCADAĞ
CVE-2024-58287 EXPLOITDB HIGH text
reNgine 2.2.0 - Authenticated Remote Code Execution via Nmap Command Parameter Injection
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine configuration.
by Caner Tercan
CVSS 8.8
CVE-2024-58286 EXPLOITDB CRITICAL text
dizqueTV 1.5.3 - Remote Code Execution via FFMPEG Executable Path
dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.
by Ahmed Said Saud Al-Busaidi
CVE-2024-46626 EXPLOITDB HIGH text
OS4ED openSIS-Classic 9.1 - SQL Injection via Crafted Payload
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
by Devrim Dıragumandan
CVSS 8.8
EIP-2026-104362 EXPLOITDB text
NoteMark < 0.13.0 - Stored XSS
by Alessio Romano (sfoffo)
EIP-2026-104264 EXPLOITDB text
Gitea 1.22.0 - Stored XSS
by Catalin Iovita_ Alexandru Postolache
EIP-2026-101707 EXPLOITDB text
Elber Wayber Analog/Digital Audio STL 4.00 - Device Config Disclosure
by LiquidWorm
EIP-2026-101706 EXPLOITDB text
Elber Wayber Analog/Digital Audio STL 4.00 - Authentication Bypass
by LiquidWorm
EIP-2026-101701 EXPLOITDB text
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Device Config
by LiquidWorm
EIP-2026-101700 EXPLOITDB text
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass
by LiquidWorm