Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-115781 EXPLOITDB text VERIFIED
Microsoft Windows - Font Subsetting DLL Heap-Based Out-of-Bounds Read in MergeFonts
by Google Security Research
EIP-2026-115637 EXPLOITDB text VERIFIED
Microsoft DirectWrite / AFDKO - Use of Uninitialized Memory While Freeing Resources in var_loadavar
by Google Security Research
EIP-2026-115636 EXPLOITDB text VERIFIED
Microsoft DirectWrite / AFDKO - Stack-Based Buffer Overflow in do_set_weight_vector_cube for Large nAxes
by Google Security Research
CVE-2019-1123 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
by Google Security Research
CVSS 8.8
CVE-2019-1117 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
by Google Security Research
CVSS 8.8
CVE-2019-1127 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1128.
by Google Security Research
CVSS 8.8
CVE-2019-1118 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
by Google Security Research
CVSS 8.8
CVE-2019-1119 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
by Google Security Research
CVSS 8.8
EIP-2026-115635 EXPLOITDB text VERIFIED
Microsoft DirectWrite / AFDKO - Out-of-Bounds Read in OpenType Font Handling Due to Undefined FontName Index
by Google Security Research
EIP-2026-115634 EXPLOITDB text VERIFIED
Microsoft DirectWrite / AFDKO - NULL Pointer Dereferences in OpenType Font Handling While Accessing Empty dynarrays
by Google Security Research
EIP-2026-115633 EXPLOITDB text VERIFIED
Microsoft DirectWrite / AFDKO - Multiple Bugs in OpenType Font Handling Related to the _post_ Table
by Google Security Research
EIP-2026-115632 EXPLOITDB text VERIFIED
Microsoft DirectWrite / AFDKO - Interpreter Stack Underflow in OpenType Font Handling Due to Missing CHKUFLOW
by Google Security Research
CVE-2019-1121 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
by Google Security Research
CVSS 8.8
CVE-2019-1124 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1127, CVE-2019-1128.
by Google Security Research
CVSS 8.8
CVE-2019-1122 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
by Google Security Research
CVSS 8.8
CVE-2019-1120 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
by Google Security Research
CVSS 8.8
EIP-2026-115631 EXPLOITDB text VERIFIED
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readEncoding
by Google Security Research
CVE-2019-1128 EXPLOITDB HIGH text VERIFIED
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127.
by Google Security Research
CVSS 8.8
EIP-2026-115630 EXPLOITDB text VERIFIED
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow Due to Integer Overflow in readTTCDirectory
by Google Security Research
CVE-2019-13344 EXPLOITDB MEDIUM text
CRUDLab WP Like Button <= 1.6.0 - Unauthenticated Settings Update via contains() Function
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.
by Benjamin Lim
CVSS 5.3
EIP-2026-108969 EXPLOITDB text
Karenderia Multiple Restaurant System 5.3 - SQL Injection
by Mehmet EMIROGLU
EIP-2026-108968 EXPLOITDB text VERIFIED
Karenderia Multiple Restaurant System 5.3 - Local File Inclusion
by Mehmet EMIROGLU
CVE-2019-9701 EXPLOITDB MEDIUM text
Symantec Data Loss Prevention 15.5 MP1 and prior - Cross-Site Scripting
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.
by Chapman Schleiss
CVSS 4.8
CVE-2019-25486 EXPLOITDB HIGH text
Varient 1.6.1 - Unauthenticated SQL Injection via user_id Parameter
Varient 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_id parameter. Attackers can submit POST requests with crafted SQL payloads in the user_id field to bypass authentication and extract sensitive database information.
by Mehmet EMIROGLU
CVSS 8.2
CVE-2019-25243 EXPLOITDB HIGH text
FaceSentry 6.4.8 - Command Injection
FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.
by LiquidWorm
CVSS 8.8