Text Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-25710 EXPLOITDB HIGH text
Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter
Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.
by Mehmet Onder
CVSS 8.2
EIP-2026-103728 EXPLOITDB text VERIFIED
Wireshark - 'get_t61_string' Heap Out-of-Bounds Read
by Google Security Research
EIP-2026-103727 EXPLOITDB text VERIFIED
Wireshark - 'get_t61_string' Heap Out-of-Bounds Read
by Google Security Research
CVE-2019-25713 EXPLOITDB HIGH text
MyT-PM 1.5.1 SQL Injection via Charge[group_total] Parameter
MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blind, or stacked query payloads to extract sensitive database information or manipulate data.
by Mehmet Onder
CVSS 7.1
CVE-2019-25454 EXPLOITDB MEDIUM text
phpMoAdmin 1.1.5 - XSS
phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25453 EXPLOITDB MEDIUM text
phpMoAdmin 1.1.5 - XSS
phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute arbitrary code in users' browsers when they visit the malicious link.
by Ozer Goker
CVSS 6.1
CVE-2019-25451 EXPLOITDB HIGH text
phpMoAdmin 1.1.5 - CSRF
phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.
by Ozer Goker
CVSS 8.8
CVE-2018-20525 EXPLOITDB CRITICAL text
Roxyfileman Roxy Fileman - Path Traversal
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
by Pongtorn Angsuchotmetee_ Vittawat Masaree
CVSS 9.1
CVE-2018-20221 EXPLOITDB HIGH text
Deltek Ajera Timesheets <9.10.16 - Code Injection
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.
by Anthony Cole
CVSS 8.8
CVE-2018-18435 EXPLOITDB HIGH text
Kioware Server < 4.9.6 - Incorrect Permission Assignment
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyone: (F)" to the contents of the directory and it's sub-folders. In addition, the program installs a service called "KWSService" which runs as "Localsystem", this will allow any user to escalate privileges to "NT AUTHORITY\SYSTEM" by substituting the service's binary with a malicious one.
by Hashim Jawad
CVSS 7.8
EIP-2026-114162 EXPLOITDB text
WordPress Plugin UserPro < 4.9.21 - User Registration Privilege Escalation
by Noman Riffat
CVE-2018-20526 EXPLOITDB CRITICAL text
Roxyfileman Roxy Fileman - Unrestricted File Upload
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
by Pongtorn Angsuchotmetee_ Vittawat Masaree
CVSS 9.8
CVE-2019-3501 EXPLOITDB MEDIUM text
Ougc Awards < 1.8.19 - XSS
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards page or in a user profile.
by 0xB9
CVSS 4.8
CVE-2018-17997 EXPLOITDB MEDIUM text
Layerbb - XSS
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
by 0xB9
CVSS 6.1
EIP-2026-106849 EXPLOITDB text VERIFIED
Embed Video Scripts - Persistent Cross-Site Scripting
by Deyaa Muhammad
EIP-2026-105100 EXPLOITDB text VERIFIED
All in One Video Downloader 1.2 - (Authenticated) SQL Injection
by Deyaa Muhammad
CVE-2018-20326 EXPLOITDB MEDIUM text
ChinaMobile PLC Wireless Router - XSS
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter.
by Kumar Saurav
CVSS 6.1
EIP-2026-117543 EXPLOITDB text
Microsoft Windows - Windows Error Reporting Local Privilege Escalation
by SandboxEscaper
EIP-2026-113533 EXPLOITDB text
WordPress Plugin Adicon Server 1.2 - 'selectedPlace' SQL Injection
by Kaimi
CVE-2018-20448 EXPLOITDB MEDIUM text
Frog Cms - XSS
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
by WangDudu
CVSS 5.4
EIP-2026-113586 EXPLOITDB text
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File Upload
by Kaimi
EIP-2026-113575 EXPLOITDB text
WordPress Plugin Audio Record 1.0 - Arbitrary File Upload
by Kaimi
CVE-2018-20418 EXPLOITDB MEDIUM text
Craftcms Craft Cms - XSS
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
by Raif Berkay Dincel
CVSS 4.8
CVE-2018-1000811 EXPLOITDB HIGH text
bludit <3.0.0 - RCE
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP code.
by BouSalman
CVSS 8.8
CVE-2018-1000890 EXPLOITDB HIGH text
FrontAccounting 2.4.5 - SQL Injection
FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.
by Sainadh Jamalpur
CVSS 7.5