Text Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-19782 EXPLOITDB MEDIUM text
FreshRSS 1.11.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.
by Netsparker
CVSS 6.1
CVE-2018-19752 EXPLOITDB MEDIUM text
DomainMOD <4.11.01 - XSS
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
by Mohammed Abdul Raheem
CVSS 4.8
CVE-2018-19749 EXPLOITDB MEDIUM text
DomainMOD <4.11.01 - XSS
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
by Mohammed Abdul Raheem
CVSS 4.8
CVE-2018-19751 EXPLOITDB MEDIUM text
DomainMOD <4.11.01 - XSS
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
by Mohammed Abdul Raheem
CVSS 4.8
CVE-2018-19750 EXPLOITDB MEDIUM text
DomainMOD <4.11.01 - XSS
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.
by Mohammed Abdul Raheem
CVSS 5.4
CVE-2018-19799 EXPLOITDB MEDIUM text
Dolibarr ERP/CRM <8.0.3 - XSS
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
by AkkuS
CVSS 6.1
CVE-2018-19627 EXPLOITDB HIGH text VERIFIED
Wireshark <2.6.5-2.4.11 - Buffer Overflow
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.
by Google Security Research
CVSS 7.5
EIP-2026-103726 EXPLOITDB text VERIFIED
Wireshark - 'cdma2k_message_ACTIVE_SET_RECORD_FIELDS' Stack Corruption
by Google Security Research
CVE-2018-19616 EXPLOITDB HIGH text
Rockwellautomation Powermonitor 1000 Firmware - Authentication Bypass
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element.
by Luca.Chiou
CVSS 8.1
CVE-2018-19615 EXPLOITDB MEDIUM text
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Code Injection
Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a targeted user’s web browser to gain access to the affected device.
by Luca.Chiou
CVSS 6.1
EIP-2026-115866 EXPLOITDB text
Mozilla Firefox 63.0.1 - Denial of Service (PoC)
by SAIKUMAR CHEBROLU
EIP-2026-113544 EXPLOITDB text
WordPress Plugin Advanced-Custom-Fields 5.7.7 - Cross-Site Scripting
by Loading Kura Kura
EIP-2026-110761 EXPLOITDB text
PHP Server Monitor 3.3.1 - Cross-Site Request Forgery
by Javier Olmedo
EIP-2026-102569 EXPLOITDB text
Budabot 4.0 - Denial of Service (PoC)
by Ryan Delaney
CVE-2018-25134 EXPLOITDB CRITICAL text
Synaccess netBooter NP-02x/NP-08x 6.8 - Auth Bypass
Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by sending crafted POST requests to create administrative accounts and gain unauthorized control over power supply management.
by LiquidWorm
CVSS 9.8
CVE-2018-19277 EXPLOITDB HIGH text
PHPOffice PhpSpreadsheet <1.5.0 - XSS
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
by Alex Leahu
CVSS 8.8
CVE-2018-19564 EXPLOITDB MEDIUM text
Easy Testimonials <3.2 - XSS
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
by En_dust
CVSS 6.1
EIP-2026-119515 EXPLOITDB text
Arm Whois 3.11 - Buffer Overflow (ASLR)
by zephyr
EIP-2026-119514 EXPLOITDB text
Arm Whois 3.11 - Buffer Overflow (ASLR)
by zephyr
CVE-2018-18923 EXPLOITDB CRITICAL text
Abisoftgt Ticketly - SQL Injection
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and status_id in reports.php.
by Javier Olmedo
CVSS 9.8
EIP-2026-109944 EXPLOITDB text
No-Cms 1.0 - 'order_by' SQL Injection
by Loading Kura Kura
EIP-2026-102669 EXPLOITDB text
MariaDB Client 10.1.26 - Denial of Service (PoC)
by strider
EIP-2026-102146 EXPLOITDB text
Zyxel VMG1312-B10D 5.13AAXA.8 - Directory Traversal
by numan türle
EIP-2026-101954 EXPLOITDB text
Ricoh myPrint 2.9.2.4 - Hard-Coded Credentials
by Hodorsec
CVE-2018-25210 EXPLOITDB HIGH text
WebOfisi E-Ticaret 4.0 SQL Injection via urun Parameter
WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL payloads through the 'urun' parameter to execute boolean-based blind, error-based, time-based blind, and stacked query attacks against the backend database.
by AkkuS
CVSS 8.2